No more typing reviews! Try our Samantha, our new voice AI agent.

Abnormal Security vs Cisco Secure Email Threat Defense comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 3, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Abnormal Security
Ranking in Email Security
11th
Average Rating
9.4
Reviews Sentiment
7.5
Number of Reviews
11
Ranking in other categories
Secure Email Gateway (SEG) (5th)
Cisco Secure Email Threat D...
Ranking in Email Security
23rd
Average Rating
8.0
Reviews Sentiment
6.7
Number of Reviews
16
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of August 2026, in the Email Security category, the mindshare of Abnormal Security is 3.6%, down from 7.1% compared to the previous year. The mindshare of Cisco Secure Email Threat Defense is 1.1%, up from 1.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Email Security Mindshare Distribution
ProductMindshare (%)
Abnormal Security3.6%
Cisco Secure Email Threat Defense1.1%
Other95.3%
Email Security
 

Featured Reviews

reviewer2251509 - PeerSpot reviewer
Senior Director, Information Technology at a insurance company with 51-200 employees
AI has helped classify threat types more accurately but product ownership can improve
Ease of use is important, and Abnormal Security's responsiveness and ability to deliver solutions when issues arise are crucial. However, there is always room for improvement, as achieving a perfect 10 means there is no more room for enhancement. For Abnormal Security, it's about leveraging AI even more, which they are already working on in their roadmap.
NM
Enginner at Millennium Information Technologies
Has faced challenges with configuration, taking actions, and learning curve but benefits from centralized management and good technical support
We have deployed Cisco Secure Email Threat Defense in two customer environments. It is still in development as a new product. Some customer requirements, such as sending logs to a Syslog server, are limited as ETD only supports sending audit logs. Customers have requirements for other system logs as well, which should be developed from their side. Another customer request is to restrict the IPs that can log in, which cannot be done from Cisco Secure Email Threat Defense yet. Any user with login details can log in. We can restrict the IPs in Cloud Mail Gateways, but not from Cisco Secure Email Threat Defense. It would be beneficial to improve this feature. Cisco Secure Email Threat Defense can take actions, such as requesting O365 to quarantine mail. In that case, the customer requires notification to the recipient from Cisco Secure Email Threat Defense. This option would be valuable if available. The real-time threat intelligence of Cisco Secure Email Threat Defense is an AI-based classification. It took one to two months to optimize the classification, but we still experience some false positives. Reducing the learning period would be beneficial. The learning curve shows that in the beginning, there are numerous false positives. For one month, we had to reclassify the false positives manually until the system learned. Reducing the learning time would be much better. Additional features desired in the next release include IP restrictions and user logging IP restrictions, ensuring only the customer environment can log in to Cisco Secure Email Threat Defense. Logs forwarding needs improvement as currently it only has audit logs. In Cloud Mail Gateway, we can create an IPsec tunnel to forward logs. However, in Cisco Secure Email Threat Defense, there is no option, and we must do API integration to send logs. Only SIM can get logs; Syslog cannot retrieve them.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It does some really cool stuff that other tools aren't doing. We found it to be really effective, and the AI/ML functionality is really what differentiates them."
"Their ability to take things out of the mailbox and catch things much faster than users is excellent."
"Initial auto-remediation allows us to auto-remediate before the email lands in the end user's inbox for a split second."
"Ease of use is undoubtedly one of the most valuable features of Abnormal Security."
"It protects us from being business email compromised, which is invaluable for maintaining our security."
"I have never encountered any stability issues with Abnormal."
"I like Abnormal's threat protection with auto-remediation, but I also love its abuse mailbox feature, which automatically responds to the end user. That feature has a super-valuable security component and helps improve the user experience."
"The features that appeal to me most are the combination of auto-remediation and Detection 360."
"The product offers protection, email security, anti-spam, and antivirus."
"This solution is easy to use."
"Cisco Cloud Mailbox is used for copying emails, anti-spamming, and securing the company's email, and we really enjoy the anti-spamming capabilities as well as the rejecting of bulk emails, which we can customize by adjusting the variables, and it is very user-friendly."
"The ability to see east-west traffic is its most valuable feature. Traditionally, email defense focuses on north-south, inbound-outbound, egress-ingress traffic. With Cisco Secure Email Cloud Mailbox, it's able to quickly identify, track, tag, and categorize emails that are internal. That can typically give us visibility into if there's an internal compromised account (for example). Someone can then use that internal compromised account to email additional accounts with either malicious software or links, but internal within that Office tenant. Effectively, that email message never leaves the tenant. Any of the mail gateways really do not have any method or way of seeing this traffic since it's not leaving the environment."
"Cisco Secure Email Cloud Mailbox can handle a complete portfolio, which is required to protect any kind of attack coming from emails. However, it does not have advanced phishing, but it is available through Cisco. If you compare Cisco Secure Email Cloud Mailbox with the competition, in the competition you have to have one or two solutions together to address the customer's requirement, whereas Cisco Secure Email Cloud Mailbox is addressing everything, such as web domain and email protection. If there is any kind of challenge it will come across through email."
"It's very easy to deploy and configure."
"Overall, it's certainly a very good idea to integrate another layer on top of Microsoft Advanced Threat Protection."
"The solution is stable."
 

Cons

"When we're working on something as engineers, and we find an idea or a method of doing something that would be greatly improved by doing it another way, there should be an ability for me to click the ideas button, type in an idea that I have, and submit it to a product review team or developers to have them think through the process a little bit more."
"I, as such, do not have anything that I do not like or would like to add, but you could argue that because they are doing it API-based, there is a chance that something could slip through temporarily before they are able to pull it out. In theory, it could happen just because of the nature of the system. They are not in line with the delivery of the mail. They are kind of asynchronous, which is a pro as well as a con. If it is synchronous, then I know it would always stop them, but because it is asynchronous, things could get through temporarily or because of some system issues on the Microsoft side or their side. It is the nature of the beast, but it is a little bit of a con."
"The ideal scenario would be for Abnormal Security to work in tandem with Microsoft to analyze incoming emails."
"Abnormal should add more automatic reports. I have an open request to our account team for more notification and report types that can be sent automatically. For example, they have an awesome report that gets sent weekly, and I also want them monthly, so I don't need to do so much adding up when my director wants numbers over time."
"One feature I'd love to see is outbound scanning."
"The biggest pain point for us is the lack of support for on-premise email systems."
"I would like to have the ability to customize the auto-remediation feature."
"There could be room for improvement in enhancing integration with other cybersecurity tools."
"The search area has room for improvement."
"The search area has room for improvement. When you go to the next page, it remains at the bottom of the current page that you're on. Also, under the reports section, it allows you to see any "convictions," but if you want to search for those convictions you have to remember when they all came in and go back and edit the search accordingly. You cannot click on the list of convictions to actually see if you had a spike at a certain time."
"Customers will benefit greatly from monthly billing because the majority of customers today use the cloud, be it Office 365, or Google Cloud."
"This solution could be improved by integration with Sandbox."
"The physical appliance has been discontinued, although the platform still exists."
"The solution is a bit expensive. It could be cheaper."
"The learning curve shows that in the beginning, there are numerous false positives. For one month, we had to reclassify the false positives manually until the system learned."
"From a technical point of view, Cisco is far behind in terms of cybersecurity, and it has to improve very much."
 

Pricing and Cost Advice

"Abnormal Security, on the other hand, provides the same level of functionality for just over $60,000 – that's half the price!"
"The pricing appears fair, and they demonstrate a genuine willingness to work with us on it."
"Overall, we'd certainly prefer lower pricing, but Abnormal Security doesn't seem unreasonable compared to similar offerings in the market."
"The license is based on the user count, so the number of users that have an email address in the organization."
"Cisco Secure Email Cloud Mailbox does not have any competition with Sophos, Trend Micro, or other vendors of the world. However, there is a pricing premium for the solution. One has to look at it from that angle that while they are buying Cisco, there will be a premium, and Cisco justifies that premium value. That's why they're charging a high price."
"The solution’s pricing is manageable."
"The feedback from vendors and customer is that it is expensive."
"It is expensive compared to other vendors."
report
Use our free recommendation engine to learn which Email Security solutions are best for your needs.
911,436 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
10%
Financial Services Firm
9%
Computer Software Company
9%
Government
6%
Marketing Services Firm
11%
Construction Company
8%
Comms Service Provider
8%
Outsourcing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business1
Midsize Enterprise2
Large Enterprise8
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise6
Large Enterprise7
 

Questions from the Community

What is your experience regarding pricing and costs for Abnormal Security?
I find the pricing to be favorable, but I did not disclose the exact cost.
What needs improvement with Abnormal Security?
Ease of use is important, and Abnormal Security's responsiveness and ability to deliver solutions when issues arise are crucial. However, there is always room for improvement, as achieving a perfec...
What is your primary use case for Abnormal Security?
The main use case for Abnormal Security is as a spam filter and for mail hygiene. This use case is for the finance industry.
What is your experience regarding pricing and costs for Secure Email Threat Defense?
Comparatively with other products, the pricing of Cisco Secure Email Threat Defense is normal. As a technical guide, I am not very aware of the pricing details.
What needs improvement with Secure Email Threat Defense?
We have deployed Cisco Secure Email Threat Defense in two customer environments. It is still in development as a new product. Some customer requirements, such as sending logs to a Syslog server, ar...
What is your primary use case for Secure Email Threat Defense?
We are working with Cloud Mail Gateway and on-premise mail gateways. We have worked with Cisco Secure Email Threat Defense.
 

Also Known As

No data available
Cisco Secure Email Cloud Mailbox, Cisco CMD, Cisco Cloud Mailbox Defense
 

Overview

 

Sample Customers

Foot Lcoker, Xerox, Liberty Mutual, Mattel, Boston Scientific
Luiss University, Lone Star College, T-Systems, Magyar Telekom
Find out what your peers are saying about Abnormal Security vs. Cisco Secure Email Threat Defense and other solutions. Updated: August 2026.
911,436 professionals have used our research since 2012.