CASE FILE // PC-2026-04
Status: Open


Filing 06.02.00Field 27 APR 2026Classification PublicStatus Open

Abnormal Security cost: quote-only, priced per mailbox per year

Abnormal is the leading independent behavioural-AI email-security vendor in 2026. It does not publish a list price: it is sold per mailbox per year by private offer. The behavioural-AI post-delivery model catches a category of sophisticated phishing that legacy gateway-style scanning fundamentally cannot catch, which justifies the price premium versus traditional alternatives.

Exhibit A

Behavioural-AI email security as a category


Behavioural-AI email security emerged as a distinct product category through 2018-2022 as the limitations of gateway-style scanning became visible against sophisticated phishing attacks. The premise of behavioural-AI is that an attack pattern can be detected not by examining the email content for malicious-indicator patterns but by examining the email metadata (sender-recipient relationship history, communication frequency, language pattern, topic novelty) for behavioural-anomaly patterns that signal something is wrong even when the content passes content-based scanning.

The category leaders in 2026 are Abnormal Security (independent, founded 2018), Tessian (acquired by Proofpoint November 2024, now bundled with TAP), and IRONSCALES (independent, founded 2014). Sublime Security has emerged through 2023-2025 as a newer entrant with detection-as-code positioning. The functional positioning across vendors is similar; the differentiation is in modelling depth, deployment ease, and pricing.

The attack patterns behavioural-AI catches best are sophisticated BEC (where the lure is grammatically perfect and refers to real organisational context), AitM lures from compromised legitimate domains (where reputation-lookup passes because the domain is legitimate), and vendor-impersonation through compromised supplier mailboxes (where the sender is real but the message intent is fraudulent). For organisations facing material exposure to these patterns, behavioural-AI is one of few product categories that meaningfully reduces residual risk. The post-delivery operating model (analysing email after it has arrived in the mailbox) means the product can use full-mailbox context for detection rather than just the inbound-stream view that gateway-style products see.[Gartner Magic Quadrant Email Security 2024 + Forrester Wave Enterprise Email Security 2024]

Exhibit B

Abnormal Security pricing and the premium justification

REFERENCE

Abnormal does not publish a list price. It is sold quote-only, per mailbox (per employee) per year, by private offer; its AWS Marketplace listing routes to a custom quote rather than a fixed rate and advertises larger discounts on 24- and 36-month terms. Cost is driven by mailbox count, the modules enabled (inbound email security, account-takeover protection, AI security mailbox, email productivity), and contract length, plus a one-off platform-onboarding fee. Buyer-data aggregators report per-mailbox figures in the low tens of dollars per year, but because no rate is published these are unverified inputs to your own quote, not a benchmark. The pricing sits above gateway-style alternatives (Microsoft Defender for Office 365 Plan 2 at near-zero incremental cost for M365 E5 customers; Proofpoint TAP, itself quote-only) but the value proposition is different.

The premium justification rests on attack-pattern coverage. Gateway-style products are highly effective against bulk and lower-sophistication phishing at low per-mailbox cost. The limit of gateway-style effectiveness is the residual sophisticated-attack category that bypasses reputation-lookup and rule-based scanning because the lure is grammatically perfect, uses a legitimate (or compromised-legitimate) sender domain, and references real organisational context. This residual category produces the highest per-event cost (because sophisticated attacks are typically targeted at high-value identities and high-value transactions) and is exactly what Abnormal's behavioural-AI is designed to catch.

The ROI logic holds even without a published rate. A mid-market organisation running TAP alongside Abnormal on 2,000 mailboxes pays the sum of two per-mailbox quotes; at an illustrative combined $100 per mailbox (substitute your own quoted rates) that is $200,000 per year. Against the modelled $4.20M average mid-market breach cost (see /by-scale/mid-market), the combined program pays back on a single avoided sophisticated-attack event. The dual-product architecture is now the standard for mid-market and enterprise organisations facing meaningful sophisticated-attack exposure.[Abnormal AWS Marketplace listing (private-offer / quote-only), checked August 2026; combined-cost figure is an illustrative model]

Exhibit C

Illustrative annual spend by organisation size


Organisation sizeMailboxesAt $25/mailbox (illustrative)At $50/mailbox (illustrative)
Mid-market500$12,500$25,000
Mid-market2,000$50,000$100,000
Upper mid-market5,000$125,000$250,000
Enterprise10,000$250,000$500,000
Large enterprise25,000$625,000$1,250,000
Fortune 50050,000$1,250,000$2,500,000

Abnormal publishes no per-mailbox rate, so this table is a scaling model, not a price list: it multiplies mailbox count by two illustrative rates to bracket a range. Locate your quoted per-mailbox rate between the columns (or substitute it directly). Spend also depends on which modules you enable and your contract term; the typical dual-product architecture (Abnormal alongside a gateway-style product) adds the gateway product's separate cost.[Illustrative scaling model (mailbox count x illustrative rate); Abnormal does not publish per-mailbox rates]

Exhibit D

The Tessian-into-Proofpoint consolidation


In November 2024, Proofpoint announced its acquisition of Tessian, the second-largest independent behavioural-AI email-security vendor at the time. The acquisition consolidated the behavioural-AI category in a way that has reshaped buyer decision-making through 2025-2026. Pre-acquisition, Tessian competed with Abnormal as the independent-vendor alternative; post-acquisition, Tessian operates as the bundled-with-TAP behavioural-AI layer in Proofpoint's stack, with Abnormal as the leading independent option.

The acquisition's effect on Abnormal pricing has been measurable. With one fewer independent competitor in the category, Abnormal's pricing power has firmed; the bottom-of-band pricing has compressed slightly. The acquisition also created a strategic-decision point for buyers who were previously running Tessian alongside a non-Proofpoint gateway product. The post-acquisition Tessian product is integrated more tightly into the Proofpoint stack, which makes it more attractive for existing Proofpoint customers and less attractive for non-Proofpoint customers who wanted Tessian-independent.

The current independent-vendor competitive landscape includes Abnormal (clear category leader by customer count), IRONSCALES (lower-priced alternative with similar functional positioning), Sublime Security (newer entrant with detection-as-code differentiation), and a handful of smaller players. For most buyers in 2026, the practical decision is between Abnormal and IRONSCALES on price-versus-feature, with Tessian-via-Proofpoint as the bundled alternative for existing Proofpoint customers.[Proofpoint-Tessian acquisition announcement November 2024 + post-acquisition product-integration analysis 2025]

Exhibit E

What Abnormal actually catches: attack-pattern coverage


Sophisticated BEC against finance and treasury

Grammatically-perfect impersonation of executives, vendors, or counsel where the lure references real organisational context. Catches sub-types that pass display-name and lookalike-domain detection because the sender appears legitimate in metadata. Strongest single use case for the product.

Vendor-mailbox-compromise BEC

Real supplier sender, real invoice format, real payment-cycle timing, but with redirected banking details. Catches the pattern that produces the largest per-event losses in manufacturing and legal-services sectors (see /by-industry/manufacturing and /by-industry/legal).

AitM lures from compromised legitimate domains

When the attacker has compromised a legitimate domain and is using it to host AitM lure infrastructure, reputation-lookup at the gateway passes because the domain is legitimate. Behavioural-AI catches the lure because the recipient has no history of receiving messages of this type from this sender.

Account-takeover detection and remediation

When an internal account is compromised and the attacker uses it to send onward phishing or data-exfil emails, behavioural-AI detects the abnormal outbound pattern (typical mailbox sends 30 messages per day, suddenly sending 500 to external recipients, with attachment content unusual for the sender). Catches the post-compromise pivot in addition to inbound attacks.

OAuth consent phishing detection

OAuth consent phishing tricks users into granting the attacker app access to their mailbox via legitimate OAuth flow. Abnormal detects the abnormal consent-grant pattern and alerts security team. Niche but valuable for organisations targeted by OAuth-consent threat actors.

Post-delivery remediation across all mailboxes

When Abnormal identifies a malicious email in one mailbox, it removes the same email from all other mailboxes that received it. The post-delivery remediation closes the lateral-spread window that gateway products cannot address.

Exhibit F

What buyers should ask before signing the Abnormal contract


What is the per-mailbox pricing including volume discount?

Compare against IRONSCALES and Sublime Security at the same volume. Abnormal is typically the premium-priced option; the premium needs to be justified on detection-quality grounds.

What is the typical detection-rate improvement over my existing stack?

Request a 30-60 day proof-of-value deployment where Abnormal runs in parallel with your existing email security and reports on attacks it catches that the incumbent missed. The detection-rate delta is the central evaluation criterion.

Is post-delivery remediation enabled?

Confirm the remediation feature is included and properly configured. The lateral-spread-closure value depends on remediation being active not just detection.

What is the integration with my SOC and SIEM?

Abnormal produces high-quality detection data that should feed into SOC workflows. Confirm integration with SIEM, SOAR, and ticketing platforms.

What is the data-residency and processing posture?

For EU operations, confirm EU-hosted deployment availability. For US-government contracts, confirm FedRAMP or equivalent authorisation status.

What is the multi-year discount and renewal-price cap?

Standard procurement questions. Multi-year commitments yield meaningful discount but optionality cost is real in a rapidly-evolving product category.

Exhibit G

Frequently filed questions

ON RECORD

How much does Abnormal Security cost?[open]

Abnormal does not publish a list price. It is quote-only, sold per mailbox (per employee) per year by private offer, including on AWS Marketplace. Cost depends on mailbox count, the modules enabled, and contract term (24- and 36-month terms carry larger discounts). Aggregator-reported per-mailbox figures exist but are unverified; treat any number as provisional until it is in your quote.

What is behavioural-AI email security?[open]

Models typical organisational communication patterns and flags messages that deviate from baseline. Catches sophisticated attacks that pass gateway-style content scanning.

How is Abnormal different from Proofpoint TAP?[open]

TAP is gateway-style (pre-delivery scanning); Abnormal is post-delivery behavioural-AI. Frequently deployed together in mature enterprise architectures.

What happened with Tessian?[open]

Acquired by Proofpoint November 2024. Now bundled with TAP. Abnormal is the leading independent vendor; IRONSCALES is the lower-priced alternative.

Why does Abnormal command a premium?[open]

Catches a category of sophisticated attacks that legacy gateway-style scanning fundamentally cannot catch. For organisations facing material sophisticated-attack exposure, Abnormal is one of few products that meaningfully reduces residual risk.

Do I need both Abnormal and a gateway product?[open]

In mature enterprise architectures, yes. Gateway catches bulk at low per-mailbox cost; Abnormal catches residual sophisticated. Abnormal-only deployments possible but suited to organisations primarily exposed to sophisticated rather than bulk attacks.

What is the proof-of-value evaluation?[open]

Request a 30-60 day parallel deployment where Abnormal reports on attacks it catches that your incumbent missed. The detection-rate delta is the central evaluation criterion.

Updated 2026-04-27