The Inbox Is Disappearing. Why Security Must Follow the Workspace
Enterprise work no longer fits neatly inside a defined perimeter. The modern workspace spans inboxes, browsers, SaaS applications, collaboration platforms, identities, endpoints, data stores and, increasingly, AI agents that can act across several of these environments at once.
Attackers have adapted to this reality faster than many enterprise security programs have. Rather than staying within a single product category, they follow the natural flow of work, moving from email to chat, from a browser session into a SaaS application, and from an identity prompt toward the data behind it.
That progression is exposing a structural gap in traditional security architecture. Many organizations still protect these layers as separate domains, even though users, applications, data and trust move between them continuously throughout the workday.
Gartner’s Market Overview for Workspace Cybersecurity Platforms captures this market shift. The report defines the emerging Workspace Cybersecurity Platform (WCP) category around protection converging across endpoints, identities, applications, data and AI usage, with the strongest platforms defined by deep integration, not loose bundling.
Trust now moves across channels
Recent Check Point Research shows how quickly attacks can move through the trusted channels employees use every day.
Researchers uncovered four vulnerabilities in Microsoft Teams that could have allowed attackers to impersonate executives, manipulate messages, alter notifications, and forge identities in video and audio calls. While the technical details matter, the larger issue is the trust employees place in familiar collaboration environments: names, prompts, notifications and interface cues all carry credibility because people use these platforms to make decisions every day.
Email creates the same kind of cross-channel risk
In a student job campaign observed by Check Point, the attack started with an email from a compromised school account. It then pushed the recipient to Google Forms and tried to collect information that could support financial fraud, account compromise or follow-on attacks.
OAuth phishing extends the path even further. A single message can lead to a legitimate Microsoft authorization workflow. Once access is granted, a malicious application may reach across Outlook, Teams, SharePoint, OneDrive, files and calendars.
At that point, it becomes difficult to say where the attack truly begins or ends. It is not simply an email attack, a SaaS attack or an identity attack. It is a workspace attack, designed to exploit trusted interfaces, legitimate services and the transitions between the tools employees rely on to get work done.
That is why the market is moving beyond loosely connected point tools. Gartner notes that resource-constrained security teams need a simpler, more unified WCP approach than traditional multivendor stacks, where silos can increase cost, introduce errors and weaken security posture.
Attackers do not respect product categories
For years, enterprise security architecture was organized around control points: the endpoint, the inbox, the browser, SaaS applications and the data layer. Each discipline remains essential, but attackers do not experience these domains as separate operating environments, and they do not limit campaigns to the boundaries defenders use to organize their tools.
The boundaries between those domains are now increasingly porous. Identity persists across applications, data moves between cloud services and endpoints, collaboration platforms carry both conversation and content, browsers have become the front door to enterprise applications, and email often serves as the starting point for workflows that continue somewhere else. AI assistants add another layer of complexity by connecting information and actions across several of these systems simultaneously.
For attackers, these handoffs are often where the opportunity begins.
Trusted services make that even harder to defend. Check Point Research’s ZipLine investigation showed attackers starting through public contact forms, building extended business conversations and later using legitimate cloud infrastructure to deliver malware.
Attackers have also abused Jira Cloud notifications sent through trusted Atlassian domains with valid email authentication. On the surface, the message looks legitimate. The risk sits in the workflow it enables.
Across these examples, the challenge is not limited to detecting a malicious object at a single point in time. Defenders need enough context to understand activity across users, communications, applications, content and behavior, because the risk often emerges from how those elements interact.
AI accelerates the convergence
Agentic AI intensifies the problem because it can operate across the same channels attackers already target, but with greater speed, broader access and less obvious human intervention.
An AI assistant may move between email, calendars, documents, browsers, collaboration tools, SaaS applications and enterprise data as part of a single workflow. Instead of a person manually shifting from one application to another, the agent can retrieve information, summarize content, recommend next steps and trigger actions at machine speed. That creates meaningful productivity potential, but it also changes the potential blast radius when trust is misplaced or malicious instructions are introduced.
Check Point Research’s 2026 AI Security Report describes AI as an expanding attack surface. It also highlights the operational risk of indirect prompt injection, where malicious instructions embedded in content can influence systems that process that information.
If an agent reads a malicious message, retrieves a document, accesses a website and then acts in another application, the key question is not which individual security product owns the interaction. The question is whether the complete workflow can be protected.
Gartner points to the same pressure. Accelerating AI adoption is one reason WCPs are converging as a category. Security teams now need ways to discover, assess, log, report on and enforce policy for both approved and unsanctioned AI usage.
From point protection to WCP
This does not mean enterprises should abandon specialized security controls. Email, endpoint, browser, SaaS, identity, data and collaboration all still require deep protection.
What is changing is the expectation that these controls work together with shared context, rather than operate as isolated checkpoints in a fragmented security stack.
A WCP approach should coordinate prevention, intelligence, policy and visibility across the environments where users and AI systems actually work. A signal detected in email should inform decisions in the browser or collaboration layer. An identity anomaly should add context to a communication. A malicious web interaction should connect to endpoint behavior, while sensitive data policies should continue to apply as information moves between applications, users and agents.
The objective is not consolidation for its own sake. Gartner is clear that WCPs are not meant to replace every cybersecurity product. Organizations will still need specialized controls for defense in depth, coverage gaps, intelligence diversity and concentration risk.
The goal is to make those controls work as one system, so defenders can see the full path of an attack instead of the fragment that lands inside one product category.
Cybersecurity architecture has historically followed infrastructure boundaries, with separate disciplines for networks, endpoints, email and cloud applications. That model made sense when work was more contained, but it is less aligned with how enterprises operate today.
The next model needs to follow the user, the data and the AI agents now acting on their behalf, because that is where business activity happens and where attackers are increasingly concentrating their efforts.
The workspace has become the new security boundary
If securing your users and AI agents is a priority for your team, sign up for a brief session with one of our specialists to discuss your environment and see how Check Point’s WCP can help. Book a Demo >



