
We don’t think of individual alerts. We look at the entire behavior and context of what’s happening. That includes the cloud, the endpoint, identity, and email. Sublime is a critical input to the cross-domain context we use for our cybersecurity intelligence platform.



Overview
Recon InfoSec is one of the highest-rated cybersecurity companies in the world, with a lifetime Net Promoter Score of +92. By comparison, its largest MDR competitors celebrate scores in the upper sixties. Recon credits the gap to three things: it gives customers back time, it investigates threats to root cause instead of just forwarding alerts, and it catches attackers fast.
To deliver these outcomes at scale Recon requires rich telemetry, flexible tools, and the ability to engineer detections-as-code. Sublime has become their go-to solution for email.
Moving further left
Before Sublime, Recon was dependent on the email tools already present in customer environments, including native Microsoft and Google capabilities and traditional email security products. Those systems varied widely in effectiveness and the quality of data provided, making it difficult to leverage automation to deliver fast detection and response at scale.
Recon’s security operations center was responding to multiple identity compromises and BEC incidents each week. Even when analysts discovered and contained them quickly, customers had already experienced a successful attack.
Recon wanted first-class email telemetry to use alongside everything else in the environment. They also wanted to hunt across organizations, apply what they learned from one customer to others, and bring email into the same correlated detection engine as identity, endpoint, and cloud security.
Traditional email security products and one-size-fits-all controls couldn’t support that vision.
Choosing technology for builders
“At Recon we hire builders,” Cook said. “The better a solution allows our team to be creative, innovative, and solve problems that matter to our customers the more we want it in our stack.”
That philosophy shaped Recon’s evaluation of email security platforms. As Cook put it, they wanted “technologies we could build on top of.” Strong APIs, detections as code, and transparency around detection logic all aligned with how the rest of Recon’s platform works.
Sublime fit that model, allowing Recon to integrate email into its existing orchestration, investigation, and response workflows instead of managing it as a separate system.
Once deployed in customer environments, the difference was immediate. Recon was able to identify two to three times more malicious emails with Sublime than with customers’ existing solutions, while historical ingestion surfaced threats already sitting in users’ mailboxes, helping investigators respond faster and customers see value quickly.
Andrew likens the shift to the introduction of endpoint detection and response.
Connecting email to the rest of the attack chain
Sublime’s telemetry allows Recon to combine email, identity, endpoint and cloud signals into a single view of an attack. Michael Robertson, Email Security Engineer at Recon, points to the quality of the underlying data. “The level of enrichment that Sublime gives us is still unparalleled,” he said.
Instead of asking whether a message is malicious, Recon asks a bigger question: what does that message reveal about the rest of the attack?
Email data also powers the “cybersecurity superpowers” Recon puts in the hands of customers to understand why messages were quarantined, investigate phishing campaigns, and communicate findings more effectively.
Turning one report into collective defense
Email intelligence also extends protection across Recon’s customer base.
When a user reports a malicious email, Recon can use Sublime data to search for the same campaign across other users and organizations, remove related messages, and improve future coverage.
This approach is especially valuable when compromised vendor accounts target multiple Recon customers, allowing a single report to trigger protection across other customer environments.
Fewer incidents, faster answers
Recon’s automation and AI workflows now resolve 99.7% of email cases without requiring analyst review. This lets Recon scale without growing analyst workload at the same pace.
When an investigation is required, Recon can typically locate, assess, and take action on an email in less than one minute. The same task in native provider email tools can take much longer, if possible at all.
The impact goes beyond efficiency. As Recon transitioned customers onto its Sublime-powered service, account compromises and wire fraud dropped to near zero. Email-originated compromises are now rare. When incidents do occur, the initial entry point is usually outside the protected corporate mailbox.
Building better security
Whether as part of Recon’s broader “drop-in replacement for traditional MDR” or as a standalone solution, treating email as a core security signal is integral to how Recon keeps its customers happy and secure.





.avif)