Acronis Advanced Email Security is an add-on pack that brings enterprise email protection to an Acronis Cyber Protect Cloud subscription. According to the official data sheet, email content is unpacked recursively, checked by multiple engines in under 30 seconds, and a clear verdict is returned within 10 seconds on average; the engines include Perception Point's CPU-level analysis technology (Acronis Advanced Email Security data sheet, 2023). Protection is run from the existing Acronis management interface, without opening a separate console.
Threat data shows why email remains the top priority. According to Acronis's H2 2025 Cyberthreats Report, more than 7,600 ransomware victims were publicly disclosed worldwide in the second half of 2025, phishing accounted for 83% of email threats, and email-based attacks rose 16% per organisation and 20% per user compared with the previous year (Acronis Cyberthreats Report H2 2025). The previous edition of the same series also shows how much gets through: in the H1 2025 report, based on signals from more than 1,000,000 unique endpoints, malware was found in 1.47% of Microsoft 365 email backups (Acronis Cyberthreats Report H1 2025).
That second figure sums up why email security and backup have to be thought about together: malicious content that reaches the mailbox also ends up in the backup when nobody notices. Acronis Cyber Protect Cloud unifies backup and baseline cyber protection in a single agent; Acronis Advanced Email Security adds the layer that stops the message before it reaches the user. At Sora Yazılım we license the pack within the Acronis solution family, set up the integration, configure policies and quarantine workflows, and — where requested — run it for you under a managed service model.
What does Acronis Advanced Email Security do, and which attack types does it stop?
Short answer: the pack puts inbound email not through a single engine but through a chain of complementary engines, each layer targeting a different type of attack. The spam filter strips out volume noise; static signature analysis catches known malware; four URL reputation engines together with image recognition detect phishing pages; SPF, DKIM and DMARC checks close off sender spoofing; and Perception Point's CPU-level dynamic detection technology examines files and links with no known signature by executing them.
Four scenarios generate the most value in practice. First, business email compromise (BEC): fake executive or supplier requests that contain no malicious attachment or link and rely purely on persuasive language are the province of the anti-spoofing layer. The official data sheet defines this layer as combining IP reputation with SPF, DKIM and DMARC record checks and machine learning algorithms in order to prevent payload-less attacks such as spoofing, look-alike domains and display name deception (Acronis, 2023). Second, phishing: links impersonating a sign-in page are evaluated using both reputation data and image recognition; new domains that imitate a brand's login screen but do not yet appear on any reputation list become visible in that second layer. Third, file-based attacks: evasion techniques such as an archive inside an archive, a password-protected file or an embedded object are defeated by unpacking the content recursively; the data sheet describes this step as a deep scan of the entire content. Fourth, outbound email risk: the pack also covers outbound email scanning for Microsoft 365, with the aim of preventing a compromised account from spreading attacks in the organisation's name.
The intelligence that feeds the detection engines is part of the pack too: the official data sheet counts threat intelligence from six sources among the capabilities the pack adds. The list also includes an incident response service, meaning that post-detection investigation is not positioned as a burden the product leaves entirely to you.
How long does scanning take — do users receive their email late?
Short answer: according to the official data sheet, content is checked in under 30 seconds and a clear verdict is returned within 10 seconds on average (Acronis, 2023). This is a critical metric for email security solutions that perform dynamic analysis: the deeper the analysis, the greater the delay — and from what we see in the field, when the delay reaches a level that harms the user experience, the scope of dynamic analysis gets narrowed and protection weakens.
To understand why this metric matters so much, it helps to look at what the typical alternative does. The classic sandbox approach runs the suspicious file in an isolated virtual machine and waits for the malware to exhibit behaviour; because that wait can stretch out depending on the depth of analysis, some deployments deliver the file to the user first, with the verdict arriving later and the message pulled retroactively from the mailbox if necessary. Since those timings vary by product and configuration, we give no comparative figure here. Perception Point's CPU-level approach, in the words of the official data sheet, aims to identify deviations from the normal execution flow at runtime and thereby detect and block the threat at the exploitation stage; the sub-30-second scan and 10-second average verdict values in the data sheet are presented as the result of that design (Acronis, 2023).
The point we pay attention to in the field is this: these are the values stated by the official data sheet, and the actual elapsed time varies with message volume, attachment size and archive depth. During rollout we measure with real traffic in a pilot group and assess latency and the false positive rate together. If your organisation needs to build a service level commitment around these timings, we share the measurement results before the contract is signed.
Exactly what does the pack add to the standard protection in Cyber Protect Cloud?
Short answer: the standard Cyber Protect Cloud subscription covers the endpoint and backup side; the email layer comes with this add-on. The official data sheet lists the capabilities the pack adds under nine headings. The table below follows that list exactly.
| Capability | What it does | Advanced Email Security |
|---|
| Spam filter | Filtering out high-volume unwanted mail | Added by the pack |
| Anti-evasion (recursive unpacking) | Defeating evasion techniques such as an archive inside an archive and embedded objects; content is checked in under 30 seconds | Added by the pack |
| Threat intelligence from six sources | Feeding the detection engines with current attack data | Added by the pack |
| Static signature analysis | Rapid elimination of known malware | Added by the pack |
| Anti-phishing: four URL reputation engines and image recognition | Catching phishing links through both reputation data and page appearance | Added by the pack |
| Anti-spoofing: SPF, DKIM, DMARC | Blocking sender spoofing and domain impersonation | Added by the pack |
| Perception Point CPU-level dynamic detection | Catching files and links with unknown signatures at the exploitation attempt stage | Added by the pack |
| Incident response service | Post-detection investigation and response support | Added by the pack |
| Outbound email scanning for Microsoft 365 | Preventing a compromised account from spreading attacks in the organisation's name | Added by the pack |
The rows in this table are based on the list in Acronis's own Advanced Email Security data sheet (Acronis, 2023). The same data sheet states that on the Microsoft 365 side protection is enabled through API-based provisioning, that rollout takes just a few minutes with no additional configuration required, and that outbound email scanning is performed through the Microsoft 365 API. Because the integration method may differ in mail environments other than Microsoft 365, we examine your configuration and clarify the approach against Acronis's current deployment documentation before committing to anything. The deployment method is the project's first decision, because it determines whether the transition can be planned without disrupting the existing mail flow.
How do email security and backup complement each other in Microsoft 365 and Google Workspace?
Short answer: email security stops the message at the door, while backup lets you come back when you could not stop it. Having both on the same platform is meaningful in the face of data showing that malware was found in 1.47% of Microsoft 365 email backups: in a world where malicious content also leaks into the backup, the point you restore from needs to have been scanned.
On the Acronis side, these two layers combine as follows. Cloud-to-cloud backup for Microsoft 365 and Google Workspace is listed in the official documentation among the capabilities available in the cloud deployment only (Acronis Cyber Protect 16 Web Help). Likewise, anti-malware scanning of Microsoft 365 backups and search within encrypted Microsoft 365 and Google Workspace archives are offered on the cloud side only; those three capabilities do not appear in the on-premises management server column (Acronis Support KB 73376, 2025). Google Workspace protection covers Gmail mailboxes, Calendars, Contacts, Google Drive and Shared drive data; Acronis states that up to 5,000 items per company can be protected without loss of performance (Acronis Cyber Protect Cloud user guide).
For organisations working with on-premises licences, scope additionally depends on the licence edition. According to Acronis's official licensing knowledge base article, Microsoft 365 and Google Workspace workloads are not included in the Standard and Advanced editions.
| Workload type | Standard | Advanced | Backup Advanced | Email Archiving |
|---|
| Microsoft 365 | No | No | Yes | Yes |
| Google Workspace | No | No | Yes | No |
| Workstation | Yes | Yes | Yes | No |
| Server | Yes | Yes | Yes | No |
| Virtual Host | Yes | Yes | Yes | No |
The table follows the workload coverage in Acronis's official licensing knowledge base article (Acronis Support KB 73387, 2026). The practical consequence: if you run an on-premises installation with Acronis Cyber Protect 16 and also want to protect your cloud mailboxes, you need to check whether your licence edition covers these workloads. If you buy your Microsoft 365 subscriptions from us, we bring both sides into a single plan. On the integrity side of the backup, the AES algorithm runs in Galois/Counter (GCM) mode with a randomly generated 256-bit key; that key is encrypted with AES-256 using the SHA-2 (256-bit) hash of the password, and the password is never stored anywhere on disk or in the backups (Acronis Cyber Protect 16 Web Help).
Why is phishing still the most effective initial access vector, and what does it cost?
Short answer: because it targets not a technical flaw but a human being's decision time, and the content produced today is no longer as easy to spot as it once was. ENISA Threat Landscape 2025 analysed 4,875 incidents between 1 July 2024 and 30 June 2025 and identified the leading initial access vectors as phishing (60%) and exploitation of vulnerabilities (21.3%); the most targeted sector was public administration at 38.2%, and 53.7% of the incidents concerned essential entities in scope of the NIS2 Directive (ENISA, 2025).
What usually comes through the door that phishing opens is ransomware. According to Acronis's H2 2025 report, more than 7,600 ransomware victims were publicly disclosed in the second half of 2025; the most active groups were Qilin with 962 victims, Akira with 726 and Cl0p with 517, and the United States led with 3,243 victims. On the cost side, the IBM Cost of a Data Breach Report 2025, which studied 600 organisations breached between March 2024 and February 2025, puts the global average cost of a data breach at USD 4.44 million (down from USD 4.88 million in 2024); the average cost of extortion and ransomware incidents rises to USD 5.08 million when disclosed by the attacker, and 63% of organisations refuse to pay the ransom (IBM & Ponemon, 2025).
None of this means the email layer is sufficient on its own. A message that cannot be stopped at the door must be caught at the endpoint, and if it is not caught there either, it must be possible to roll back to a clean backup. That is why in most projects we position Advanced Email Security together with Acronis Advanced Security + EDR: when an attachment that could not be blocked at the email layer is caught at the endpoint, the incident can be assessed along the attack chain together with the email records. Given that exploitation of vulnerabilities is the second leading entry route, the Acronis Advanced Management add-on, which brings patching into the same console, completes the third link.
How do you choose between Acronis Advanced Email Security, Trend Micro Email Security and FortiMail?
Short answer: the choice depends on which platform you want email security to be part of. Acronis offers email protection as a layer of a backup and cyber protection platform; Trend Micro positions it inside its own threat intelligence and security platform; Fortinet treats email security as a component of the Security Fabric architecture. All three are legitimate choices; the right answer depends on which platform the organisation has invested in and which team will operate email protection.
| Criterion | Acronis Advanced Email Security | Trend Micro Email Security | Fortinet FortiMail |
|---|
| Primary position | Email layer of a backup and cyber protection platform | Email component of the Trend Micro security platform | Email security within the Fortinet Security Fabric |
| Console | The existing Acronis Cyber Protect console; no separate console is opened | Trend Micro management interface | Fortinet management interface |
| Integration with backup | Direct: mailbox backup and email protection on the same platform | No backup component | No backup component |
| Dynamic detection approach | Perception Point CPU-level detection; content checked in under 30 seconds, verdict returned in 10 seconds on average | The platform's own analysis and intelligence infrastructure | Fortinet's own analysis and intelligence infrastructure |
| Typical reason for choosing it | Backup is already in Acronis; protecting email without a separate contract and a separate console | Coherence when endpoint and server security are already managed in Trend Micro | Staying within the same architecture when network security is managed with Fortinet |
We see three patterns in the field. In organisations where security investment is concentrated on the network side and the network team will operate email protection, FortiMail is the natural choice. If endpoint and server security are managed with Trend Micro, Trend Micro Email Security is evaluated so that the email layer stays on the same platform. For organisations using Bitdefender at the endpoint, Bitdefender GravityZone Email Security is positioned by the same logic. Acronis Advanced Email Security stands out in particular for organisations that have already consolidated backup and cyber protection on Acronis, have no dedicated security team and do not want to increase the number of contracts. It is worth noting that these products are not mutually exclusive: email protection can live in one product while mailbox backup lives in another.
KVKK, data residency and rollout: how do we plan an email security project?
Short answer: KVKK (Turkey's data protection law) does not mandate a particular product name; it expects the data controller to take appropriate technical and administrative measures, and in an email-borne incident both prevention and the ability to roll back are part of those measures. The "Backing Up Personal Data" section of the Personal Data Security Guide published by the Turkish Personal Data Protection Authority states that, if data is damaged, destroyed or stolen, the data controller must use the backed-up data to resume operations as quickly as possible; that backup strategies must be developed against ransomware; that only the system administrator should be able to access backed-up personal data; and that data set backups must be kept off the network (KVKK Personal Data Security Guide).
Within that framework, email protection helps at two points: quarantine and detection records produce an audit trail showing which message was blocked and why, while outbound email scanning limits the leakage of personal data through a compromised account. On the data residency side, Istanbul also appears on Acronis's official data centre list (Acronis Cyber Cloud Data Centers); where mailbox backups will be stored is therefore a matter that can be settled at the start of the project. In addition, since September 2024, immutable storage in Governance mode with a 14-day retention period has been enabled by default across all Acronis-hosted storages and all Partner and Customer tenants (Acronis Cyber Protect 16 Web Help).
Our rollout approach consists of the following steps: reviewing the existing email environment and any email security solution already in place; determining the integration method against Acronis's current deployment documentation; auditing SPF, DKIM and DMARC records and completing what is missing; measuring latency and false positives with real traffic in a pilot user group; defining quarantine policies and the user notification workflow; setting up a hardened rule set for high-risk groups such as executives and finance; enabling outbound email scanning; and establishing the reporting calendar. For broader needs around email authentication records, DNS management and integration, our DevOps and infrastructure services come into play.
Let's assess together whether Acronis Advanced Email Security is the right fit for your organisation, taking your existing email environment and backup investment into account. Share your mailbox count, your email provider and any existing security solution, and we will prepare a proposal covering licence scope, integration method and rollout plan. Get in touch via our contact page — Turkish-language technical support and post-deployment operational support are included in the way we work.