KnowBe4 has finalised its acquisition of UK-based Egress, a provider of intelligent email security solutions focused on outbound threat protection and behavioural-based risk mitigation. The deal, announced on 9 July 2024, expands KnowBe4’s portfolio beyond security awareness training and into dynamic, policy-driven email defence, particularly targeting the growing risk of data loss and outbound email threats.
Terms of the transaction have not been disclosed, but the move clearly signals KnowBe4’s strategic ambition to evolve from a training-first vendor into a more comprehensive platform for managing human-layer risk across the email threat landscape.
Core Capabilities: What Egress Brings
Egress is best known for its adaptive email security platform, which uses AI and contextual analysis to prevent data loss, misdirected emails, and phishing attacks. Its flagship products include:
- Egress Prevent – real-time detection of potential outbound email mistakes, such as sending sensitive information to the wrong recipient.
- Egress Protect – secure email encryption with user-level controls.
- Egress Defend – behavioural-based anti-phishing designed to stop advanced threats by analysing intent and content.
This complements KnowBe4’s focus on human behaviour but extends its capabilities into real-time intervention rather than post-training awareness. It also gives KnowBe4 an operational foothold in email encryption and DLP (Data Loss Prevention), areas previously outside its core remit.
Industry Context: Expanding the Human Layer
The acquisition reflects a growing market consensus: tackling the human layer requires more than education, it demands real-time enforcement and intelligent automation. KnowBe4, long dominant in the security awareness training (SAT) sector, has increasingly faced pressure to prove its training translates into measurable threat reduction. While SAT remains foundational, CISOs and compliance leaders are now prioritising solutions that can mitigate risk at the point of action, not just in a simulated environment.
This mirrors moves by other players: Proofpoint has expanded its threat protection with adaptive controls; Mimecast’s recent Elevate Security acquisition similarly focused on behavioural risk insights; and Microsoft has continued to develop integrated compliance and DLP features across its M365 stack.
Strategic Fit and Market Implications
Egress fills a critical functional gap for KnowBe4, allowing it to operationalise human risk insights through automated defences rather than relying solely on behavioural change. This could prove a compelling value proposition in sectors where regulatory scrutiny around data handling and email governance is high particularly finance, healthcare, and legal services.
Additionally, Egress brings a significant UK and European customer base. This gives KnowBe4 stronger geographic reach and regulatory alignment (especially in GDPR-centric markets), positioning it to compete more directly with European vendors such as Tessian, Clearswift, and Hornetsecurity.
Why This Matters to the Email Ecosystem
For the email industry, this deal signals a new phase in the convergence of training, behavioural analytics, and technical enforcement. The email threat surface is increasingly shaped by users’ outbound behaviours accidental data leakage, credential sharing, and misaddressed emails remain high-frequency, high-risk events.
This acquisition offers the potential for a more integrated response: users are trained, but also monitored and supported in real time with intelligent prompts, encryption policies, or automated controls. If executed well, this could reduce both compliance risk and operational overhead for enterprise security teams.
However, it also raises competitive stakes. Email security vendors with legacy DLP or encryption tools may face pressure to modernise their offerings with behavioural context and AI-powered decisioning. Conversely, SAT providers may need to prove their models can evolve into more proactive frameworks if they wish to remain relevant in the broader cybersecurity stack.









