Take that last one. Picture a finance clerk at a 500-person company in Hyderabad. An email arrives from a supplier the company pays every month. It says the supplier has changed banks, and asks for this month's payment to go to a new account. There is no attachment and no strange link. If the clerk pays, the money goes to the attacker.
Attacks like these are called phishing: fake messages built to trick a person into giving away a password or money. When the fake message pretends to come from a boss or a supplier to get money moved, it is called business email compromise, or BEC. Either way, the attacker's target is a person, not a machine. So the defence has to sit where the person is, which is the inbox.
This Market Segment is about the companies that sell that defence. Their buyers are the IT security teams of other companies. Email is one of the most common ways attacks begin, so this Market Segment comes first in Industry Vertical 4, Cybersecurity.
Every company named here has posted software engineering jobs in India. Famous companies that don't actively hire software engineers in India are left out.
The industry had three ideas for stopping these emails, roughly in this order. Each one is a sub-segment:

Keep reading, free
Three more sections are on this page: The gateway in front of the inbox, Reading the mail the way a person would, and Training the person. Sign in to read them here, in full.
Continue with Google- The gateway in front of the inbox
- Reading the mail the way a person would
- Training the person
Take the fake invoice from the start of this Market Segment. If the company uses an email gateway, the invoice reaches the gateway first. Here, a gateway means a mail filter, not a payment gateway. The company sends all its incoming mail to the gateway company's servers by changing a DNS setting called the MX record. The gateway checks each message for known malware, bad links and forged senders. It passes on only the ones it finds safe.
The gateway is the older product, and still the bigger business. The companies that built it have all grown into the things a gateway naturally touches:
- archiving the mail
- training the people who receive it
- protecting chat tools like Microsoft Teams and Slack, which now carry as much work as email does
Archiving matters because regulated firms, such as banks and stockbrokers, must keep a copy of their staff's email for the regulator. The gateway already sees every message, so it can keep the copies.
One piece of this business protects the company's name rather than its inbox. It is called DMARC. DMARC is a standard that lets a company publish a rule for every mail server in the world: only these senders may send mail from our domain. A tool to manage DMARC is how a bank stops strangers sending mail in the bank's name. So the gateway guards the company's own inbox, and DMARC guards the company's name in everyone else's.

Back to the fake invoice from the start of this Market Segment. It is simply a believable request from a believable address. The address is one letter off, but the attacker really owns that look-alike domain. The mail truly comes from the domain it claims, so DMARC has nothing to catch. And a gateway built to scan for malware sees nothing wrong.
A newer idea came once companies moved their email to Microsoft 365 and Google Workspace, the business versions of Outlook and Gmail. The newer companies do not sit in front of the mailbox. They connect to it through Microsoft's or Google's API. From there, they build a profile of how every person in the company normally writes, who they write to and who they pay. Then they flag the message that breaks the pattern. Here, that is a first-time sender asking for money to go to a new bank account.
It also catches a harder case: mail sent from a colleague's real account after an attacker has taken it over. This is called account takeover.
One company here works outside the inbox instead. Think of the first email from the start of this Market Segment, the one that links to a fake login page.
Generative AI, the kind behind ChatGPT, now writes phishing mail without the spelling mistakes that used to give it away. Defenders use the same kind of AI to read the tone and intent of every message. Abnormal AI is the company in this Market Segment built for that contest. The gateway companies are adding the same detection to their filters.
Back to the fake invoice from the start of this Market Segment. Whatever the filters catch, some mail gets through. Then the last defence is the clerk who pauses before paying and phones the supplier to check. Training employees to pause like this is called security awareness training.
One company here works on a different answer instead: sending sensitive documents without using email at all.
Who these companies hire, and for what, is on What cybersecurity hires for.