Malicious email detection up 20%.
Spam cut by 20%.
Tessian replaced its rules-based email security engine with machine learning — catching more real threats, filtering more spam, and scaling to 50,000 requests a minute in production.
email detection
spam volume
per minute
in LLM research
Client
Tessian, a global cybersecurity firm focused on email security.
Goal
Move email threat detection off static rules and onto machine learning — catching more phishing and impersonation attempts, cutting false positives, and reducing the manual work needed to keep detection rules current.
Static rules couldn’t keep up with the threats.
Tessian’s detection system ran on rules. As email volume and complexity grew, the rules couldn’t scale with it. Sophisticated phishing, impersonation attempts, and constantly evolving threat patterns slipped past a system built to match known patterns, not adapt to new ones.
The rules also generated too many false positives, frustrating users and creating extra work. And every new threat pattern meant another rule to write and maintain by hand — a manual workload that only grew as attackers got smarter.
Three constraints were non-negotiable:
- A rules engine that couldn’t scale with email volume
- Sophisticated phishing and executive impersonation slipping through
- High false positives and constant manual rule maintenance
A machine learning stack, built for scale.
The detection system moved from rules to machine learning. CatBoost models, fed by Spark preprocessing pipelines, took over malicious email detection and lifted accuracy by 20%.
Twenty percent more threats caught, twenty percent less spam, and the whole thing runs at 50,000 requests a minute.
Fine-tuned large language models handled email topic classification, filtering out irrelevant email and cutting spam by 20% — a change that also improved sales team efficiency by keeping their inboxes cleaner. A separate transformer-based model was built specifically to catch senior executive impersonation attempts, one of the hardest threats for a rules-based system to spot.
Everything runs on AWS SageMaker, scaled to handle 50,000 requests per minute — fast enough for real-time threat response in production.
The detection numbers moved — and so did the business case.
Detection got sharper, spam dropped, and the system now runs at production scale without buckling under request volume. Beyond the immediate numbers, the work opened the door to deeper email body text analysis and made the case — with executive backing — for further investment in LLM research.
* Case studies reflect work undertaken by our Heads of AI either during their tenure with Head of AI or in prior roles before they were part of the Head of AI network; they are provided for illustrative purposes only and are based on conversations with our Heads of AI.
More case studies.
Your biggest pain point.
Fixed in 14 days. 50% off.
This started with one conversation. Book a 30 minute brainstorm call — we’ll plan your first AI project together and issue your 50% discount code. No payment today.
*Case studies reflect work undertaken by our Heads of AI either during their tenure with Head of AI or in prior roles before they were part of the Head of AI network; they are provided for illustrative purposes only and are based on conversations with our Heads of AI.