SWISS POST GROUP · SOVEREIGN BY DESIGN
AI Matrix
Platform
Solutions
Switch to OS
Resources
Partner
Company
Financial services · Asset managementEnabling Qapital

Up to 40% more malicious email blocked, before it reaches the inbox.

Advanced Email SecurityFINMA-regulatedManaged~USD 900M AUM
Enabling Qapital
In short

The challenge, the solution, the outcome.

Enabling Qapital Ltd. is a FINMA-regulated Swiss impact asset manager with around 60 employees and close to USD 1 billion under management. As a fully cloud-based, globally active firm, it regularly faces domain impersonation and targeted phishing - and email is by far its most critical attack vector. Advanced Email Security from Open Systems added a proactive filtering layer before messages reach the inbox, intercepting up to 40% more malicious email while keeping false positives low.

The challenge

Despite Microsoft 365 Defender and existing filters, sophisticated phishing - impersonating platforms like DocuSign and LinkedIn, and hidden in PDFs and QR codes - kept reaching the inboxes of this FINMA-regulated, roughly 60-person asset manager, where 80-90% of attacks arrive by email.

The solution

Advanced Email Security from Open Systems added a proactive, AI-powered layer alongside Secure Email Gateway and Advanced Threat Protection, using machine learning and relationship-based communication analysis to catch what pattern-based filters miss.

The results

Up to 40% more malicious email intercepted during the proof of concept, a low false-positive rate despite tighter filtering, and significantly fewer risky messages reaching employee inboxes.

Solutions in play

At a glance

More caught, less risk.

A proactive filtering layer added before the inbox, measured during the proof of concept against the existing Microsoft 365 setup.

40%
More malicious email caught
During the proof of concept, vs. the previous setup
80-90%
Of attacks arrive by email
The company's primary attack vector
Top 5%
In the latest FINMA IT audit
Among the highest-rated institutions assessed
~60
Employees protected
A globally distributed team, ~USD 900M under management
The interview

"A cost factor - until something happens."

We sat down with Christoph Dreher, Executive Management & Partner at Enabling Qapital, to talk through the company's IT security and email security challenges - and how Open Systems enabled a holistic solution.

Christoph DreherExecutive Management & Partner, Enabling Qapital
01

What is your role at Enabling Qapital, and what responsibility do you carry for IT and email security?

As COO/CFO, I'm responsible for several functions, including IT, HR and Finance. In our second year, we made a conscious decision to elevate IT security to the executive and board level - for us, cybersecurity carries the same importance as portfolio management and business development.

Given our international presence, global investments and geographically distributed workforce, IT security is a business-critical factor. It's not just about preventing attacks but about managing the impact of an incident. As an asset manager, we depend on our clients' trust, and that trust has to be reflected in the security of our systems and data.

A security-related incident early in the company's history highlighted how costly it is when security isn't prioritized consistently. Since then, IT security has been firmly embedded at the highest management level. Despite our relatively small size - around 60 employees and close to USD 1 billion under management - we regularly face attacks such as domain impersonation and targeted phishing. No organization today is immune.

At the same time, cybersecurity is largely a matter of mindset. Measures are often seen as a cost factor while their value stays invisible in daily operations - which is why strong executive sponsorship is essential for sustainable investment in security.

For us, 80-90% of attacks originate through email. It is by far our most critical attack vector.
Christoph Dreher, Executive Management & Partner
02

What importance does email security have for your organization, particularly given your global operations?

Email is our primary attack vector. Our endpoints are protected through comprehensive device management, but in practice, 80-90% of attacks originate through email. Ultimately, the deciding factor is always the human element - whether an attack succeeds depends on the user.

Operating internationally increases the risk further, since our communication partners are located across the globe and don't all follow the same security standards. That's why we see inbound email as our most significant entry point for threats.

Our approach has two layers: first, detect and block as many threats as possible before they reach the inbox; second, invest heavily in security awareness training so employees recognize and respond to risk. For us, email security is at least as important as device management.

03

What specific challenges or risks did you face in email security before working with Open Systems?

One defining incident happened shortly after the company was founded, before we'd invested in more advanced cybersecurity measures. An employee's email account was compromised and misused for communication without immediate detection - the attacker attempted to manipulate a financial transaction. We also saw attempts to distribute malware through email. These incidents showed how email can serve as both a direct attack vector and a mechanism for expanding an attack once access is gained.

As a result, we adopted a holistic security strategy: advanced email security to identify threats early, combined with Managed Detection and Response (MDR) and Managed Vulnerability Mitigation (MVM), so we can respond quickly and isolate affected systems when necessary.

In asset management, trust is everything. That is why IT security carries the same importance as portfolio management or business development.
Christoph Dreher, Executive Management & Partner
04

What role do your international offices and markets play in your security strategy?

We treat all our markets as equally risk-bearing. As a fully cloud-based organization - particularly through Microsoft 365 - we don't distinguish between regions. Whether an employee works in Switzerland or Nairobi is irrelevant to our security model.

Our strategy is to establish clear boundaries between internal and external systems while maintaining strict access controls. Looking ahead, we're moving toward a Zero Trust approach, based on the assumption that any system could potentially be compromised and every access request must be explicitly authorized.

05

What prompted you to introduce Advanced Email Security in addition to your existing solution?

Despite existing protection, we saw certain threats still reaching users - attacks disguised as messages from platforms like DocuSign or LinkedIn, and malicious attachments embedded in PDFs and QR codes.

A major limitation of traditional solutions is their reliance on known patterns and threat databases, so new and highly targeted attacks often go undetected. Open Systems' Advanced Email Security provides a significant advantage through machine learning and relationship-based communication analysis: because a large share of our email traffic runs with established business partners, the system can quickly identify unusual behavior within normal communication patterns.

The combination of protection methods - AI-based analysis of attachments, links and QR codes, sender reputation checks, and behavioral analysis - significantly reduces risk. Each message is evaluated against numerous signals and interpreted in our specific organizational context, so threats are identified early, and the system keeps learning and adapting to new attack techniques.

During testing, we saw a substantial increase in the number of potentially dangerous emails detected and filtered out.

06

Why did you choose to take this step with Open Systems?

Beyond technical capability, the quality of the partnership is critical for us. We place great value on trusted relationships and want to keep vendor management as simple as possible.

Open Systems' service - particularly through Mission Control - stands out for rapid response times and a high level of expertise. Unlike some outsourcing models, Open Systems provides around-the-clock access to experienced professionals who can make informed decisions independently.

Regulatory considerations mattered too: Open Systems has an excellent reputation with FINMA and holds relevant ISO and SOC1/ISAE certifications. Having a Swiss-based provider is an important factor for us as a regulated company.

The service provided by Open Systems is outstanding: fast, highly competent, and delivered at a level that is difficult to find elsewhere.
Christoph Dreher, Executive Management & Partner
07

What role did compliance requirements and data sovereignty play?

Compliance and regulatory requirements are central to our business. As a regulated organization, our cybersecurity solutions have to meet the expectations of regulators and auditors - Open Systems' certifications and strong market position significantly simplify both audits and regulatory discussions.

Data sovereignty was another important consideration, carefully assessed as part of our risk analysis. As a Microsoft 365 customer, we operate within a certain level of regulatory complexity, including considerations related to the CLOUD Act. We deliberately rely on Microsoft's enhanced customer agreements for the Swiss financial sector - often called the "Swiss Cloud" - which give us the framework to meet regulatory requirements while still benefiting from cloud technology.

Many organizations see email security as a cost factor, until something happens and the true cost becomes visible.
Christoph Dreher, Executive Management & Partner
08

What insights did you gain from the proof of concept, and what measurable improvements do you expect?

The results were highly encouraging. One key observation: many emails that would previously have been delivered at least to the spam folder were now blocked entirely before they could reach users. Overall, the proof of concept showed approximately 30-40% more emails filtered out compared to our previous solution.

We regularly run phishing simulations, both automated and manually designed, and we know how easily even well-trained employees can be deceived by sophisticated attacks - so minimizing the number of potentially dangerous emails reaching inboxes is essential. Advanced Email Security showed clear strength in analyzing communication patterns and detecting sophisticated techniques, including QR-code-based attacks, while filtering significantly more threats and keeping a low false-positive rate.

We expect a significant increase in phishing detection rates, particularly for targeted attacks and previously unseen threat patterns, while keeping false-positive rates low. A key objective is to quantify how many additional malicious emails are intercepted and track that performance over time - metrics we monitor and review regularly.

09

How would you describe your collaboration with Open Systems?

The partnership is characterized by openness, direct communication and deep technical expertise. Despite our size, we have dedicated contacts in both account management and technical support.

Compared with other providers, we experience considerably faster response times and a much higher quality of support - that level of service creates significant value for us. Overall, we regard the collaboration as consistently excellent.

10

How does the team support you on a day-to-day basis?

Mission Control serves as our primary operational point of contact. Requests and reports, including false-positive cases, are handled quickly and professionally. For us, the most important differentiator is the combination of fast responsiveness and technical expertise.

11

Why would you choose Open Systems again?

Three factors stand out: exceptional service, deep expertise, and technologically advanced solutions. We also value the company's clear innovation roadmap and its focus on the security challenges that matter most.

12

What insights did you gain from the FINMA audit, particularly regarding your security posture compared to other organizations?

The outcome of our latest IT audit provided strong confirmation that our security strategy is on the right track. Being ranked among the top 5% shows that we don't just meet key requirements - we achieve an above-average level of security in critical areas.

At the same time, this strengthens our clients' confidence that their data is protected to the highest standards. IT security has become an integral part of our quality commitment and customer trust proposition.

13

What advice would you give to other organizations?

Email security should be regarded as one of the most important pillars of any cybersecurity strategy. It extends far beyond traditional spam filtering and has a major impact on an organization's overall risk profile.

Companies should be willing to invest in preventive controls rather than relying solely on standard security solutions - measures that filter threats before they reach users are essential, in our view.

Our experience also shows that even established solutions such as Microsoft 365 Defender don't reliably catch every attack. A layered security approach that combines multiple technologies is critical to reducing risk sustainably.

Go deeper

The thinking behind the move.

Why email remains the top attack vector for regulated financial firms, and what real protection looks like today.

Same problem, different logo?

Tell us what you run today and we will tell you honestly what changes.

Book a demo All customer stories
Already a customerEverything you use today keeps running.