5 minutes reading time

Email Security in Holding Structures: The Weakest Subsidiary Puts the Whole Group at Risk

In holdings, intra-group trust is high but security maturity varies by subsidiary. The weakest one becomes the group's attack door. Lateral movement and centralized multi-tenant protection.

The finance director of a holding group with many subsidiaries was shaken by an email from an accounting employee at one of the group companies: the employee, acting on an instruction "from the holding CFO," had made an urgent payment to another group company's supplier. That instruction had never been sent. The attacker had taken over the email account of a small, weakly secured subsidiary, learned the group's correspondence patterns from it, and weaponized intra-group trust.

Holding structures carry a peculiar paradox for email security: intra-group trust is high, but security maturity varies enormously from one subsidiary to another. The result is clear — a subsidiary in the weakest link becomes the attack door for the entire group. In this article we cover the risks specific to holdings, the lateral-movement mechanism, and a centralized protection approach.

 


 

1. The Risk Specific to Holdings: Uneven Security Maturity

 

Under a holding, a mature flagship company with a corporate IT team can sit next to a five-person family subsidiary with no IT at all. For the attacker, this is an opportunity: they target not the best-protected company but the weakest subsidiary. Because within the group:

  • Companies send money to one another routinely (intra-group current accounts, shared procurement).
  • There's reflexive obedience to instructions "from holding top management."
  • An account compromised at one subsidiary looks "familiar and trustworthy" to the others.
  • Email domains may differ, but brand/group affiliation creates trust.

In other words, a holding's security level is the level of its weakest subsidiary, not its strongest.

 

2. How Intra-Group Lateral Movement Works

 

  1. Entry: The attacker takes over a user's email account at a small, weakly protected subsidiary (an old data breach, a weak password, missing MFA).
  2. Reconnaissance: From that account they read intra-group correspondence; they learn who pays whom, in what tone, in what amounts. The holding org chart is already public on LinkedIn.
  3. Weaponizing trust: From the compromised real account, or under a "holding top management" identity, they send an instruction to another subsidiary's finance team. Intra-group trust grants a credence that wouldn't be given to an external email.
  4. Money movement: The target subsidiary, believing it's a "group instruction," skips the usual confirmation steps.

The critical point: a significant part of this attack is internal phishing — sent from a compromised subsidiary account into the group. Traditional gateway architectures can't see internal email because it never visits the external filter. We explained the architectural difference in our API vs Gateway article.

 

3. Field Note: The Two Gaps We See Most in Holdings

 

First: inconsistent DMARC posture. While a holding's flagship company has DMARC set to "reject," the domains of small subsidiaries usually have no DMARC record at all or sit in the ineffective "none" mode. The attacker can impersonate the unprotected subsidiary domain to email both into the group and to external stakeholders.

Second: fragmented visibility. Each subsidiary has its own security tool (if any); there's no holistic threat visibility across the holding. An attack that begins at one subsidiary can progress unnoticed at the others. When there's no single dashboard at the holding level, the attack between the parts is invisible.

 

4. Defense: A Centralized, Multi-Tenant Approach

 

Technology

 

Check Point Harmony Email & Collaboration offers an API-based, multi-tenant model for holding structures:

  • Connects each subsidiary via its own Microsoft 365 / Google Workspace tenant in minutes through the API — the MX doesn't change.
  • Scans inbound, outbound, and inter-subsidiary internal email; makes intra-group lateral movement visible.
  • Provides a centralized dashboard at the holding level to monitor, from a single screen, which subsidiary has which kind of threat.
  • Policies can be defined centrally and applied to each subsidiary, pulling up the "weakest link."

 

Process

 

A standard confirmation protocol — verification through a second channel independent of email — must be made mandatory across all subsidiaries for intra-group money movements and payments framed as "holding top-management instructions."

 

Governance

 

A minimum email-security standard at the holding level (DMARC reject for every subsidiary, mandatory MFA, an additional protection layer) should be defined and propagated to subsidiaries — as a group policy, not one by one.

 


 

Frequently Asked Questions

 

Each subsidiary has a different domain and a different IT team — can it be managed with a single solution?

 

Yes. The API-based multi-tenant model connects each subsidiary via its own tenant but provides centralized visibility and policy management at the holding level. The subsidiaries' independence is preserved while a group-wide protection standard takes hold.

 

Some of our subsidiaries are very small — does separate investment make sense for them?

 

Because the weakest subsidiary is the attack door for the whole group, protecting the small subsidiaries actually protects the flagship company. If the risk is group-wide, the protection must be group-wide too. Licensing scales by user count per subsidiary.

 

How do we obtain group-wide attack visibility?

 

When all subsidiaries are connected to a single management console, a unified threat dashboard forms at the holding level. An attack that begins at one subsidiary and tries to spread to others appears early on this dashboard.

 

Can we measure how much intra-group lateral movement our current protection sees?

 

Yes. With a 14-day monitor-mode trial at a few subsidiaries you choose, we report missed threats — including internal phishing and intra-group BEC.

 


 

What Should You Do Now?

 

If your holding structure has subsidiaries at different maturity levels and intra-group money movements are routine, it's worth measuring the "weakest link" risk.

  1. Free Field Audit: We produce an SPF/DKIM/DMARC report card for your subsidiaries' domains and report your group-wide exposure surface.
  2. 14-Day Check Point Trial (monitor mode): At subsidiaries you choose, without touching existing protection, we measure internal and external threats.

Schedule an intro meeting

 


 

About this article: Kinetik Bilişim is the Türkiye partner of Check Point Software Technologies at the Advanced Partner 2026 level, holding Email, Endpoint & Browser, Mobile, and SASE Solution Specialization accreditations. The author, Kemal Özleyen, is a cybersecurity engineer certified as a Check Point Workspace Security Expert. Field scenarios are shared in anonymized form from cases seen among our holding and group-company customers in Türkiye.