business

Verdict

Submitted 5/15/2026, 2:28:58 AM · Completed 5/15/2026, 2:31:54 AM

6.5
pivot
The idea

M365, Anti-Malware policy issues

Pain point
Blocking htm/html attachments in anti-malware policies disrupts user workflows and causes IT release requests for legitimate files.
Who has this problem
IT administrators managing email security policies
Contradiction (TRIZ)
Need to block malicious htm files but allow legitimate ones from Apple Mail and B2B systems
Ideal final result
Automatically distinguish between malicious and legitimate htm files without manual intervention
Suggested solution
Implement a machine learning-based email attachment classifier that differentiates between phishing htm files and legitimate ones from Apple Mail or B2B systems, with automated policy enforcement and minimal IT intervention.
Show original source text →
Hi, So I've started blocking htm and html attachments, because they are used in phishing mails and a colleague recently fell into this trap (.js was loaded, looking like a OneDrive page and then it went on from there). But a lot of mails we receive, have mail history and signatures attached as htm files, along side a lot of pretty much empty htm files. This looks to be Apple mail on iOS and maybe MacOS. All mails caught in this Anti-Malware policy, needs to be released by IT, hence IT gets a lot of release requests and the users workflows are interrupted. We aim to release quickly, but this causes some friction. Customer facing support is getting hit hard here, because a lot of customers uses iPhones and the Apple Mail client. But then there is the B2B customers who auto attach htm files, because... I have no clue actually, maybe old ERP systems? How do you all handle this?
TRIZ inventive level: 3/5· Principles: parameter changes, mechanical interaction
Synthesis verdict
**Pivot**: The idea of developing a solution to differentiate between legitimate and malicious HTM/HTML attachments in emails has potential, but it requires a clearer path to defensibility and a more robust revenue model. The market pain point is real, with enterprises experiencing friction due to false-positive release requests and user workflow interruptions. However, the competitive landscape is crowded, and the solution's effectiveness is heavily dependent on third-party behaviors, such as Apple's decisions regarding Mail client updates. A pivot could involve focusing on a more specific niche, such as developing a solution for a particular industry or integrating with existing email security platforms.

Strengths

  • Clear market pain point: enterprises experience significant friction due to false-positive release requests and user workflow interruptions
  • Technically feasible: leveraging existing machine learning libraries and focusing on a simple, rule-based initial classification system can develop a viable v1
  • High willingness to pay: enterprises are willing to spend $5-10/user/month for a plugin that can intelligently filter out malicious HTML attachments

Weaknesses

  • Dependence on third-party behaviors: the solution's effectiveness is heavily dependent on Apple's decisions regarding Mail client updates
  • Low perceived value by cost-sensitive customers: many individuals and smaller businesses may not be willing to pay for a solution to a problem they might not perceive as critical
  • High churn risk: the primary pain point might not be fully alleviated if the solution only partially addresses the issue or introduces new complexities

Best angle

Develop a context-aware allow-list that distinguishes legitimate corporate .htm attachments from phishing-laden ones, with seamless release for Apple Mail users, and integrate directly with Apple Mail's attachment handling to reduce IT load and improve user experience.

Panel verdicts

Viability

meta/llama-4-maverick-17b-128e-instruct

8.0

A viable v1 can be built by leveraging existing machine learning libraries and focusing on a simple, rule-based initial classification system.

The idea is to develop a solution to differentiate between legitimate and malicious HTM/HTML attachments in emails, reducing the number of false positives that require IT intervention. A solo or 2-person team can potentially build a basic version (v1) within 4-12 weeks. The task involves analyzing email attachments, possibly using machine learning or rule-based approaches to classify them as benign or malicious. The technical complexity lies in developing an accurate classification system that can handle various types of HTM/HTML files and understand the context in which they are used. However, leveraging existing libraries for HTML parsing and machine learning can simplify the task. The team would need expertise in natural language processing, machine learning, and possibly email protocol specifics. The development process would involve data collection, feature engineering, model training, and integration with existing email systems. While challenging, a focused 2-person team with the right skills can achieve a functional v1 within the given timeframe by prioritizing the most critical features and simplifying the initial model.

Monetization

mistralai/mistral-medium-3.5-128b

8.0

Automating the sanitization of benign .htm attachments solves a high-friction, high-cost problem for IT and support teams.

The problem is concrete: Apple Mail and legacy ERP systems generate .htm/.html attachments that trigger anti-phishing policies, creating friction for IT and support teams. The revenue model could target enterprises with a SaaS solution that automatically sanitizes or converts these attachments to safe formats (e.g., PDF, plaintext) before they hit the mail server, eliminating manual release requests. Pricing could be per-user (e.g., $2-5/user/month) or per-domain (e.g., $500/month for unlimited users), with tiered plans based on volume. Channels include direct sales to IT/security teams, partnerships with MSPs, and integrations with email security vendors (e.g., Proofpoint, Mimecast). Gross margins would be high (80%+) due to low COGS (cloud-based processing). Unit economics improve with scale, as the cost to sanitize each attachment is near-zero. The key risk is adoption—companies may prefer to tweak existing policies rather than pay for a new tool. However, the pain point (IT overhead, user friction) is acute enough to justify spend, especially for customer-facing teams.

Risk

nvidia/llama-3.3-nemotron-super-49b-v1

2.0

Dependence on unchanged third-party behaviors (Apple, B2B ERP systems) and low perceived value by cost-sensitive customers make sustainability highly unlikely.

The proposed venture faces insurmountable challenges due to its reactive nature and dependence on third-party behaviors. Firstly, **regulation** is unlikely to be the killer within 6-12 months as the issue is more about compatibility and user experience rather than violating existing regulations. **Platform risk** is high because the solution's effectiveness is heavily dependent on Apple's decisions regarding Mail client updates, which could render any workaround obsolete overnight (e.g., changing how attachments are handled). **Churn** will be significant because the primary pain point (IT and user frustration with release requests) might not be fully alleviated if the solution only partially addresses the issue or introduces new complexities. However, the most immediate killer is **no-budget customers**; many individuals and smaller businesses (especially B2B clients with 'old ERP systems') are unlikely to pay for a solution to a problem they might not perceive as critical or might blame on Apple/their email client rather than seeking a third-party fix. The venture's viability hinges on convincing a broad base of users to pay for a fix to a problem many will work around (e.g., by changing email clients or settings) or tolerate as a minor inconvenience.

Competition

nvidia/nemotron-3-nano-omni-30b-a3b-reasoning

7.0

A nuanced, context‑aware allow‑list that distinguishes legitimate corporate .htm attachments from phishing‑laden ones, with seamless release for Apple Mail users, offers the most defensible differentiation.

The market already offers broad email security gateways (e.g., Proofpoint, Mimecast, Cisco IronPort) and native platform controls (Microsoft Defender for Office 365, Google Workspace Security) that block file types like .htm/.html to stop phishing. These solutions typically apply blanket rules, which creates the exact friction described—IT receives many release requests and users experience workflow interruptions, especially on iOS Apple Mail where .htm signatures and history files are common. A new entrant could differentiate by replacing the static blocklist with a context‑aware policy engine that uses content signatures, machine‑learning classification, and user‑feedback loops to distinguish benign corporate .htm attachments from malicious payloads. Integrating directly with Apple Mail’s attachment handling and providing a one‑click, contextual release button (or automated release for trusted B2B sources) would reduce IT load and improve user experience. However, durability is uncertain: large vendors can quickly add similar whitelisting capabilities, and sophisticated phishing campaigns may evolve to hide malicious code inside apparently benign .htm files, forcing the entrant to continuously refine its detection models. The competitive moat will depend on the quality of the contextual analysis, the speed of updates, and the ability to integrate tightly with Apple’s ecosystem, which are non‑trivial challenges.

Market

qwen/qwen3-next-80b-a3b-instruct

8.0

Enterprises don't need to block HTML attachments — they need to intelligently trust the ones that are harmless, and Apple Mail's default behavior is creating a costly, scalable false-positive crisis.

There is a clear, measurable pain point affecting enterprise IT teams and customer support functions, particularly in organizations with high volumes of iOS Apple Mail users and B2B clients using legacy systems. The problem isn't theoretical — it's operational: IT teams are overwhelmed with false-positive release requests, user productivity is disrupted, and customer support is bogged down by explainers and workarounds. The audience is large: enterprises with 500+ employees using Apple Mail (iOS/macOS) are widespread, especially in industries like finance, legal, healthcare, and consulting where mobile-first communication is standard. Many B2B vendors still auto-generate HTML attachments via outdated ERP/CRM systems (e.g., SAP, Oracle legacy integrations), creating systemic noise. The unmet need isn't just blocking malicious HTML — it's intelligent filtering that distinguishes benign, structured email history/signature HTML from malicious payloads. Current solutions (block-all, manual releases) are blunt and costly. A SaaS product that analyzes attachment context (signature patterns, sender reputation, embedded script behavior, MIME structure) and auto-approves safe HTML while flagging only real threats would save hours per week per IT team. Enterprises already spend heavily on email security (Proofpoint, Mimecast, etc.); this is a gap in their existing stack. The willingness to pay is high — a $5–10/user/month plugin for major email security platforms would be adopted rapidly. The market is real, the friction is quantifiable, and the solution is technically feasible with ML + rule-based heuristics.

Synthesized by meta/llama-3.3-70b-instruct · 14.4s