phishing
Email Security Teams Are Drowning in Alert Triage
2026-06-24

Most companies have poured real money into email security, and yet phishing, business email compromise and account takeovers still chew through analyst hours like nothing else on the desk. The detection side is largely fine. Alerts fire. Users report things. The bottleneck is everything that happens after.
Picture the routine. A suspicious email lands in the abuse queue. An analyst opens it, checks the sender, looks at recent logins for the recipient, sees what they clicked, pivots through two or three other consoles to corroborate, then decides whether it's real. Five to ten minutes, give or take, for a single report. Now multiply by a few hundred reports a week.
What you get is predictable. Backlogs build. Fatigue sets in. And the genuinely nasty incidents, the ones where someone has actually handed over credentials or wired money to a fake supplier, end up sitting in a queue behind a stack of newsletters and marketing emails that a well-meaning employee flagged as phishing.
The webinar
BleepingComputer is running a session on 8 July 2026 with Dan Nickolaisen of Abnormal AI and Eric Danneker of Novant Health on exactly this problem. The pitch is behavioural AI: software that learns what normal looks like for a given user and mailbox, then automates the triage work so analysts only see the messages that warrant a human eye.
That is a familiar pitch by now, and the room for argument is mostly about how well it works in practice. Worth a look if you run an inbox abuse queue.
The bigger point
Whether or not behavioural AI is the answer for your environment, the underlying maths is hard to argue with. The volume of email-borne attacks is not trending downward. The supply of analyst hours is finite. Throwing more humans at manual review has a ceiling, and most mature teams have already hit it.
Two things tend to separate the organisations that cope from the ones that don't.
- Fewer dodgy emails reach a person in the first place. Layered filtering, sensible DMARC enforcement, and a hard look at which third-party senders actually need inbound trust all reduce the raw volume hitting the queue.
- The people who do see one know what to do. A workforce trained to spot the patterns, report cleanly, and not panic-click is the cheapest force multiplier a security team has. It also reduces the noise of well-intentioned but misdirected reports, which is half the triage problem in the first place.
Tools will keep getting better at the triage layer. That is a good thing. But the input side of the funnel, the sheer number of attempts and the human judgement calls in front of them, is where most of the leverage still sits. A queue that is half the size is a queue an analyst can actually work.