Security teams have gotten better at phishing. Handling time per incident is down 16%, to 23.2 minutes. The cost of dealing with an individual phishing email has fallen 12%, to $27.51. By any reasonable measure, that is progress.
And yet the total bill went up anyway. According to The (Higher) Business Cost of Phishing, research IRONSCALES conducted with Osterman Research across 128 security professionals, phishing now consumes 36.5% of security team hours, up from 33.5% in 2022, and the annual cost per security analyst has climbed 13.6% to $51,948. Efficiency gains are linear. Attack volume is not, and attackers are the ones with a hand on the dial.
Expert Insights sat down with Steve Malone, Chief Product & Strategy Officer at IRONSCALES, an email security platform that integrates natively with Microsoft 365 and Google Workspace. Malone has spent over 20 years in cybersecurity and product leadership, including more than eight years at Mimecast and a spell as VP of Product at Egress, and is a named inventor on five U.S. patents.
In this interview, Malone discusses what separates Phishing 3.0 from the attacks that came before it, why the red flag checklist and callback verification advice no longer hold, how IRONSCALES uses OSINT-driven red teaming agents to harden detection before an attack lands, and the deepfake threat now surfacing in recruitment pipelines.
Listen to the full episode on the Expert Insights Podcast:
Q. You’ve been in email security for the best part of two decades. When you look at the phishing threat today versus even three or four years ago, what’s different, and what are the same problems accelerated?
When you say 20 years, that sounds terrifying, but unfortunately or fortunately, it is true. I’ve been working within the field of cyber, and especially email security, for a very long time. I’ve seen the market evolve, I’ve seen the attack surface evolve, and I’ve seen the way vendors approach that attack surface and that threat landscape evolves. When I look at the threat landscape, I can frame it in three ways. Email is still the primary channel of attack for any organization. The people within the organization are the biggest risk. But agents and the use of AI are what I would class as the new risk frontier.
Email as a technology has not moved on greatly in the last 20 plus years, which means the attack methods haven’t really evolved either. The goals of the attackers haven’t evolved. They’re looking for credentials, they’re looking to elicit a payment, they’re looking for some kind of foothold that they can use email to get within the organization. The targets haven’t really moved either. Most email attacks are based on attacking a person’s judgment. It’s the people using email, not the mail server.
What has changed is speed and quality. The AI revolution over the last couple of years has absolutely revolutionized productivity, but it has also revolutionized the way attackers work. Before AI, it was rare to find an attack that was high quality and very convincing. It took a lot of manual research. Now we’re in a situation where it costs pennies to create very hyper-realistic attacks, to scale those, and to target multiple organizations and many employees.
And all of the old red flags have disappeared. People used to talk about looking for bad grammar, odd phrasing, generic sign-offs, generic greetings. All of that has now been removed. AI has polished all of those pieces out of these attacks. Attackers are using AI to probe and then to launch very personalized, hyper-realistic attacks. That’s really the big change.
Q. Your new business cost of phishing report found an almost counterintuitive point: teams are handling each phishing attack faster than ever, yet phishing is costing them more. What does that tell us about the way most organizations are approaching the problem?
That was our Osterman Research report. We surveyed 128 security professionals at organizations of between a thousand and five thousand employees, so fairly decent size. We benchmarked against the first report we did with Osterman, which was back in 2022, and we did that because 2022 was before ChatGPT came into the world. So, it was a nice ‘before and after’ with the same questions.
What we found was that security teams have become faster. The handling time per incident actually fell. The cost per phishing email fell. Those are gains. But what was interesting was that the total bill went up anyway. Phishing now consumes, according to our report, 36.5% of security team hours, and that’s up from just over 33%.
The reason we saw was that efficiency gains are quite linear, but volume growth is not. So, even though the unit cost fell, the volume of attacks rose much, much faster. And this is really the challenge. Attackers control the volume dial on these attacks, and because the barriers to entry for creating these attacks have fallen, attackers can create much more realistic attacks at much higher volume. Everybody in the security world has got faster, but attackers have got faster at a faster rate. You can’t really win on cycle time when the adversary is the one that is setting the volume. So, the way we interpret this is that the right approach is actually reducing how many incidents reach a human security professional in the first place, rather than trying to reduce the time per incident. If we can have agentic tooling and agents getting to these attacks before the human needs to review them, that balances out that disparity.
Q. IRONSCALES frames the current era as Phishing 3.0. What does that actually mean for a security leader, and why do the defenses that worked in the last era start to break down?
When we talk about Phishing 3.0, we’re essentially talking about the evolution of the way attackers use email to breach organizations. Think about it in the simplest terms, which is 1.0, 2.0 and 3.0, using terminology that IT professionals are very used to.
The first wave of phishing was really things like bad content. Going way, way back, when emails had an infected attachment or a weaponized attachment, maybe an executable file attached to the email. That moved on to things like malicious links being used in emails, and even Microsoft Office files being weaponized through the use of unsafe macros. But all of that 1.0 phishing was essentially reliant on there being something within the email that would download a piece of ransomware or direct a user to an external website.
Then the phishing world evolved. Phishing 2.0 was the evolution where attackers realized that vendors were getting better at blocking emails with attachments, or with links, or with any kind of executable content. That was where these attacks moved on to things like Business Email Compromise (BEC), impersonation attacks, especially of senior execs, and attacks that used social engineering rather than code within the emails to persuade users to take unsafe action. “Please can you send me the payroll details for these individuals.” “I’m the CFO, I really need to make this payment, but I’m out of the office, so can you make this payment for me? Here are the details.” All of those attacks rely purely on persuasion, and they were harder to detect.
What we’re seeing now is this era of Phishing 3.0, which is essentially the evolution of all of those attacks. It has come about because of AI, but also the framing of these attacks as multi- channel. Email attacks used to be very focused on email only. We’ve seen an uptick in both speed and quality of attacks, but we’ve also seen all of these attacks becoming multi-channel or multimodal as well.
What that means is that a single campaign can start with email, can initiate an account takeover, can allow an attacker to move into a collaboration tool like Microsoft Teams, and then use the access they have within Teams to deploy a deepfake persona, either voice or video, to again persuade people in the organization to take unsafe actions. So, really moving across the systems that people rely on. The reason that the old type of defenses break is that there is no content to inspect now. We don’t have executables within mails, there are no attachments, and email reputation and signature models aren’t able to keep up with these high-powered AI-generated attacks. The other piece, going back to how I framed the threat landscape earlier, is that if you were attacking a human, then that assumed there was some kind of attacker error or human error. We historically trained people to spot mistakes within emails. But with attacks becoming more realistic, that has also become more difficult.
So, essentially, for security leaders, the response model shifts away from purely blocking to detect and respond, but now moving forwards to being able to preempt attacks. You need to know what an attack designed for your specific organization looks like before it arrives.
Q. Historically we would teach end users to spot the red flags in an email, or to trust a voice rather than just text. Do you think we’re having to move away from that user training, or is it still an important piece within the overall solution?
I think it has a place, and the security awareness and training market has itself evolved greatly over the last seven or eight years, moving away from purely training-based offerings to talking about secure behavior management or human risk management. But essentially, the way that we think about making humans secure really needs to change.
You mentioned that whole red flag checklist. In the old days we taught people to look for typos within an email. We asked them to look for a sign-off that maybe wasn’t familiar, so “Stephen” rather than “Steve” as an example, or a sense of urgency. All of those things were the artifacts of very basic and cheap attacks.
We also used to give advice, and when I say we, I mean the security industry, that you should verify. So, if you receive an email asking you to transfer a million dollars, pick up the phone and verify that. But again, that assumes that the attacker hasn’t already put that into the attack framework and is not using a deepfake, for either voice or video, to scam you when you make that verification call. So even that longstanding advice is now exploitable. As part of the survey work that we’ve done, we’ve done a lot of work on deepfakes, and our stat is that 62.5% of respondents say that deepfake attacks are already being disruptive in their organizations. So, this is a very rapidly emerging attack vector.
Going back to what I was saying earlier, the way that we asked people to verify trust now really becomes one of the least verifiable ways of trusting. Pick up the phone or jump on a call with somebody isn’t now trustworthy. What’s interesting is that the social engineering element of this hasn’t really changed. Some of those things like pretext, authority and urgency still give context. But the challenge is that AI has made the delivery of those things completely flawless. That’s really the problem.
So, when we’re thinking about how we teach our end users to be secure now, rather than saying you need to spot the fake, what we need to be telling users is that you need to verify the process that you’re being asked to undertake in a much more robust way. Call back on a number that you have from your own records, not the one that you’re seeing in the email that has been sent to you.
Organizations also need to think in a more procedural way, at a business level, about how they handle certain high value processes. As an example, for large transactions, organizations need to think about who has the authority to make bank detail changes, credential resets, wire transfer approvals, requests for HR data. What is the business process, and who is involved in that process? The control for this shouldn’t be reliant on somebody noticing that something feels wrong. There should be a defined process for anything high value relating to data or money within the organization.
Q. Thinking about all of those challenges, the extreme high volume of attacks, the flawless AI-generated content and deepfakes, and the cross-channel attacks: what does IRONSCALES do differently from the defenses most organizations already have in place?
The way that organizations think about email security products has changed massively over the last 20 years, from on-premise Exchange servers with on-premise email security appliances and antivirus appliances and spam appliances, moving through the era of secure email gateways consolidating all of those services, and then consolidating those services into the cloud. And then Microsoft 365 and Google really expanding their core platforms, making secure email gateways less relevant because they add layers of additional cost and additional functionality duplication.
So, the ecosystem has changed, and we fit into the category of native API. We are natively API integrated into either Microsoft 365 or Google. The benefit there is that the organization doesn’t need to change their MX record. There isn’t a gateway, there are no agents to install, so we’re very fast and easy to install. And most importantly, we run alongside what the organization already has in place. So, if they have Microsoft 365 and a secure email gateway, we provide defense in depth. If they have Microsoft 365 plus Defender and no secure email gateway, we can also provide a layered set of defense in depth. From a deployment point of view, we sit right in the middle of that layer of flexibility.
Our detection approach is very AI native and AI-first. Rather than relying on signatures and policies, our adaptive AI essentially builds a communication baseline, a social graph for every user. The question that we ask is: is this normal communication for the relationship that this person has, rather than is this single email malicious? That’s how we catch BEC. It’s looking at communication chains rather than individual mails.
Going back to what we were talking about earlier, about security teams actually having more to deal with, we address that with our Agentic Virtual SOC. What we try to do is handle as much of the remediation as possible without having humans involved. We want to take away the workload from SOC teams and from security professionals. That drops the response time down, and it’s how we balance out that mismatch of statistics that we saw in the report.
We also have a set of agents that really help to bring in the preemptive layer that I talked about earlier. We have a red teaming agent, and this is one of our most exciting pieces of innovation over the last year. The red teaming agent essentially researches your organization on your behalf using external data sources, using things like OSINT. Then the agent virtually attacks your instance of IRONSCALES, works out if there are any weak points, and then we preemptively harden the defenses for your organization based on what that agent has found. So, rather than relying on one detection stack for all customers, this agent is essentially making hyper-personalized detection for individual companies.
The other thing that makes us important in the industry is that we’re a consolidation point. We’re focused on detection, we’re also focused on account takeover, and we’re focused on human risk management through the lens of security awareness and training, DMARC, encryption, and deepfake protection. So, we’re essentially filling in the gaps where those underlying platforms are weak. Where Microsoft or Google are not strong, we fill the gaps, we augment those platforms.
Q. You said earlier that the people inside the organization are the biggest risk. Where does security awareness training fit into that picture, and what are you doing differently there?
People are users of email, and it’s the people in the organizations who are making mistakes. It’s very easy to point the finger of blame at people within organizations, but ultimately it’s our responsibility to help make people as cyber aware as possible. But those old methods aren’t working.
If you think about the classic approach to security awareness and training, an organization would create a very generic phishing testing template, and they would send that individual mail out to everybody in the organization. The same mail for all the users. Most of the time, those very generic templates were something that would maybe be roughly applicable to the organization, maybe not particularly realistic, or maybe not relevant to everybody in the organization, which meant that people took nothing from them.
The right way to approach this now is essentially to use AI, and again we have an agent to support this, to create hyper-personalized training on a per user basis. Using the technology that we have with our red teaming agent, we’ve kind of reversed that. The agent is doing the same research on behalf of our customers. That agent essentially uses OSINT and external data to research users within the organization, and then enables you to send very personalized attacks to each user individually.
That cuts down the time that security teams need to spend on security awareness training, but it also increases the efficiency of those attacks. We’re sending the right simulation to the people who actually have that exposure, based on their role, based on their behavior, and based on their presence out in the wider internet landscape.
Q. Let’s talk about the deepfake protection piece. How does that work?
This is one of the most exciting products that we have in the portfolio. And one thing to be very aware of is that it links very tightly with our other products. The main reason for that is because we’re protecting the platforms that our customers use. If you think about an organization using Microsoft 365, they’re sending and receiving email through that platform, but they’re also very likely using Microsoft Teams for chat and for video collaboration. And now that it’s becoming much easier for Teams to be used with external parties, both for video, voice and chat, it opens up that part of the attack surface.
If you think about what I was saying earlier, that attacks are multi-modal or multi-channel, an attack can start in email, but that email can attempt to gain credentials, essentially an account takeover attack. If that account takeover attack is successful, it’s very likely that the attacker will gain access to the Microsoft 365 user account and then move laterally into other applications, Microsoft Teams being a great example. So, Teams and video form part of that attack chain.
What we have built is the ability to do real time identity verification of users in Teams meetings. It’s both visual and audio analysis, and that’s created against a learned baseline. We do automatic profiling, baselining the people that are in those meetings based on both audio as much as video. It’s far easier to spoof voice, so, obviously that’s a really common use case. We don’t record anything. We’re not logging anything. So, this isn’t a solution that has privacy concerns, and we try to be as unintrusive as possible with the product when customers are using it.
That extends even to the response that we have. Rather than just kicking people out of the meetings, we have a process of graduated response. We warn either the meeting owner or the participants that there may be somebody in the meeting that we can’t be sure of the identity of, and then we intervene if no action is taken. The most important thing though is that this is real time, and that’s really the requirement for this scenario. The fraud is happening in that live call. If you were to review that call afterwards, it’s too late. Those things have already happened.
And we’re extending the deepfake product currently to cover what we see as one of the most strongly emerging deepfake use cases, which is the recruiter or HR use case, as we call it. We are seeing globally as an industry the huge proliferation of deepfakes being used in the candidate recruitment process, and often it’s nation state attackers who are initiating applications for jobs. They’re using deepfake personas to essentially go through the interview process with an organization, with the ultimate goal to receive a laptop from that organization as part of the onboarding. And obviously if you have a laptop as part of your new job, you’re given credentials, you’re given access to systems. If you can make that attack work, it’s an easy way in. With deepfakes becoming easier to achieve, and again, like phishing, way more realistic, this is a real attack vector that organizations really need to think about in detail.
Q. How will that recruitment-focused protection work in practice?
Again, we’re building this in as least intrusive a way as possible. We’ll be able to integrate with the ATS systems that organizations have within their existing infrastructure. We’ll be able to essentially take a look at resumes, or CVs for folks in the UK, to start really at the point of application. So, are there problems with the application? Again, using OSINT research, being able to understand if this persona is fake even before it gets to the real time element. But we’ll also be able to analyze video and audio content, really to go defense in depth, to be very “belt and braces” in our approach.
Q. Finally, what are the most important things you would tell a security leader to prioritize right now?
CISOs and security leaders are under a lot of pressure, as they always have been. But going back to the topic of AI, the pressure that security professionals are now under is increasing exponentially.
First, think differently about what you’re actually measuring. As we talked about earlier, attack volume is increasing and that will continue, so think about different ways to measure the success of your security programs. If you look at Mean Time To Remediate (MTTR) in isolation, that will become misleading. Reframe that as the total share of security team hours consumed by phishing, rather than focusing on very specific items. So, try to measure differently.
Second, thinking about the people in your organization, assume that content detection and red flag training are just no longer sufficient by themselves. Consider putting in, or even hardening, the processes that you have within your organization. So, anything critical that involves the movement of money, credentials or data, make those processes out of band. Review how you’re doing those things at the moment, and move away from just depending on somebody spotting that something feels wrong.
And thirdly, we’ve talked about AI a lot in this conversation, mainly through the lens of how attackers are using AI. But AI is also being used by vendors. It’s still an arms race, and vendors have access to AI models and tooling that attackers don’t, which gives us a fantastic advantage. So, the third tip I would say is ask your vendors what AI they actually have access to, not just within the products that you’re consuming from them, but also what access they have to frontier models, through things like Anthropic’s program or OpenAI’s program. Ask how they are using AI and what models they have access to that will benefit the detection and the protection that they provide for you.