Q&A: Cofense CEO Marc Olesen On How Defenders Can Fight Back Against AI-Driven Phishing

Cofense CEO Marc Olesen on why AI is reshaping the phishing threat landscape, what polymorphic and multi-channel attacks mean for enterprise security teams, and why defenders need to “compress the gap” between automation and the human layer.

Published on Jul 21, 2026
Joel Witts Written by Joel Witts
Marc Olesen, CEO of Cofense, Interview

Phishing remains the most common entry point for enterprise breaches, and AI is only accelerating the risk. Cofense’s recent New Era of Phishing report found malicious emails landing in inboxes every 19 seconds in 2025, with a 204% year-over-year jump in phishing emails delivering malware and polymorphic attacks becoming the default delivery model. Personalization that once took an attacker 16 hours of manual research can now be generated in under five minutes.

Expert Insights sat down with Marc Olesen, CEO of Cofense, an email security platform focused on post-perimeter defense, AI-driven threat intelligence, and human-supervised threat response. Olesen joined Cofense in January 2025 and brings over 30 years of technology leadership experience, including CEO at TokenEx, President and CEO at Sift, and senior leadership positions at Splunk and McAfee.

In this conversation, Olesen discusses how AI has changed the scale and sophistication of phishing, why polymorphic and multi-channel attacks are evading traditional pattern-based defenses, the role of post-perimeter defense in protecting the inbox, and the importance of compressing what he calls the “automation gap” between attackers and defenders with both AI and a trained human layer.

Q. You’ve been at Cofense for over a year now. What drew you to Cofense, and how have you seen the phishing threat landscape evolve in that time?

It really comes down to the market need for a solution like Cofense. The phishing challenge does not seem to be going away. In fact, it seems to be getting worse. That was a big part of it. The other part was that Cofense has a unique solution and a differentiated capability to address that market need.

And the landscape is evolving fast. I’ve been here coming up a year and a half, and the pace of that evolution, the acceleration of how sophisticated, unique, and differentiated the attacks are, is creating both a challenge and an opportunity for solution providers like us.

Q. Cofense’s recent report, The New Era of Phishing: Threats Built in the Age of AI, found malicious emails landing every 19 seconds in 2025, alongside a 204% jump in phishing emails delivering malware. For a large enterprise processing millions of messages a day, how has AI changed the scale and nature of the threat they’re facing?

It’s multifaceted. There’s the massive increase in volume. There’s a massive increase in sophistication and personalization. And then there’s an increase in variation, or uniqueness. One report I just saw said that 88% of AI-generated attacks are unique. That means they’re different from any prior attack, different from any signature, signal, or pattern we’ve seen before.

What used to take an attacker 16 hours to generate a phishing attack now takes five minutes with AI. So, there’s a 200x efficiency increase for the attacker, which is what’s driving the volume, sophistication, and uniqueness we’re seeing.

And it’s all machine-driven. AI is out there looking through the internet, grabbing everything that’s personal or in the public domain about someone, and leveraging that in a personalized attack. Attackers can now make every email relevant to the individual recipient and their role, at scale.

Q. The report also describes polymorphic phishing as the “default delivery model” for phishing. For those less familiar, what is polymorphic phishing, and what does it mean for enterprise security teams still relying on traditional, pattern-based detection?

It sounds like a fancy term, and it is. But what it really means is that each email an attacker delivers in their campaign is slightly different, slightly varied, slightly unique from the previous one. That makes it very hard for traditional perimeter defenses, traditional rule-based or signature-based threat defenses, to identify the attack, because it’s slightly changing every time.

These campaigns also come in mass and in bulk. It’s not just one attack or one isolated email. It’s a coordinated campaign. So, it’s crucial for defenses to be able to extrapolate from a signature or a pattern, and predict what the next variation looks like, or could look like, to get ahead of the attack.

Q. Another striking takeaway was the rise of conversational attacks like business email compromise, now the second most common threat vector. Why is AI making these text-based attacks so much harder to catch, and what impact can BEC have on an organization if even one email slips through?

The impact is pretty significant. Most estimates peg the average cost of a breach at around $10 million, so it’s not small.

With business email compromise, AI has accelerated the attacker’s capability in two ways. The first is the high degree of personalization we’ve been talking about. The second is throughput. They can run those personalized attacks at scale.

With business email compromise, you also now have multi-channel attacks. An attacker can socially engineer their target with text, voice, and chat, through tools like Teams, Slack, or Zoom, to complement the attack coming through email. Email is still the dominant channel we see. But the attacker can make things look more real by leveraging these other channels, which just ratchets up the vigilance employees have to bring to every message.

And those attacks are designed to catch people when they’re rushed, busy, and distracted. Those are the moments when we’re most vulnerable.

Q. Phishing campaigns increasingly exploit legitimate system tools, remote access software, and trusted cloud platforms to blend into normal corporate traffic. So-called living-off-the-land tactics feature in Black Hat’s Advanced Threat Actor Tradecraft track this year. How significant is this shift, and why does it make these attacks so difficult for large organizations to detect among their normal day-to-day activity?

It creates a real challenge. The protection has to be twofold. The first is how much automation we can leverage. People talk about fighting AI with AI, and yes, we want to leverage AI on the defender side as much as we can. In terms of mitigating that noise, that’s where having really strong threat intelligence comes in: AI-based threat intelligence that extrapolates from fit-for-purpose signals and a fit-for-purpose threat database.

The second part is the human layer. I talk about what I call the automation gap. There are always going to be a set of attacks that get through, past all the defenses, whether that’s perimeter defenses, rule-based filters, or AI automation, because the attackers are always going to be a step ahead. They have that advantage. Our job is to compress that gap with our own AI and automation capabilities, and then have a talented, trained human defense layer to mitigate what’s left, and to cycle through to keep compressing the gap. It’s a scale challenge. You leverage AI as much as you can, and then you have a formidable human defense layer behind it.

Q. Cloud identity and authorization abuse is a major theme at Black Hat this year, with attackers using phishing to trick users into granting OAuth permissions, turning a single click into silent access across cloud platforms like Microsoft 365 and Slack. Does this reinforce that the mailbox is still ground zero, even as the industry talks about identity as the new perimeter?

I have a strong belief in defense in depth. It takes a community, an ecosystem, layers of defense. The perimeter is crucial. Identity is crucial. So, in no way do I want to short-shrift the importance of those defenses.

At the same time, in order to compromise the perimeter or compromise identity, it really starts with the human, which starts with the inbox. From an attacker’s standpoint, the best channel to compromise an employee is email. We’ve talked about it becoming more multi-channel. Text, voice, and chat help reinforce attacks and make them feel real. But email is still the primary channel to compromise the employee, and I don’t think that’s going away.

Even to compromise identity, you need some information from the employee. You need them to take an action, to grant access, to provide credentials. Ground zero is still the email inbox. It’s the classic line of why do you rob a bank? Because that’s where the money is. It works for attackers.

Q. Let’s turn to the solutions. Can you give us an overview of Cofense and the Vision platform, and the approach you take to phishing defense?

We believe phishing defense is about defense in depth, and for us, we focus on post-perimeter. We focus on the threats that reach the inbox. There’s great protection upstream, but ultimately, as we’ve talked about, attacks are going to reach the inbox, and that’s our primary focus.

We look at it as a fully integrated solution: identify the threats, neutralize those threats, and prepare for the next threat. It’s a closed-loop cycle. For detection, we leverage AI automation and our AI threat intelligence to identify as many threats as we can, so they’re neutralized in seconds. For those threats that are so unique they go beyond automated detection, we have the human defense layer.

It’s still about speed and accuracy. Whether we’re detecting automatically and neutralizing in seconds, or our customers’ employees are reporting suspicious emails, the question is how fast and accurately we neutralize the threat. We strive to neutralize a threat that an employee reports in under 10 minutes. And we use the attacks that get through to prepare employees to be great reporters of suspicious emails on the next go-around.

Q. Most enterprises have invested heavily in securing the perimeter, yet threats keep landing in inboxes. Why are perimeter defenses no longer enough on their own, and what does effective post-perimeter defense look like at scale?

I think it’s just crucial. We’re beyond the point where “good enough is good enough.” It’s not. The average cost of a breach and the impact it can have on the business mean you really want best-in-class defense in depth.

Ultimately, after you apply all of the filters, automation, AI, and logic that you can, the attacker is going to be that step ahead. So how efficiently can you neutralize the attack that gets through? How quickly can you do it? And accuracy is a big part of it too. It’s not just speed. It’s speed and accuracy. If your accuracy goes down, you start affecting the business in other ways. Email is such a crucial channel that if you’re not accurate, you compromise the business in other ways.

Q. One of the headline themes at Black Hat this year is offensive and defensive AI, including autonomous attack frameworks capable of launching thousands of personalized phishing emails per second. When attacks move at machine speed, many have suggested we now “need AI to fight AI.” Cofense has built AI into the platform, but you also emphasize human-supervised intelligence. Why can’t AI fight AI alone, and what does the human layer add?

It’s crucial, but I don’t want to sell the automation component short. The automation is equally crucial, because otherwise we get overwhelmed before we reach the point where the human layer needs to pick up. We do want to fight AI with AI. We want the best threat intelligence, the best models, the best behavioral profiling, so that we can leverage automation.

At the same time, there’s going to be this gap. I often use a sports analogy. In athletics, swimming, cycling, there are athletes who decide to cheat, and there are testers helping to keep the sport clean. The testers continue to get more sophisticated. As soon as their testing improves, the athletes who decide to cheat find different ways to cheat. Then the testing improves again. It’s a constant leapfrog, and there’s always a gap.

Cybersecurity is very similar. As defenders, we’re going to continue to get better with our automated capability, and as soon as we do, attackers will find another way. There’s always going to be a gap. Our job is to compress that gap as much as we can; to keep it small so we’re not overwhelmed at scale. But knowing the gap is there is what makes the human defense layer so important. We’re always going to need our employees, colleagues, and coworkers to be as vigilant, trained, and suspicious as possible.

We compress the gap, but the gap is not going away. We compress it with technology, and then we plug it with people. That’s going to be everyone in the organization being vigilant.

Q. Who is most at risk from phishing and BEC, and how does Cofense help customers solve these challenges? You work heavily with regulated industries like finance and healthcare. Where do you see Cofense making the biggest difference?

Everyone is at risk. Every company is at risk. But large-scale enterprises in regulated industries are generally going to come under the greatest attack: financial services, healthcare, energy, manufacturing, critical infrastructure. They recognize that it’s crucial to have best-in-class defense in depth.

It’s not one layer or one solution. It’s a community. We’re playing a team sport, and it takes a collection. For us at Cofense, we feel good about the post-perimeter defense layer, and we feel good about the speed and accuracy with which we operate in that layer. We want to complement what regulated industries already have in place, because those are the customers under the greatest scrutiny and the greatest potential for compromise.

Q. Looking ahead, what do you expect the phishing landscape to look like over the next 12 months, particularly as threats like deepfakes and AI-generated content become more sophisticated?

I think we’re going to see exactly that. Highly personalized, highly hard-to-detect attacks. The scraping that AI can do at scale, the gathering of information from the public domain, means we’re going to see a high degree of personalization.

Deepfakes are going to be very hard to detect. We’re reading about it every day, how compelling deepfakes are, how closely they look like the real thing. And it’s going to be multi-channel. That’s going to continue to increase over the next year as well.

What it comes back to is that we need our colleagues and our employees to be extremely vigilant. I think we’re going to start to see a lot more confirmation, and the ability to categorize where to confirm. Think about identity. We talked about multi-factor authentication earlier. Where do we apply it? We definitely do it with our bank. We may not do it with some less important account. I think we’re going to start to see this need where there’s always going to need to be confirmation of an email that’s received, depending on the type of request. When deepfakes are so real, so strong, so compelling, how do we confirm that? We’re going to be in a confirmation stage.

Q. For a security leader at a large enterprise looking to strengthen their phishing defense, where should they start today, and what advice would you have for teams on building greater phishing resilience?

It starts with defense in depth, and making sure you really have the best capability at each layer. We’re beyond the consolidated platform with “good enough” layers of defense. I’d highly recommend best-in-class defense in depth.

That starts upstream. Make sure your identity protection and your perimeter are strong. Every layer is crucial. Any CISO or security executive should be looking at covering all of them. Specifically for post-perimeter defense, I think an integrated solution is crucial. It’s going to deliver the most value, because in order to prepare employees for that next iteration of attack, you have to be able to train off what is currently getting through. That fit-for-purpose feedback loop is what continues to compress the gap and deliver the greatest speed and accuracy in addressing the attacks that do get through.


Learn more about Cofense.


This field is for validation purposes and should be left unchanged.

FREE NEWSLETTER

Cyber Weekly

Get curated cybersecurity news, threats and insights delivered free every Thursday.

Written By Written By
Joel Witts
Joel Witts Content Director

Joel is the Director of Content and a co-founder at Expert Insights; a rapidly growing media company focussed on covering cybersecurity solutions.

He’s an experienced journalist and editor with 8 years’ experience covering the cybersecurity space. He’s reviewed hundreds of cybersecurity solutions, interviewed hundreds of industry experts and produced dozens of industry reports read by thousands of CISOs and security professionals in topics like IAM, MFA, zero trust, email security, DevSecOps and more.

He also hosts the Expert Insights Podcast and co-writes the weekly newsletter, Decrypted. Joel is driven to share his team’s expertise with cybersecurity leaders to help them create more secure business foundations.