Triaging what staff report to the phishing mailbox
Reads each message forwarded to the report-phishing address, pulls sender, headers, links and attachments out of the raw source, collapses reports of one campaign into a single case, and drafts a verdict naming the indicators it relied on — so an analyst confirms or overturns a judgement instead of opening four hundred near-identical mails.
- Effort
- Weeks of work
- Skill level
- Some technical skill
- Organisation size
- Mid-market
- Value
- Time saved, Risk reduced
Tools named for this
- A mail parser that keeps the original headers and the raw source intact
- A language model that returns its verdict together with the specific indicators it used
- A link and attachment reputation or detonation service, run in isolation from the corporate network
What to check before you ship it in India
- For service providers, intermediaries, data centres, body corporate and Government organisations, phishing attacks sit on the list of cyber security incidents that must be reported to CERT-In, and the direction of 28 April 2022 puts that window at six hours from noticing the incident. A triage queue reviewed the next morning has already spent it. Organisations outside those categories are not reached by the direction.
- A reported message is somebody's mail. It routinely carries the reporter's own correspondence and personal data about third parties who never reported anything, and section 8(5) requires reasonable security safeguards over personal data in the fiduciary's control. The triage store is usually the least-guarded copy of it in the building.
Sources
Every claim on this page traces to one of these, on the date it was read.
- CERT-In Directions No. 20(3)/2022-CERT-In under sub-section (6) of section 70B of the Information Technology Act, 2000, dated 28 April 2022 — direction (ii) read with Annexure I(vii) · Indian Computer Emergency Response Team (CERT-In), Ministry of Electronics and Information Technology · a rule · read 2026-09-01
- The Digital Personal Data Protection Act, 2023 (No. 22 of 2023) — most obligations commence 13 May 2027 under the DPDP Rules 2025 — s.8(5) · Ministry of Electronics and Information Technology · a rule · read 2026-09-01
- Evaluating Large Language Models for Phishing Detection, Self-Consistency, Faithfulness, and Explainability · arXiv (Kuikel, Piplai, Aggarwal) · how it is done · read 2026-09-01