María has been running her awareness program for a year, and one number makes her proud. The suspicious email reporting rate is up 40%. Her 800 employees use the report button in Outlook and Gmail, and when they see something odd, they speak up. Exactly what she taught them to do.
At the weekly meeting, the SOC analyst shows her a different number. This month 183 reports of real emails came in, and 47 are still unreviewed. Some have been sitting there for three days.
María asks the only question available. Is any of those 47 real phishing? The analyst has not opened them yet, so he has nothing to answer with.
The numbers in this article describe one month at one specific organisation, not an industry average. The arithmetic, on the other hand, repeats in any program that starts working.
What happens to a suspicious email after someone reports it?
Reported email triage is the work of deciding, one by one, whether what an employee reported is a real attack or a false alarm. Somebody has to do it, and in most organisations that somebody is a person.
María’s analyst works through them in arrival order. For each report he:
- Opens the original email in a controlled environment.
- Checks the headers and the sender authentication.
- Verifies where the links actually lead, which is rarely where they claim to.
- Analyses the attachments, including the file pretending to be an invoice.
- Classifies the case and closes it.
Each report takes him between five and fifteen minutes, depending on how murky the case is. At 183 a month and climbing, he cannot keep up.
And here is the uncomfortable part. The program worked. People report. What did not grow at the same pace is the organisation’s capacity to process what they report, so the better you train your people, the longer the queue gets.
That queue was in nobody’s plan. It showed up as a consequence of awareness succeeding, and it rarely appears in any results deck. Reporting is the other half of the funnel that starts with the click, and we already wrote about the click half in what has to be configured before you trust your click rate.
That queue has an answer at SMARTFENSE, Smart Triage, an artificial intelligence agent that classifies each reported email as real phishing or a false alarm in seconds rather than hours. Later in this series we cover it in detail. Here the focus is the problem it solves, because that is the one almost nobody measures.
Why are most reported emails not attacks?
Of those 183 reports, 160 turned out to be harmless. There was a genuine invoice that looked odd, a promotion and an email from a new supplier nobody had seen before.
Those 160 emails are the sign that people are paying attention. An employee who hesitates over a legitimate email and speaks up did exactly what was asked, and discouraging that hesitation is the fastest way to run out of reports.
The difficulty sits elsewhere. Each of those doubts costs somebody’s time, and that cost appears in no program indicator. The reporting rate goes up and gets celebrated at the board; the hours that increase consumes are measured nowhere. We have already discussed which metrics actually reflect an awareness program, and this is one of the ones almost never on the dashboard.

What does it cost when a real attack waits in the queue?
The other 23 emails that month were attacks. Each waited its turn behind a pile of false alarms, because the queue is worked in arrival order rather than by risk.
The time between the report and the decision is time during which that email is still sitting in everyone else’s inbox. Nobody can warn, block or contain something that has not been looked at yet. If the oldest report is three days old, your organisation’s current worst case is a three-day-old attack that nobody has opened.
A report button with no fast classification behind it works like a fire alarm that rings while nobody checks the panel to see which zone it came from.
Two things that usually travel together in the same conversation are worth separating. One is the organisation’s detection capability, which in María’s case is good and improved over the year. The other is its response speed, which depends on how much queue one person has that week. The first is measured by the reporting rate and presented with pride. The second is almost never measured.
That distinction also changes how you read the organisation’s human risk. A company whose people detect and report, but which takes three days to act, has a process problem rather than a people problem.
What should your team receive when someone reports an email?
When an employee reports an email, your team needs an answer to three questions: what this email is, how risky it is and why. With that, the person in charge stops classifying and starts deciding, which is what you hired them for.
The difference between the two tasks is concrete. Classifying means opening a file and finding out what is inside. Deciding means reading a verdict, confirming or correcting it, and triggering whatever follows. The first grows with report volume. The second does not.
The SMARTFENSE phishing report button installs as an add-in for Outlook, Gmail and Thunderbird, and it also integrates with the native Outlook report button, so nobody has to learn a new gesture. On the employee’s side, the speaking-up part is solved. What decides whether the program holds is what happens next, when that alert lands in somebody’s report console.
There is a calculation worth doing before the next board meeting: how many reports came in last month, how many are still undecided, and how many days old the oldest one is. The first number is the one usually presented. The third is the one that describes the risk, and it is the only one of the three nobody asks for.
The other half of the story
All of this looks at the queue from the security team’s side. The other half is missing, and it is the half that decides whether there are still reports next year.
Lucía, in operations, hesitated over an email, decided not to click and spoke up. From where she stands, nothing happened afterwards. No reply, no sign that her warning was of any use. That is what what happens to the reporting habit when nobody answers is about, the next piece in this series. The question there is what happens to the habit of speaking up when speaking up has no visible consequence.
Leave a Reply