{"id":45235,"date":"2026-09-03T16:43:33","date_gmt":"2026-09-03T14:43:33","guid":{"rendered":"https:\/\/smartfense.com\/?p=45235"},"modified":"2026-09-03T16:44:39","modified_gmt":"2026-09-03T14:44:39","slug":"journey-of-a-reported-email","status":"publish","type":"post","link":"https:\/\/smartfense.com\/en\/blog\/journey-of-a-reported-email\/","title":{"rendered":"The journey of a reported email, from 11:23 to 11:27"},"content":{"rendered":"<p>Wednesday, 11:23. Luc\u00eda receives an email that looks like it comes from IT, asking her to renew her VPN credentials before noon. Something feels off. She presses the report button and goes back to what she was doing.<\/p>\n<p>That is all she does. <a href=\"https:\/\/smartfense.com\/en\/blog\/phishing-reporting-habit-no-response\/\">The previous piece in this series<\/a> left open the point that the reporting habit only holds if reporting has a consequence the person can perceive, and that this consequence depends on how long a real email takes to get an answer. Automated phishing email triage is what compresses that wait, and here is its journey step by step, without jargon. The times and the numbers belong to one specific organization, the same one as the previous pieces, and are not industry averages.<\/p>\n<h2>What is the first thing checked when a reported email comes in?<\/h2>\n<p>The first thing is whether your own program sent it. That is the only question the platform can answer without investigating anything, because it holds the record of every <a href=\"https:\/\/smartfense.com\/en\/platform\/simulation-tools\/phishing-attacks\/\">phishing simulation<\/a> it sent, which is why it goes first.<\/p>\n<p>When the answer is yes, the case closes on the spot. The platform credits the person for spotting it, adds it to their score, and there is nothing left to analyze. Luc\u00eda\u2019s email is not a simulation, so the journey continues.<\/p>\n<h2>What does the analysis of a reported email check?<\/h2>\n<p>11:24. From here the email is analyzed automatically, with the same level of detail someone from the security team would apply, but without anyone having to open it.<\/p>\n<p>It checks whether the email really comes from where it claims to, or whether someone is impersonating a known company. It follows each link to its final destination, because a link can display one address and lead to another. It examines the attachments, including the classic one that pretends to be an invoice and is not.<\/p>\n<p>And it looks at the images in the message. That is where a good part of what email security cannot see is hiding today. A QR code takes the place of the link and a screenshot takes the place of the text, so an analysis that only reads the text walks straight past both cases.<\/p>\n<blockquote>\n<p>An analysis that only reads the text of an email cannot see the attack that arrives inside an image.<\/p>\n<\/blockquote>\n<p>How to simulate that attack to train your people is already covered in <a href=\"https:\/\/smartfense.com\/en\/blog\/quishing-qr-code-phishing-how-to-simulate\/\">the article on quishing<\/a> on this blog. Here the QR code arrives in an email somebody has already reported, and what has to be done with it is decide what it is.<\/p>\n<h2>And when the technical evidence is not enough?<\/h2>\n<p>Some emails are not settled by the evidence. The sender is legitimate, the links are on no list, there are no attachments, but the message asks for something that does not fit, with an urgency that does not fit either. This is the grey area where the judgment of a person used to be required.<\/p>\n<p>For those cases there is an artificial intelligence agent that analyzes what the email says and how it says it, from the urgency and the pressure to the pretext it uses to justify the request. It does not replace the technical check. It steps in when that check falls short, which is exactly where the difficult reports used to pile up.<\/p>\n<p>In Luc\u00eda\u2019s email the evidence is more than enough. The sender\u2019s domain was registered 48 hours ago, the links point to a server in a country where the company does not operate, and sender authentication fails.<\/p>\n<p><strong>Verdict: phishing. Risk score: 92 out of 100.<\/strong><\/p>\n<h2>What does the security team receive when the analysis is done?<\/h2>\n<p>11:25. What reaches the security team is a result instead of an email to open. It is three things.<\/p>\n<ul>\n<li><strong>A verdict.<\/strong> Real phishing or false alarm.<\/li>\n<li><strong>A risk score from 0 to 100.<\/strong> The priority, without having to read anything else.<\/li>\n<li><strong>An explanation of why<\/strong>, written in the language of whoever is reading it.<\/li>\n<\/ul>\n<p>The third one is what changes who can work with the report. The explanation does not arrive in the language of an email header, it arrives in sentences such as \u00abthe attachment hides its real file type\u00bb or \u00abreplies to this email would go to an address other than the sender\u2019s\u00bb. You do not need to know how to read an email from the inside to understand them, and that means the report stops waiting for the one person on the team who does.<\/p>\n<h2>What happens to reported emails that turn out to be harmless?<\/h2>\n<p>Luc\u00eda\u2019s email was phishing, but most are not. In the month we have been talking about, 160 of the 183 reported emails turned out to be harmless. A real invoice that looked odd, a promotion, an email from a new supplier nobody had on their calendar.<\/p>\n<p>That is what happens when people pay attention. An organization that treats the false alarm as a cost ends up teaching its people not to report. The person who hesitated over a legitimate email did exactly what was asked of them.<\/p>\n<p>What changes with automated analysis is that those 160 emails also get their verdict and close without costing anyone\u2019s time. They stop being the pile underneath which the 23 that really were attacks are waiting.<\/p>\n<h2>How long does the complete journey take?<\/h2>\n<p>11:27. Whoever is on duty opens the report, finds the analysis already done, confirms the verdict and starts the response protocol. The decision is still theirs. What changed is that they no longer have to build the evidence in order to make it.<\/p>\n<p>And the protocol does not have to wait for that confirmation. A <a href=\"https:\/\/smartfense.com\/en\/platform\/engagement-tools\/playbooks\/\">Playbook<\/a> is a set of actions that run on their own when a given event occurs, so the verdict can chain the first ones without anybody launching them.<\/p>\n<p>It can be an alert to the team by email, by Slack or by Microsoft Teams, plus a call to whatever systems you have integrated, so containment starts while the person on duty reviews the case. Where to draw that line is each organization\u2019s call, because some responses are better off starting on their own and others should not move until somebody looks.<\/p>\n<p>Between the moment Luc\u00eda pressed the button and the moment the security team started acting, four minutes passed. With the queue of 47 reports we described in <a href=\"https:\/\/smartfense.com\/en\/blog\/who-opens-the-phishing-reports\/\">the first piece of the series<\/a>, it would have been three days.<\/p>\n<p>That difference carries a cost the queue does not show. A phishing email waiting three days to be classified stays three days in everybody else\u2019s inbox, and nobody can warn, block or contain an attack that has not been looked at yet. Classification time is the time the attack has to keep working.<\/p>\n<h2>What Luc\u00eda notices, without anyone explaining it to her<\/h2>\n<p>There is a second reading of those four minutes, and it is on no security dashboard. Luc\u00eda spoke up and something happened.<\/p>\n<p>The verdict and the score will never reach her screen, and she does not need them. It is enough for her to sense that her warning entered a circuit that moved, because that is what will weigh the next time she hesitates over an email. When the journey is measured in days, the answer arrives late for her and late for the organization. When it is measured in minutes, the circuit closes on its own.<\/p>\n<p>That journey is what Smart Triage runs inside the <a href=\"https:\/\/smartfense.com\/en\/platform\/reports-and-auditing\/\">reporting console<\/a> of SMARTFENSE, over the emails your people report with the button. If you want to see it on your own reports, the console holds the detail of every analysis and the history of what was classified.<\/p>\n<p>In the next piece of the series we are going to shift the point of view again, and look at the month of the SOC analyst who opened those 183 reports one by one and at the hours automated triage gives back.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Automated triage of reported emails, step by step. What gets checked, what the security team receives and how long the complete journey takes.<\/p>\n","protected":false},"author":2,"featured_media":45230,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[3,686],"tags":[2180,2313,454,849,2064],"class_list":["post-45235","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-artificial-intelligence","tag-automation","tag-ciso-en","tag-phishing-en","tag-reporte-de-phishing"],"acf":[],"yoast_head":" \n<title>The journey of a reported email, minute by minute<\/title>\n<meta name=\"description\" content=\"Automated triage of reported emails, step by step. What gets checked, what the security team receives and how long the complete journey takes.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/smartfense.com\/en\/blog\/journey-of-a-reported-email\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The journey of a reported email, minute by minute\" \/>\n<meta property=\"og:description\" content=\"Automated triage of reported emails, step by step. What gets checked, what the security team receives and how long the complete journey takes.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/smartfense.com\/en\/blog\/journey-of-a-reported-email\/\" \/>\n<meta property=\"og:site_name\" content=\"SMARTFENSE\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-03T14:43:33+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-03T14:44:39+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/smartfense.com\/file\/2026\/09\/hero-en.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t<meta property=\"og:image:height\" content=\"1080\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Nicol\u00e1s Bruna\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Nicol\u00e1s Bruna\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/journey-of-a-reported-email\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/journey-of-a-reported-email\\\/\"},\"author\":{\"name\":\"Nicol\u00e1s Bruna\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#\\\/schema\\\/person\\\/5494c12e79213c554fa449135589c24c\"},\"headline\":\"The journey of a reported email, from 11:23 to 11:27\",\"datePublished\":\"2026-09-03T14:43:33+00:00\",\"dateModified\":\"2026-09-03T14:44:39+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/journey-of-a-reported-email\\\/\"},\"wordCount\":1327,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/journey-of-a-reported-email\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/hero-en.png\",\"keywords\":[\"artificial intelligence\",\"automation\",\"ciso\",\"phishing\",\"reporte de phishing\"],\"articleSection\":[\"Blog\",\"Blog\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/journey-of-a-reported-email\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/journey-of-a-reported-email\\\/\",\"url\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/journey-of-a-reported-email\\\/\",\"name\":\"The journey of a reported email, minute by minute\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/journey-of-a-reported-email\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/journey-of-a-reported-email\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/hero-en.png\",\"datePublished\":\"2026-09-03T14:43:33+00:00\",\"dateModified\":\"2026-09-03T14:44:39+00:00\",\"description\":\"Automated triage of reported emails, step by step. What gets checked, what the security team receives and how long the complete journey takes.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/journey-of-a-reported-email\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/journey-of-a-reported-email\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/journey-of-a-reported-email\\\/#primaryimage\",\"url\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/hero-en.png\",\"contentUrl\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/hero-en.png\",\"width\":1920,\"height\":1080,\"caption\":\"Timeline diagram with four moments, from 11:23 to 11:27, showing the journey of a reported email from the report button to the security team's decision\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/journey-of-a-reported-email\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Portada\",\"item\":\"https:\\\/\\\/smartfense.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"The journey of a reported email, from 11:23 to 11:27\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/smartfense.com\\\/en\\\/\",\"name\":\"SMARTFENSE - Concienciaci\u00f3n en Ciberseguridad\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/smartfense.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#organization\",\"name\":\"SMARTFENSE\",\"url\":\"https:\\\/\\\/smartfense.com\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2023\\\/08\\\/logo-smartfense-240x40-1.png\",\"contentUrl\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2023\\\/08\\\/logo-smartfense-240x40-1.png\",\"width\":241,\"height\":40,\"caption\":\"SMARTFENSE\"},\"image\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"description\":\"SMARTFENSE es una plataforma SaaS de concienciaci\u00f3n en seguridad de la informaci\u00f3n fundada en 2016. Combina capacitaci\u00f3n interactiva, simulaci\u00f3n de phishing, ransomware, smishing y USB drop, y m\u00e9tricas de riesgo humano. Dise\u00f1ada para Latinoam\u00e9rica, Espa\u00f1a, Portugal e Italia.\",\"foundingDate\":\"2016\",\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/company\\\/smartfense\\\/\"],\"knowsAbout\":[\"Concienciaci\u00f3n en ciberseguridad\",\"Security awareness training\",\"Simulaci\u00f3n de phishing\",\"Simulaci\u00f3n de ransomware\",\"Smishing\",\"Gesti\u00f3n del riesgo humano\",\"Cumplimiento normativo en seguridad de la informaci\u00f3n\"],\"areaServed\":[{\"@type\":\"Country\",\"name\":\"Argentina\"},{\"@type\":\"Country\",\"name\":\"Chile\"},{\"@type\":\"Country\",\"name\":\"Colombia\"},{\"@type\":\"Country\",\"name\":\"M\u00e9xico\"},{\"@type\":\"Country\",\"name\":\"Per\u00fa\"},{\"@type\":\"Country\",\"name\":\"Uruguay\"},{\"@type\":\"Country\",\"name\":\"Paraguay\"},{\"@type\":\"Country\",\"name\":\"Ecuador\"},{\"@type\":\"Country\",\"name\":\"Panam\u00e1\"},{\"@type\":\"Country\",\"name\":\"Costa Rica\"},{\"@type\":\"Country\",\"name\":\"Rep\u00fablica Dominicana\"},{\"@type\":\"Country\",\"name\":\"Guatemala\"},{\"@type\":\"Country\",\"name\":\"Bolivia\"},{\"@type\":\"Country\",\"name\":\"Brasil\"},{\"@type\":\"Country\",\"name\":\"Espa\u00f1a\"},{\"@type\":\"Country\",\"name\":\"Portugal\"},{\"@type\":\"Country\",\"name\":\"Italia\"}],\"slogan\":\"La plataforma online de concienciaci\u00f3n en Seguridad de la Informaci\u00f3n galardonada internacionalmente, que genera h\u00e1bitos seguros en los usuarios.\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#\\\/schema\\\/person\\\/5494c12e79213c554fa449135589c24c\",\"name\":\"Nicol\u00e1s Bruna\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/b03096bf4c3dd886cfcffd7415eadf6f80d2c8126188409e7d4d1d1b6b911fcb?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/b03096bf4c3dd886cfcffd7415eadf6f80d2c8126188409e7d4d1d1b6b911fcb?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/b03096bf4c3dd886cfcffd7415eadf6f80d2c8126188409e7d4d1d1b6b911fcb?s=96&d=mm&r=g\",\"caption\":\"Nicol\u00e1s Bruna\"},\"description\":\"Product Manager de SMARTFENSE. Su misi\u00f3n en la empresa es mejorar la plataforma d\u00eda a d\u00eda y evangelizar sobre la importancia de la concientizaci\u00f3n. Ha escrito dos whitepapers y m\u00e1s de 150 art\u00edculos sobre gesti\u00f3n del riesgo de la ingenier\u00eda social, creaci\u00f3n de culturas seguras y cumplimiento de normativas. Tambi\u00e9n es uno de los autores de la Gu\u00eda de Ransomware de OWASP y el Calculador de costos de Ransomware, entre otros recursos gratuitos.\",\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/nicolasbruna\\\/\"],\"url\":\"https:\\\/\\\/smartfense.com\\\/en\\\/author\\\/nicolas\\\/\"}]}<\/script>\n ","yoast_head_json":{"title":"The journey of a reported email, minute by minute","description":"Automated triage of reported emails, step by step. What gets checked, what the security team receives and how long the complete journey takes.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/smartfense.com\/en\/blog\/journey-of-a-reported-email\/","og_locale":"en_US","og_type":"article","og_title":"The journey of a reported email, minute by minute","og_description":"Automated triage of reported emails, step by step. What gets checked, what the security team receives and how long the complete journey takes.","og_url":"https:\/\/smartfense.com\/en\/blog\/journey-of-a-reported-email\/","og_site_name":"SMARTFENSE","article_published_time":"2026-09-03T14:43:33+00:00","article_modified_time":"2026-09-03T14:44:39+00:00","og_image":[{"width":1920,"height":1080,"url":"https:\/\/smartfense.com\/file\/2026\/09\/hero-en.png","type":"image\/png"}],"author":"Nicol\u00e1s Bruna","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Nicol\u00e1s Bruna","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/smartfense.com\/en\/blog\/journey-of-a-reported-email\/#article","isPartOf":{"@id":"https:\/\/smartfense.com\/en\/blog\/journey-of-a-reported-email\/"},"author":{"name":"Nicol\u00e1s Bruna","@id":"https:\/\/smartfense.com\/en\/#\/schema\/person\/5494c12e79213c554fa449135589c24c"},"headline":"The journey of a reported email, from 11:23 to 11:27","datePublished":"2026-09-03T14:43:33+00:00","dateModified":"2026-09-03T14:44:39+00:00","mainEntityOfPage":{"@id":"https:\/\/smartfense.com\/en\/blog\/journey-of-a-reported-email\/"},"wordCount":1327,"commentCount":0,"publisher":{"@id":"https:\/\/smartfense.com\/en\/#organization"},"image":{"@id":"https:\/\/smartfense.com\/en\/blog\/journey-of-a-reported-email\/#primaryimage"},"thumbnailUrl":"https:\/\/smartfense.com\/file\/2026\/09\/hero-en.png","keywords":["artificial intelligence","automation","ciso","phishing","reporte de phishing"],"articleSection":["Blog","Blog"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/smartfense.com\/en\/blog\/journey-of-a-reported-email\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/smartfense.com\/en\/blog\/journey-of-a-reported-email\/","url":"https:\/\/smartfense.com\/en\/blog\/journey-of-a-reported-email\/","name":"The journey of a reported email, minute by minute","isPartOf":{"@id":"https:\/\/smartfense.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/smartfense.com\/en\/blog\/journey-of-a-reported-email\/#primaryimage"},"image":{"@id":"https:\/\/smartfense.com\/en\/blog\/journey-of-a-reported-email\/#primaryimage"},"thumbnailUrl":"https:\/\/smartfense.com\/file\/2026\/09\/hero-en.png","datePublished":"2026-09-03T14:43:33+00:00","dateModified":"2026-09-03T14:44:39+00:00","description":"Automated triage of reported emails, step by step. What gets checked, what the security team receives and how long the complete journey takes.","breadcrumb":{"@id":"https:\/\/smartfense.com\/en\/blog\/journey-of-a-reported-email\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/smartfense.com\/en\/blog\/journey-of-a-reported-email\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/smartfense.com\/en\/blog\/journey-of-a-reported-email\/#primaryimage","url":"https:\/\/smartfense.com\/file\/2026\/09\/hero-en.png","contentUrl":"https:\/\/smartfense.com\/file\/2026\/09\/hero-en.png","width":1920,"height":1080,"caption":"Timeline diagram with four moments, from 11:23 to 11:27, showing the journey of a reported email from the report button to the security team's decision"},{"@type":"BreadcrumbList","@id":"https:\/\/smartfense.com\/en\/blog\/journey-of-a-reported-email\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Portada","item":"https:\/\/smartfense.com\/en\/"},{"@type":"ListItem","position":2,"name":"The journey of a reported email, from 11:23 to 11:27"}]},{"@type":"WebSite","@id":"https:\/\/smartfense.com\/en\/#website","url":"https:\/\/smartfense.com\/en\/","name":"SMARTFENSE - Concienciaci\u00f3n en Ciberseguridad","description":"","publisher":{"@id":"https:\/\/smartfense.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/smartfense.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/smartfense.com\/en\/#organization","name":"SMARTFENSE","url":"https:\/\/smartfense.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/smartfense.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/smartfense.com\/file\/2023\/08\/logo-smartfense-240x40-1.png","contentUrl":"https:\/\/smartfense.com\/file\/2023\/08\/logo-smartfense-240x40-1.png","width":241,"height":40,"caption":"SMARTFENSE"},"image":{"@id":"https:\/\/smartfense.com\/en\/#\/schema\/logo\/image\/"},"description":"SMARTFENSE es una plataforma SaaS de concienciaci\u00f3n en seguridad de la informaci\u00f3n fundada en 2016. Combina capacitaci\u00f3n interactiva, simulaci\u00f3n de phishing, ransomware, smishing y USB drop, y m\u00e9tricas de riesgo humano. Dise\u00f1ada para Latinoam\u00e9rica, Espa\u00f1a, Portugal e Italia.","foundingDate":"2016","sameAs":["https:\/\/www.linkedin.com\/company\/smartfense\/"],"knowsAbout":["Concienciaci\u00f3n en ciberseguridad","Security awareness training","Simulaci\u00f3n de phishing","Simulaci\u00f3n de ransomware","Smishing","Gesti\u00f3n del riesgo humano","Cumplimiento normativo en seguridad de la informaci\u00f3n"],"areaServed":[{"@type":"Country","name":"Argentina"},{"@type":"Country","name":"Chile"},{"@type":"Country","name":"Colombia"},{"@type":"Country","name":"M\u00e9xico"},{"@type":"Country","name":"Per\u00fa"},{"@type":"Country","name":"Uruguay"},{"@type":"Country","name":"Paraguay"},{"@type":"Country","name":"Ecuador"},{"@type":"Country","name":"Panam\u00e1"},{"@type":"Country","name":"Costa Rica"},{"@type":"Country","name":"Rep\u00fablica Dominicana"},{"@type":"Country","name":"Guatemala"},{"@type":"Country","name":"Bolivia"},{"@type":"Country","name":"Brasil"},{"@type":"Country","name":"Espa\u00f1a"},{"@type":"Country","name":"Portugal"},{"@type":"Country","name":"Italia"}],"slogan":"La plataforma online de concienciaci\u00f3n en Seguridad de la Informaci\u00f3n galardonada internacionalmente, que genera h\u00e1bitos seguros en los usuarios."},{"@type":"Person","@id":"https:\/\/smartfense.com\/en\/#\/schema\/person\/5494c12e79213c554fa449135589c24c","name":"Nicol\u00e1s Bruna","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/b03096bf4c3dd886cfcffd7415eadf6f80d2c8126188409e7d4d1d1b6b911fcb?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/b03096bf4c3dd886cfcffd7415eadf6f80d2c8126188409e7d4d1d1b6b911fcb?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/b03096bf4c3dd886cfcffd7415eadf6f80d2c8126188409e7d4d1d1b6b911fcb?s=96&d=mm&r=g","caption":"Nicol\u00e1s Bruna"},"description":"Product Manager de SMARTFENSE. Su misi\u00f3n en la empresa es mejorar la plataforma d\u00eda a d\u00eda y evangelizar sobre la importancia de la concientizaci\u00f3n. Ha escrito dos whitepapers y m\u00e1s de 150 art\u00edculos sobre gesti\u00f3n del riesgo de la ingenier\u00eda social, creaci\u00f3n de culturas seguras y cumplimiento de normativas. Tambi\u00e9n es uno de los autores de la Gu\u00eda de Ransomware de OWASP y el Calculador de costos de Ransomware, entre otros recursos gratuitos.","sameAs":["https:\/\/www.linkedin.com\/in\/nicolasbruna\/"],"url":"https:\/\/smartfense.com\/en\/author\/nicolas\/"}]}},"_links":{"self":[{"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/posts\/45235","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/comments?post=45235"}],"version-history":[{"count":2,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/posts\/45235\/revisions"}],"predecessor-version":[{"id":45246,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/posts\/45235\/revisions\/45246"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/media\/45230"}],"wp:attachment":[{"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/media?parent=45235"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/categories?post=45235"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/tags?post=45235"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}