{"id":45755,"date":"2026-09-09T19:24:46","date_gmt":"2026-09-09T17:24:46","guid":{"rendered":"https:\/\/smartfense.com\/?p=45755"},"modified":"2026-09-09T19:25:10","modified_gmt":"2026-09-09T17:25:10","slug":"phishing-report-triage-manual-or-automatic","status":"publish","type":"post","link":"https:\/\/smartfense.com\/en\/blog\/phishing-report-triage-manual-or-automatic\/","title":{"rendered":"From twenty hours to three, what changes when triage stops being manual"},"content":{"rendered":"<p>The month this series has been talking about had 183 emails reported by employees themselves. <a href=\"https:\/\/smartfense.com\/en\/blog\/journey-of-a-reported-email\/\">The previous piece<\/a> followed one of them from the button to the security team\u2019s decision, and that journey took four minutes. This piece looks at the same month from the other side of the desk, back when the triage of phishing reports was still manual work and those 183 emails were opened one by one. The numbers come from one specific organization, the same one as the earlier pieces, and they are not industry averages.<\/p>\n<h2>How much time does it take to classify a reported email by hand?<\/h2>\n<p>Every report asked for exactly the same thing. Open the original email. Review the headers and the sender authentication. Check the reputation of the domain and of every link, one at a time. Analyze the attachments. And only then classify.<\/p>\n<p>Each report took between five and fifteen minutes, depending on how ambiguous the case was. They added up to around twenty hours a month, half a work week spent overwhelmingly on confirming that 160 emails were harmless.<\/p>\n<p>The first step on that list is also the one nobody wants to take. Opening the original email means handling by hand the file somebody reported precisely because it looked dangerous, with all the care that requires, on the computer of whoever is reviewing it.<\/p>\n<p>There is something worse than the total hours, and it is the order. A queue processed by arrival date treats the new supplier\u2019s email and the targeted attack exactly alike, because until somebody opens them there is no way to know which is which. Priority does not exist before classification, so classification is the first thing to get out of the way.<\/p>\n<h2>What work is left when triage is automatic?<\/h2>\n<p>Reports enter the console already resolved. Each one arrives with its verdict, with a risk score from 0 to 100 that also names the band it falls into, and with the detail of what was checked to get there. The listing is still ordered by date, like any inbox, but now it can be filtered by verdict and the severity can be read at a glance, without opening anything.<\/p>\n<blockquote>\n<p>Your team stops classifying emails and starts reviewing decisions.<\/p>\n<\/blockquote>\n<p>The month takes a different shape. The ones flagged as phishing get a close review, and they are few and already arrive with the evidence assembled, while the false alarms get an audit pass to check they are correctly classified. Three hours. The other seventeen go to investigating the confirmed threats, which is the work that person was hired for.<\/p>\n<p>That score should not be confused with the <a href=\"https:\/\/smartfense.com\/en\/blog\/human-risk-score-siem-signals\/\">human risk score<\/a> of the person who reported. One measures how dangerous an email is. The other measures behaviour over time, and reporting counts in your favour.<\/p>\n<h2>Who has the final say on the verdict?<\/h2>\n<p>The analysis proposes and your team decides, and that rests on the mechanics rather than on a promise. Any report can be confirmed or corrected by hand from its own detail view, in one click. If somebody corrects the verdict while the analysis is still running, the person\u2019s correction wins.<\/p>\n<p>The console does not lose track of who decided what either. Every report shows with an icon whether its verdict was left by the automatic analysis or by a person, and that same distinction travels to the exported listing. The name, the time and the classification that was there before the change stay in the report\u2019s audit trail.<\/p>\n<p>That is what answers the question that shows up six months later, when somebody wants to know why an email was classified a certain way. The answer is on record, with an author and a date, and when the author was the analysis the record says so too.<\/p>\n<h2>What happens when the analysis gets it wrong?<\/h2>\n<p>It gets things wrong, the way email security gets things wrong and the way a person gets things wrong at six on a Friday evening. What decides whether that is a problem is how cheap it is to correct the error and how visible the change stays.<\/p>\n<p>The audit pass over the false alarms is that control, and it pays off more with an explicit criterion. A dangerous email filed as a false alarm costs far more than a false alarm treated as phishing, so the review concentrates on one side only rather than on debating the correct calls.<\/p>\n<p>When somebody corrects a verdict, that report stops counting as resolved by the analysis and starts counting as resolved by a person. That is the right reading, and it is also what keeps the month\u2019s tally clean, because what the dashboard presents as automatic classification is exactly what nobody had to touch.<\/p>\n<h2>How do you keep the alerts from overwhelming the team?<\/h2>\n<p>Alerts are controlled with three independent notices, each with its own switch.<\/p>\n<ul>\n<li><strong>New report notice.<\/strong> It fires every time somebody uses the button, without waiting for any analysis.<\/li>\n<li><strong>Alert for phishing confirmed by AI.<\/strong> It goes out when the analysis closes the case as a real attack.<\/li>\n<li><strong>Notice for a false alarm detected by AI.<\/strong> It goes out when the analysis rules the email out.<\/li>\n<\/ul>\n<p>The last two also have their own list of recipients, so the alert about a real attack and the record of a false alarm do not have to reach the same people.<\/p>\n<p>The security lead in this story turned on only one, the confirmed-phishing alert, addressed to her team. The new report notice stayed off, because finding out 183 times a month that somebody reported something changes none of her decisions. The false alarm one stayed off too, because those are 160 emails that need not interrupt anyone in order to close.<\/p>\n<p>A large SOC may want all three on, each with its own recipients. A team of two people may turn none of them on and look at the dashboard once a day. The difference between a tool that helps and one that wears you down is almost always decided by who controls when the phone rings.<\/p>\n<h2>What do you watch on the dashboard once triage no longer eats the month?<\/h2>\n<p>The reports dashboard shows what the automatic classification resolved in the current month, how many reports are still undecided, the most recent analyses and the month-by-month activity of the last six months.<\/p>\n<p>Of those four, the one that says most about the state of the programme is the undecided reports. They are a running total rather than a monthly flow, so one left open three months ago still counts today. That number is the real debt of triage, and with the automatic analysis running it should trend towards zero without anyone working longer hours.<\/p>\n<h2>What changes beyond the hours that get freed up?<\/h2>\n<p>It is easy to read all of this as a productivity calculation, and it is one. Seventeen hours a month are worth what they are worth, and anyone can multiply them by what an hour of their team costs.<\/p>\n<p>But the change that matters is a different one. When triage is manual, how long your organization takes to find out about an attack depends on how big one person\u2019s queue is that week, on whether they are on leave, and on whether the report arrived on a Monday or a Friday. With the classification resolved before anyone looks, containment speed stops being a scheduling variable.<\/p>\n<p>That is how Smart Triage works inside the <a href=\"https:\/\/smartfense.com\/en\/platform\/reports-and-auditing\/\">reporting console<\/a> of SMARTFENSE, on the emails your people report with the button. The notices, the recipients and the level of detail are configured by each organization according to its own protocol.<\/p>\n<p>In the last piece of the series the report stops being a security team matter and returns to the awareness programme, where it changes what each person receives next. And the board\u2019s question arrives.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>How long it takes to classify reported emails by hand, what work is left when triage is automatic, and who has the final say on the verdict.<\/p>\n","protected":false},"author":2,"featured_media":45750,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[3,686],"tags":[2180,2313,454,849,2064],"class_list":["post-45755","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-artificial-intelligence","tag-automation","tag-ciso-en","tag-phishing-en","tag-reporte-de-phishing"],"acf":[],"yoast_head":" \n<title>Phishing report triage, manual or automatic<\/title>\n<meta name=\"description\" content=\"How long it takes to classify reported emails by hand, what work is left when triage is automatic, and who has the final say on the verdict.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/smartfense.com\/en\/blog\/phishing-report-triage-manual-or-automatic\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Phishing report triage, manual or automatic\" \/>\n<meta property=\"og:description\" content=\"How long it takes to classify reported emails by hand, what work is left when triage is automatic, and who has the final say on the verdict.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/smartfense.com\/en\/blog\/phishing-report-triage-manual-or-automatic\/\" \/>\n<meta property=\"og:site_name\" content=\"SMARTFENSE\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-09T17:24:46+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-09T17:25:10+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/smartfense.com\/file\/2026\/09\/hero-en-1.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t<meta property=\"og:image:height\" content=\"1080\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Nicol\u00e1s Bruna\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Nicol\u00e1s Bruna\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/phishing-report-triage-manual-or-automatic\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/phishing-report-triage-manual-or-automatic\\\/\"},\"author\":{\"name\":\"Nicol\u00e1s Bruna\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#\\\/schema\\\/person\\\/5494c12e79213c554fa449135589c24c\"},\"headline\":\"From twenty hours to three, what changes when triage stops being manual\",\"datePublished\":\"2026-09-09T17:24:46+00:00\",\"dateModified\":\"2026-09-09T17:25:10+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/phishing-report-triage-manual-or-automatic\\\/\"},\"wordCount\":1322,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/phishing-report-triage-manual-or-automatic\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/hero-en-1.png\",\"keywords\":[\"artificial intelligence\",\"automation\",\"ciso\",\"phishing\",\"reporte de phishing\"],\"articleSection\":[\"Blog\",\"Blog\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/phishing-report-triage-manual-or-automatic\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/phishing-report-triage-manual-or-automatic\\\/\",\"url\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/phishing-report-triage-manual-or-automatic\\\/\",\"name\":\"Phishing report triage, manual or automatic\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/phishing-report-triage-manual-or-automatic\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/phishing-report-triage-manual-or-automatic\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/hero-en-1.png\",\"datePublished\":\"2026-09-09T17:24:46+00:00\",\"dateModified\":\"2026-09-09T17:25:10+00:00\",\"description\":\"How long it takes to classify reported emails by hand, what work is left when triage is automatic, and who has the final say on the verdict.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/phishing-report-triage-manual-or-automatic\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/phishing-report-triage-manual-or-automatic\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/phishing-report-triage-manual-or-automatic\\\/#primaryimage\",\"url\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/hero-en-1.png\",\"contentUrl\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/hero-en-1.png\",\"width\":1920,\"height\":1080,\"caption\":\"Comparison of the triage month for reported emails, with twenty hours a month of manual triage against three hours of automatic triage and seventeen hours freed up to investigate confirmed threats\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/phishing-report-triage-manual-or-automatic\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Portada\",\"item\":\"https:\\\/\\\/smartfense.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"From twenty hours to three, what changes when triage stops being manual\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/smartfense.com\\\/en\\\/\",\"name\":\"SMARTFENSE - Concienciaci\u00f3n en Ciberseguridad\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/smartfense.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#organization\",\"name\":\"SMARTFENSE\",\"url\":\"https:\\\/\\\/smartfense.com\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2023\\\/08\\\/logo-smartfense-240x40-1.png\",\"contentUrl\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2023\\\/08\\\/logo-smartfense-240x40-1.png\",\"width\":241,\"height\":40,\"caption\":\"SMARTFENSE\"},\"image\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"description\":\"SMARTFENSE es una plataforma SaaS de concienciaci\u00f3n en seguridad de la informaci\u00f3n fundada en 2016. Combina capacitaci\u00f3n interactiva, simulaci\u00f3n de phishing, ransomware, smishing y USB drop, y m\u00e9tricas de riesgo humano. Dise\u00f1ada para Latinoam\u00e9rica, Espa\u00f1a, Portugal e Italia.\",\"foundingDate\":\"2016\",\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/company\\\/smartfense\\\/\"],\"knowsAbout\":[\"Concienciaci\u00f3n en ciberseguridad\",\"Security awareness training\",\"Simulaci\u00f3n de phishing\",\"Simulaci\u00f3n de ransomware\",\"Smishing\",\"Gesti\u00f3n del riesgo humano\",\"Cumplimiento normativo en seguridad de la informaci\u00f3n\"],\"areaServed\":[{\"@type\":\"Country\",\"name\":\"Argentina\"},{\"@type\":\"Country\",\"name\":\"Chile\"},{\"@type\":\"Country\",\"name\":\"Colombia\"},{\"@type\":\"Country\",\"name\":\"M\u00e9xico\"},{\"@type\":\"Country\",\"name\":\"Per\u00fa\"},{\"@type\":\"Country\",\"name\":\"Uruguay\"},{\"@type\":\"Country\",\"name\":\"Paraguay\"},{\"@type\":\"Country\",\"name\":\"Ecuador\"},{\"@type\":\"Country\",\"name\":\"Panam\u00e1\"},{\"@type\":\"Country\",\"name\":\"Costa Rica\"},{\"@type\":\"Country\",\"name\":\"Rep\u00fablica Dominicana\"},{\"@type\":\"Country\",\"name\":\"Guatemala\"},{\"@type\":\"Country\",\"name\":\"Bolivia\"},{\"@type\":\"Country\",\"name\":\"Brasil\"},{\"@type\":\"Country\",\"name\":\"Espa\u00f1a\"},{\"@type\":\"Country\",\"name\":\"Portugal\"},{\"@type\":\"Country\",\"name\":\"Italia\"}],\"slogan\":\"La plataforma online de concienciaci\u00f3n en Seguridad de la Informaci\u00f3n galardonada internacionalmente, que genera h\u00e1bitos seguros en los usuarios.\",\"founder\":{\"@type\":\"Person\",\"name\":\"Mauro Graziosi\",\"jobTitle\":\"CEO\",\"sameAs\":\"https:\\\/\\\/www.linkedin.com\\\/in\\\/mgraziosi\\\/\"},\"employee\":[{\"@type\":\"Person\",\"name\":\"Mauro Graziosi\",\"jobTitle\":\"CEO\",\"sameAs\":\"https:\\\/\\\/www.linkedin.com\\\/in\\\/mgraziosi\\\/\"},{\"@type\":\"Person\",\"name\":\"Mauro S\u00e1nchez\",\"jobTitle\":\"CTO\",\"sameAs\":\"https:\\\/\\\/www.linkedin.com\\\/in\\\/maurolsanchez\\\/\"},{\"@type\":\"Person\",\"name\":\"Leonardo Bally\",\"jobTitle\":\"COO\",\"sameAs\":\"https:\\\/\\\/www.linkedin.com\\\/in\\\/lbally\\\/\"},{\"@type\":\"Person\",\"name\":\"Nicol\u00e1s Bruna\",\"jobTitle\":\"Chief Product Officer\",\"sameAs\":\"https:\\\/\\\/www.linkedin.com\\\/in\\\/nicolasbruna\\\/\"},{\"@type\":\"Person\",\"name\":\"Carla Caggiano\",\"jobTitle\":\"Chief Content Officer\",\"sameAs\":\"https:\\\/\\\/www.linkedin.com\\\/in\\\/carla-v-caggiano\\\/\"},{\"@type\":\"Person\",\"name\":\"Salom\u00e9 Carpio\",\"jobTitle\":\"Global Head of Sales\",\"sameAs\":\"https:\\\/\\\/www.linkedin.com\\\/in\\\/salome-carpio\\\/\"},{\"@type\":\"Person\",\"name\":\"Andr\u00e9s Lista\",\"jobTitle\":\"Global Head of Alliances\",\"sameAs\":\"https:\\\/\\\/www.linkedin.com\\\/in\\\/andreslista\\\/\"},{\"@type\":\"Person\",\"name\":\"Ezequiel Azzarini\",\"jobTitle\":\"Sales Development Director\",\"sameAs\":\"https:\\\/\\\/www.linkedin.com\\\/in\\\/ezequielazzarini\\\/\"},{\"@type\":\"Person\",\"name\":\"Emilia Pal\u00e1\",\"jobTitle\":\"Head of People & Culture\",\"sameAs\":\"https:\\\/\\\/www.linkedin.com\\\/in\\\/mariaemiliapala\\\/\"},{\"@type\":\"Person\",\"name\":\"Florencia Carmel\u00e9\",\"jobTitle\":\"Administration Manager\",\"sameAs\":\"https:\\\/\\\/www.linkedin.com\\\/in\\\/mar%C3%ADa-florencia-carmele\\\/\"},{\"@type\":\"Person\",\"name\":\"Carolina Barlatay\",\"jobTitle\":\"Finance Manager\",\"sameAs\":\"https:\\\/\\\/www.linkedin.com\\\/in\\\/carolina-barlatay\\\/\"},{\"@type\":\"Person\",\"name\":\"Valeria Carena\",\"jobTitle\":\"Compliance Manager\",\"sameAs\":\"https:\\\/\\\/www.linkedin.com\\\/in\\\/valeriacarena\\\/\"}],\"numberOfEmployees\":{\"@type\":\"QuantitativeValue\",\"value\":63},\"address\":{\"@type\":\"PostalAddress\",\"streetAddress\":\"C\\\/ Santos Ovejero 1, Despacho P1-03\",\"addressLocality\":\"Le\u00f3n\",\"addressRegion\":\"Castilla y Le\u00f3n\",\"postalCode\":\"24008\",\"addressCountry\":\"ES\"},\"foundingLocation\":{\"@type\":\"Place\",\"address\":{\"@type\":\"PostalAddress\",\"addressRegion\":\"C\u00f3rdoba\",\"addressCountry\":\"AR\"}}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#\\\/schema\\\/person\\\/5494c12e79213c554fa449135589c24c\",\"name\":\"Nicol\u00e1s Bruna\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/b03096bf4c3dd886cfcffd7415eadf6f80d2c8126188409e7d4d1d1b6b911fcb?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/b03096bf4c3dd886cfcffd7415eadf6f80d2c8126188409e7d4d1d1b6b911fcb?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/b03096bf4c3dd886cfcffd7415eadf6f80d2c8126188409e7d4d1d1b6b911fcb?s=96&d=mm&r=g\",\"caption\":\"Nicol\u00e1s Bruna\"},\"description\":\"Product Manager de SMARTFENSE. Su misi\u00f3n en la empresa es mejorar la plataforma d\u00eda a d\u00eda y evangelizar sobre la importancia de la concientizaci\u00f3n. Ha escrito dos whitepapers y m\u00e1s de 150 art\u00edculos sobre gesti\u00f3n del riesgo de la ingenier\u00eda social, creaci\u00f3n de culturas seguras y cumplimiento de normativas. Tambi\u00e9n es uno de los autores de la Gu\u00eda de Ransomware de OWASP y el Calculador de costos de Ransomware, entre otros recursos gratuitos.\",\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/nicolasbruna\\\/\"],\"url\":\"https:\\\/\\\/smartfense.com\\\/en\\\/author\\\/nicolas\\\/\"}]}<\/script>\n ","yoast_head_json":{"title":"Phishing report triage, manual or automatic","description":"How long it takes to classify reported emails by hand, what work is left when triage is automatic, and who has the final say on the verdict.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/smartfense.com\/en\/blog\/phishing-report-triage-manual-or-automatic\/","og_locale":"en_US","og_type":"article","og_title":"Phishing report triage, manual or automatic","og_description":"How long it takes to classify reported emails by hand, what work is left when triage is automatic, and who has the final say on the verdict.","og_url":"https:\/\/smartfense.com\/en\/blog\/phishing-report-triage-manual-or-automatic\/","og_site_name":"SMARTFENSE","article_published_time":"2026-09-09T17:24:46+00:00","article_modified_time":"2026-09-09T17:25:10+00:00","og_image":[{"width":1920,"height":1080,"url":"https:\/\/smartfense.com\/file\/2026\/09\/hero-en-1.png","type":"image\/png"}],"author":"Nicol\u00e1s Bruna","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Nicol\u00e1s Bruna","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/smartfense.com\/en\/blog\/phishing-report-triage-manual-or-automatic\/#article","isPartOf":{"@id":"https:\/\/smartfense.com\/en\/blog\/phishing-report-triage-manual-or-automatic\/"},"author":{"name":"Nicol\u00e1s Bruna","@id":"https:\/\/smartfense.com\/en\/#\/schema\/person\/5494c12e79213c554fa449135589c24c"},"headline":"From twenty hours to three, what changes when triage stops being manual","datePublished":"2026-09-09T17:24:46+00:00","dateModified":"2026-09-09T17:25:10+00:00","mainEntityOfPage":{"@id":"https:\/\/smartfense.com\/en\/blog\/phishing-report-triage-manual-or-automatic\/"},"wordCount":1322,"commentCount":0,"publisher":{"@id":"https:\/\/smartfense.com\/en\/#organization"},"image":{"@id":"https:\/\/smartfense.com\/en\/blog\/phishing-report-triage-manual-or-automatic\/#primaryimage"},"thumbnailUrl":"https:\/\/smartfense.com\/file\/2026\/09\/hero-en-1.png","keywords":["artificial intelligence","automation","ciso","phishing","reporte de phishing"],"articleSection":["Blog","Blog"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/smartfense.com\/en\/blog\/phishing-report-triage-manual-or-automatic\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/smartfense.com\/en\/blog\/phishing-report-triage-manual-or-automatic\/","url":"https:\/\/smartfense.com\/en\/blog\/phishing-report-triage-manual-or-automatic\/","name":"Phishing report triage, manual or automatic","isPartOf":{"@id":"https:\/\/smartfense.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/smartfense.com\/en\/blog\/phishing-report-triage-manual-or-automatic\/#primaryimage"},"image":{"@id":"https:\/\/smartfense.com\/en\/blog\/phishing-report-triage-manual-or-automatic\/#primaryimage"},"thumbnailUrl":"https:\/\/smartfense.com\/file\/2026\/09\/hero-en-1.png","datePublished":"2026-09-09T17:24:46+00:00","dateModified":"2026-09-09T17:25:10+00:00","description":"How long it takes to classify reported emails by hand, what work is left when triage is automatic, and who has the final say on the verdict.","breadcrumb":{"@id":"https:\/\/smartfense.com\/en\/blog\/phishing-report-triage-manual-or-automatic\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/smartfense.com\/en\/blog\/phishing-report-triage-manual-or-automatic\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/smartfense.com\/en\/blog\/phishing-report-triage-manual-or-automatic\/#primaryimage","url":"https:\/\/smartfense.com\/file\/2026\/09\/hero-en-1.png","contentUrl":"https:\/\/smartfense.com\/file\/2026\/09\/hero-en-1.png","width":1920,"height":1080,"caption":"Comparison of the triage month for reported emails, with twenty hours a month of manual triage against three hours of automatic triage and seventeen hours freed up to investigate confirmed threats"},{"@type":"BreadcrumbList","@id":"https:\/\/smartfense.com\/en\/blog\/phishing-report-triage-manual-or-automatic\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Portada","item":"https:\/\/smartfense.com\/en\/"},{"@type":"ListItem","position":2,"name":"From twenty hours to three, what changes when triage stops being manual"}]},{"@type":"WebSite","@id":"https:\/\/smartfense.com\/en\/#website","url":"https:\/\/smartfense.com\/en\/","name":"SMARTFENSE - Concienciaci\u00f3n en Ciberseguridad","description":"","publisher":{"@id":"https:\/\/smartfense.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/smartfense.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/smartfense.com\/en\/#organization","name":"SMARTFENSE","url":"https:\/\/smartfense.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/smartfense.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/smartfense.com\/file\/2023\/08\/logo-smartfense-240x40-1.png","contentUrl":"https:\/\/smartfense.com\/file\/2023\/08\/logo-smartfense-240x40-1.png","width":241,"height":40,"caption":"SMARTFENSE"},"image":{"@id":"https:\/\/smartfense.com\/en\/#\/schema\/logo\/image\/"},"description":"SMARTFENSE es una plataforma SaaS de concienciaci\u00f3n en seguridad de la informaci\u00f3n fundada en 2016. Combina capacitaci\u00f3n interactiva, simulaci\u00f3n de phishing, ransomware, smishing y USB drop, y m\u00e9tricas de riesgo humano. Dise\u00f1ada para Latinoam\u00e9rica, Espa\u00f1a, Portugal e Italia.","foundingDate":"2016","sameAs":["https:\/\/www.linkedin.com\/company\/smartfense\/"],"knowsAbout":["Concienciaci\u00f3n en ciberseguridad","Security awareness training","Simulaci\u00f3n de phishing","Simulaci\u00f3n de ransomware","Smishing","Gesti\u00f3n del riesgo humano","Cumplimiento normativo en seguridad de la informaci\u00f3n"],"areaServed":[{"@type":"Country","name":"Argentina"},{"@type":"Country","name":"Chile"},{"@type":"Country","name":"Colombia"},{"@type":"Country","name":"M\u00e9xico"},{"@type":"Country","name":"Per\u00fa"},{"@type":"Country","name":"Uruguay"},{"@type":"Country","name":"Paraguay"},{"@type":"Country","name":"Ecuador"},{"@type":"Country","name":"Panam\u00e1"},{"@type":"Country","name":"Costa Rica"},{"@type":"Country","name":"Rep\u00fablica Dominicana"},{"@type":"Country","name":"Guatemala"},{"@type":"Country","name":"Bolivia"},{"@type":"Country","name":"Brasil"},{"@type":"Country","name":"Espa\u00f1a"},{"@type":"Country","name":"Portugal"},{"@type":"Country","name":"Italia"}],"slogan":"La plataforma online de concienciaci\u00f3n en Seguridad de la Informaci\u00f3n galardonada internacionalmente, que genera h\u00e1bitos seguros en los usuarios.","founder":{"@type":"Person","name":"Mauro Graziosi","jobTitle":"CEO","sameAs":"https:\/\/www.linkedin.com\/in\/mgraziosi\/"},"employee":[{"@type":"Person","name":"Mauro Graziosi","jobTitle":"CEO","sameAs":"https:\/\/www.linkedin.com\/in\/mgraziosi\/"},{"@type":"Person","name":"Mauro S\u00e1nchez","jobTitle":"CTO","sameAs":"https:\/\/www.linkedin.com\/in\/maurolsanchez\/"},{"@type":"Person","name":"Leonardo Bally","jobTitle":"COO","sameAs":"https:\/\/www.linkedin.com\/in\/lbally\/"},{"@type":"Person","name":"Nicol\u00e1s Bruna","jobTitle":"Chief Product Officer","sameAs":"https:\/\/www.linkedin.com\/in\/nicolasbruna\/"},{"@type":"Person","name":"Carla Caggiano","jobTitle":"Chief Content Officer","sameAs":"https:\/\/www.linkedin.com\/in\/carla-v-caggiano\/"},{"@type":"Person","name":"Salom\u00e9 Carpio","jobTitle":"Global Head of Sales","sameAs":"https:\/\/www.linkedin.com\/in\/salome-carpio\/"},{"@type":"Person","name":"Andr\u00e9s Lista","jobTitle":"Global Head of Alliances","sameAs":"https:\/\/www.linkedin.com\/in\/andreslista\/"},{"@type":"Person","name":"Ezequiel Azzarini","jobTitle":"Sales Development Director","sameAs":"https:\/\/www.linkedin.com\/in\/ezequielazzarini\/"},{"@type":"Person","name":"Emilia Pal\u00e1","jobTitle":"Head of People & Culture","sameAs":"https:\/\/www.linkedin.com\/in\/mariaemiliapala\/"},{"@type":"Person","name":"Florencia Carmel\u00e9","jobTitle":"Administration Manager","sameAs":"https:\/\/www.linkedin.com\/in\/mar%C3%ADa-florencia-carmele\/"},{"@type":"Person","name":"Carolina Barlatay","jobTitle":"Finance Manager","sameAs":"https:\/\/www.linkedin.com\/in\/carolina-barlatay\/"},{"@type":"Person","name":"Valeria Carena","jobTitle":"Compliance Manager","sameAs":"https:\/\/www.linkedin.com\/in\/valeriacarena\/"}],"numberOfEmployees":{"@type":"QuantitativeValue","value":63},"address":{"@type":"PostalAddress","streetAddress":"C\/ Santos Ovejero 1, Despacho P1-03","addressLocality":"Le\u00f3n","addressRegion":"Castilla y Le\u00f3n","postalCode":"24008","addressCountry":"ES"},"foundingLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressRegion":"C\u00f3rdoba","addressCountry":"AR"}}},{"@type":"Person","@id":"https:\/\/smartfense.com\/en\/#\/schema\/person\/5494c12e79213c554fa449135589c24c","name":"Nicol\u00e1s Bruna","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/b03096bf4c3dd886cfcffd7415eadf6f80d2c8126188409e7d4d1d1b6b911fcb?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/b03096bf4c3dd886cfcffd7415eadf6f80d2c8126188409e7d4d1d1b6b911fcb?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/b03096bf4c3dd886cfcffd7415eadf6f80d2c8126188409e7d4d1d1b6b911fcb?s=96&d=mm&r=g","caption":"Nicol\u00e1s Bruna"},"description":"Product Manager de SMARTFENSE. Su misi\u00f3n en la empresa es mejorar la plataforma d\u00eda a d\u00eda y evangelizar sobre la importancia de la concientizaci\u00f3n. Ha escrito dos whitepapers y m\u00e1s de 150 art\u00edculos sobre gesti\u00f3n del riesgo de la ingenier\u00eda social, creaci\u00f3n de culturas seguras y cumplimiento de normativas. Tambi\u00e9n es uno de los autores de la Gu\u00eda de Ransomware de OWASP y el Calculador de costos de Ransomware, entre otros recursos gratuitos.","sameAs":["https:\/\/www.linkedin.com\/in\/nicolasbruna\/"],"url":"https:\/\/smartfense.com\/en\/author\/nicolas\/"}]}},"_links":{"self":[{"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/posts\/45755","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/comments?post=45755"}],"version-history":[{"count":1,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/posts\/45755\/revisions"}],"predecessor-version":[{"id":45760,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/posts\/45755\/revisions\/45760"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/media\/45750"}],"wp:attachment":[{"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/media?parent=45755"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/categories?post=45755"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/tags?post=45755"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}