Join our Newsletter — 33% off our NHI Course

Threat Reporting

Threat reporting is the act of employees identifying and escalating suspicious activity, such as phishing attempts or unusual messages. In a mature human risk programme, stronger reporting is a useful signal that people are engaged and willing to participate in defense. It also gives security teams earlier visibility into active risk.

What threat reporting really measures

Threat reporting is less about the count of suspicious emails or messages than about whether people notice, trust their instincts, and escalate early enough for security teams to act. A strong reporting culture turns employees into a detection layer that can surface phishing, impersonation, and unusual communication patterns before they become incidents.

That makes the term useful as both a behavioural signal and an operational one. It indicates whether awareness training, reporting channels, and response workflows are actually being used in practice, not just documented on paper.

In mature programmes, reporting quality matters as much as volume. A report that contains enough context to triage quickly is more valuable than a high number of vague or duplicate reports, because the security team can separate genuine campaigns from everyday noise faster.

Why reporting speed and quality matter

Threat reporting only helps when escalation is fast enough to preserve evidence and contain the issue. Early employee reporting can expose an active phishing wave, a brand impersonation attempt, or a suspicious internal message while the attacker is still using the same infrastructure.

The practical value comes from narrowing the window between first contact and defensive action. If reports are delayed, incomplete, or routed through too many handoffs, security teams lose time, analysts get flooded, and the original threat may spread further through accounts, inboxes, or collaboration tools.

Reporting also improves detection coverage. Human observers often see the first sign of social engineering, and their reports can help teams tune filters, block sender patterns, and identify broader campaigns that automated controls missed.

How threat reporting fits a human risk programme

In a human risk programme, reporting is a participation signal. Employees who report suspicious activity show engagement, but the organisation should care just as much about what happens after the report arrives: triage, validation, communication, and feedback to the reporter.

The most effective programmes make reporting easy and low-friction, then close the loop so people know the signal mattered. That reinforces the behaviour and increases the likelihood that staff will keep escalating borderline cases instead of ignoring them.

The term also sits alongside broader security awareness and incident reporting disciplines. It is not a substitute for technical controls, but it is a practical complement to them because it surfaces context that logs alone may not capture, especially in phishing and impersonation scenarios.

As a benchmark for how serious identity abuse can become once malicious content reaches users, NHIMG’s Ultimate Guide to NHIs notes that 80% of identity breaches involved compromised non-human identities such as service accounts and API keys, underscoring why early human reporting of suspicious activity matters before a wider compromise takes hold.

What good threat reports contain

A useful report usually includes the suspicious message or activity itself, the time it was seen, who received it, and any notable details such as sender addresses, links, attachments, or unusual requests. The point is not perfection, but enough fidelity for triage without forcing the reporter to become an analyst.

Good reporting workflows preserve the original evidence and avoid unnecessary rewriting by the employee. That matters because small details, such as subject lines, link structure, or reply-to anomalies, can be decisive in determining whether a message is a one-off nuisance or part of a broader campaign.

Teams should also expect that some reports will be false alarms. That is not a failure of the programme, it is part of how a healthy reporting culture works. The real failure is when people stop reporting because they believe nothing will happen or that they will be blamed for raising the wrong alert.

Risk and Threat Considerations

Threat reporting reduces exposure only when suspicious activity is surfaced early and handled consistently. If employees do not report, or if reports disappear into slow triage, phishing, impersonation, and social engineering campaigns can continue long enough to steal credentials, trigger fraud, or establish deeper access.

Failure mechanism: The control fails when human detection exists but the organisation does not convert it into timely defensive action, allowing attacker messaging, links, or requests to keep circulating after the first warning signs appear.

Impact: Delayed escalation can increase the chance of account compromise, wider user exposure, and missed opportunities to block the same lure across the rest of the environment.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
CIS Controls v8 18.2 — User Awareness and Skills Training Threat reporting depends on trained users recognizing and escalating suspicious activity.
17.4 — Incident Response Testing Reporting is only useful if escalation and triage pathways work under pressure.
Recommendation — Reinforce reporting cues in awareness training and teach users how to escalate suspicious messages quickly. Test reporting workflows in exercises so suspicious activity reaches responders without delay.
NIST CSF 2.0 RS.AN-1 — Analysis Reported threats must be analyzed to determine scope, severity, and response.
DE.CM-8 — Monitoring for Unusual Behavior Employee reports extend monitoring by surfacing unusual messages and activity humans notice first.
RS.CO-2 — Incident Reporting Threat reporting is a direct form of incident reporting from users into the response process.
Recommendation — Analyze user-reported activity promptly and correlate it with telemetry to determine impact. Use reported suspicious activity as an input to continuous monitoring and detection tuning. Define a simple reporting path that routes suspicious activity to the incident response team.

Practitioner Guidance

What to watch for: Treat reporting volume, report quality, and time-to-triage as separate signals. A programme with high awareness but poor follow-through often looks healthy on the surface while still missing active threats.

Practitioner takeaway: The best threat reporting programmes make escalation simple, preserve evidence automatically where possible, and feed outcomes back to employees so reporting becomes a habit rather than a one-time exercise.