TL;DR: Phishing and spear phishing remain difficult to contain with technical controls alone, and Knowbe4’s whitepaper argues that pairing AI with user-sourced intelligence can improve proactive detection and response. The governance issue is not just better filtering, but building an operating model that turns people, telemetry, and review processes into a single defense layer.
NHIMG editorial — based on content published by Knowbe4: Whitepaper on the future of phishing defense, AI, and crowdsourcing
Questions worth separating out
Q: How should security teams combine user reporting and AI for phishing defence?
A: Use AI to cluster and prioritise suspicious messages, then use user reports to add context that automated tools often miss.
Q: Why do phishing attacks remain effective even with secure email gateways?
A: Because gateways inspect messages, not human decisions or downstream identity behaviour.
Q: What do organisations get wrong about phishing prevention?
A: They often treat phishing as a training problem instead of an identity control problem.
Practitioner guidance
- Create a single phishing reporting path Route user-reported suspicious messages into the same queue as automated detections so analysts can compare context, sender patterns, and account targets before escalation.
- Connect phishing signals to identity controls When a campaign is confirmed, trigger password resets, session revocation, MFA challenge review, and privileged access checks for exposed accounts instead of treating email defence as a standalone action.
- Measure time from report to containment Track how long it takes from first user report to analyst validation, then from validation to blocking, session termination, or account review.
What's in the full article
Knowbe4's full whitepaper covers the operational detail this post intentionally leaves for the source:
- The specific case for combining AI with crowdsourced user intelligence in phishing defence workflows
- Actionable guidance on building a proactive programme instead of relying only on reactive filtering
- The source's framing of how users can contribute to real-time threat detection without becoming analysts
- The whitepaper's discussion of technology and human resource balance in phishing mitigation
👉 Read Knowbe4's whitepaper on AI-driven phishing defence and user crowdsourcing →
Phishing defense in the AI era: what security teams need to change?
Explore further
Human signal is becoming a core phishing control, not a soft supplement. The article’s central idea is right to treat users as a source of threat intelligence rather than only as the target of training. That matters because phishing detection is increasingly about speed, context, and correlation, and users often see the first anomalous message before automated systems do. For identity teams, that means phishing defence should sit closer to authentication, access review, and incident response than to awareness alone.
A question worth separating out:
Q: How should teams respond when phishing may have exposed an account?
A: Contain the identity first. Reset credentials where needed, revoke active sessions, review MFA status, and check privileged entitlements before assuming the message was harmless. If the account belongs to a sensitive user or admin, prioritise rapid investigation of sign-in history and any downstream access that may already have occurred.
👉 Read our full editorial: AI and crowdsourced intelligence are reshaping phishing defense