A third of suspicious emails reported by employees are phishing

33% of emails employees report as phishing are either malicious or highly suspect, according to new research. The finding comes from an analysis of emails reported by employees from organisations across the globe during the first half of 2021, and highlights the efficacy of employee-led efforts in preventing cyber attacks.

Approximately one third of people working for organisations using F-Secure’s email reporting plugin for Microsoft Office 365 submitted over 200 000 emails for analysis during the first half of the year. On average, active users submitted 2.14 emails each during the period.

According to the analysis the most common reason users gave for reporting emails was a suspicious link, which was cited by 59% of users. 54% reported an email because of an incorrect or unexpected sender, and 37% because of suspected spam. 34% of users suspected the use of social engineering in an email, while 7% reported because of a suspicious attachment.

99% of the reports were automatically analysed. Out of those, 33% were classified as phishing. Security professionals manually investigated the remaining 1% of reported emails and determined 63% of those were phishing attempts.

“You often hear that people are security’s weak link. That’s very cynical and doesn’t consider the benefits of using a company’s workforce as a first line of defense,” said F-Secure Director of Consulting Riaan Naude. “Employees can catch a significant number of threats hitting their inbox if they can follow a painless reporting process that produces tangible results.”

Email is the most common method cyber criminals use to spread malware, and accounted for over half of infection attempts in 2020.* While aggressive reporting can clearly combat this problem, there are downsides. For every reported email, a trained professional needs to investigate and respond. Naude estimates this can take anywhere between 15 minutes to an hour depending on professional background and complexity of the particular case.

Considering that 73% of organisations surveyed in a 2019 study from the Ponemon Institute said burnout due to an increasing workload made working in a security operations center (SOC) painful, organisations need to give security teams tools to properly manage the increased workload. 67% of respondents in the study identified automation of workflow as the most important measure to alleviate their SOC team’s pain.

“Manual triage is clearly a burden, and reporting emails initiates this triage process, regardless of whether or not the email is an actual threat. It’s clearly one of those areas where experts need tech to help them scale existing knowledge and skills,” said Naude.

 

To stay up to date on the latest, trends, innovations, people news and company updates within the global security market please register to receive our newsletter here.

Media contact

Rebecca Morpeth Spayne,
Editor, Security Portfolio

Tel: +44 (0) 1622 823 922
Email: [email protected]

About Security Buyer

Security Buyer is the leading authority in global security content, delivering expert news, in-depth articles, exclusive interviews, and industry insights across print, digital, and event platforms. Published 10 times a year, the magazine is a trusted resource for professionals seeking updates and analysis on the latest developments in the security sector.

To submit an article, or for sponsorship opportunities, please contact our team below.

Rebecca Spayne picture 2025

Rebecca Spayne

Managing
EDITOR

Georgina Turner image

Georgina Turner

Sales
Manager

Afua Akoto image - Security Buyer

Afua Akoto

Marketing Manager

Read the Latest Issue

Follow us on X

Follow us on X

Click Here

Follow us on LinkedIn

Follow us on LinkedIn

Click Here

Advertise here

Reach decision makers and amplify your marketing

Advertise here

Click Here

Related News

Product Spotlight - HID

Product Spotlight – HID

Access control is evolving into a smart, responsive platform—integrating embedded apps, IoT, and cybersecurity to deliver…
Genetec

Genetec brings new capabilities to Security Center SaaS

Genetec announced new updates to Security Center SaaS, the company’s enterprise-grade Security-as-a-Service (SaaS) solution..
I-Pro

i-PRO Launches Revamped EMEA Partner Program

i-PRO announced a major expansion of its EMEA Partner Program. The move supports i-PRO’s long-term growth strategy and…
ASIs international

ASIS International Introduces New ANSI-Approved Investigations Standard

ASIS International, a leading authority in security standards, is excited to announce the release of its revised American National Standards.
Gallagher Security and Yusuf Bin Ahmed Kanoo Company Limited sign MOU in Riyadh

Gallagher Security MOU with Yusuf Bin Ahmed Kanoo Company

Gallagher Security is proud to announce the signing of a Memorandum of Understanding (MOU) with Yusuf Bin Ahmed Kanoo Company…
Mike Hurst - Security Buyer

Zygal appoints Mike Hurst CPP CPOI

Zygal, which produces cutting edge AI cloud VMS and monitoring solutions for connecting, managing, and monitoring assets…
Secure Logiq

Secure Logiq expands into APAC

Secure Logiq is heading into the Asia-Pacific region with big plans and a clear focus on Australia and New Zealand. Helping to steer…
Sophos

Sophos Enhances Protection and Incident Response

Sophos announces an update to its Sophos Firewall, now including Sophos NDR Essential, which is free for all customers with an…
Dallmeier

Tenerife Airport relies on video technology

Tenerife Norte-Ciudad de La Laguna Airporthas significantly improved its safety by installing state-of-the-art video technology..
ICT

ICT announces Stewart Meyer as Chief Marketing Officer

Integrated Control Technology (ICT®), a leading provider of intelligent access control, intrusion detection, building automation and…
Scroll to Top