06/18/2026
AI-driven phishing is now 3x more effective than traditional campaigns (per the 2025 Microsoft Digital Defense Report). Microsoft scans 5 billion emails daily for malware and phishing, and attackers keep finding ways through.
Hard truth, another phishing simulation isn't going to save you. Click rates plateau around 4 to 7% across mature programs. They never hit zero. Because humans aren't the control. Speed is.
If a phish lands in 1,000 inboxes and 30 people click, the question isn't how to get those 30 to stop clicking. The question is, from the moment the first user reports, how fast can your environment contain it for everyone else?
Three metrics actually matter here:
Report rate - the percentage of phish-receiving users who hit Report Message. If it's under 15%, your reporting friction is too high.
Time-to-triage - from report to verdict. Mature SOCs hit under 10 minutes using Defender for Office 365 plus Sentinel automation plus the Security Alert Triage Agent introduced at Ignite 2025.
Time-to-contain - from verdict to organization-wide ZAP. This should be automated, with the playbook pre-authorized for the obvious cases.
Stack the layers. Safe Links rewrites URLs at click time. Safe Attachments detonates payloads in a sandbox. Reporting flows directly into Sentinel. Copilot agents triage at scale, and Microsoft's early data shows analysts detecting malicious emails up to http://6.5x faster with the agent in the loop.
Quick wins this week:
Enable the Security Alert Triage Agent in Defender (E5-inclusive).
Verify Report Message is one click in Outlook desktop, web, mobile, and Teams.
Pre-authorize ZAP and URL blocklisting in your Sentinel playbooks.
Stop measuring training completion. Start measuring containment time.