Stop Phishing for Needles in a Haystack: How Phish are Crushing Your SOC
Download resourcesAbout this session
Mick Leach, field CISO and head of security operations at Abnormal Security, walks through why security operations teams are being overwhelmed by phishing and business email compromise. He shows how generative AI lets attackers automate convincing, personalized messages in moments rather than the twenty minutes manual research used to take, and demonstrates real emails his company scored as AI-written. He then argues that the three classic defenses are all breaking down: phishing awareness training teaches users to over-report everything as phishing, secure email gateways only catch known-malicious links and attachments, and dumping more logs into the SIEM just adds cost and noise. Drawing on his own experience building an in-house triage tool that failed, he explains why an API-based, behavioral approach that reads message content, models organizational relationships and uses OCR caught attacks his stack had missed, including a sextortion email disguised as a screenshot and a business email compromise attempt against his HR team. He closes with how automating the abuse mailbox cut phishing-report review from twenty hours a week to five minutes.
Key takeaways
- Assume attackers now use generative AI to produce large volumes of personalized, socially-engineered phishing and BEC emails in minutes instead of tens of minutes of manual research each.
- Reconsider punitive phishing-training programs; they drive users to over-report everything as phishing, which overwhelms SOC triage capacity.
- Recognize that secure email gateways only stop known-malicious links and attachments and will miss text-only social engineering and screenshotted ransom messages.
- Automate the abuse mailbox so reported messages are re-scanned automatically, related messages are found and remediated, and users get instant feedback instead of an analyst spending hours per week on triage.
- Favor API-based, behavioral email security that reads message content and models organizational relationships over perimeter tools that only see traffic crossing the gateway.
Speakers

Mick Leach is Field CISO of Abnormal Security, an AI-native email security company that uses behavioral AI to prevent business email compromise, vendor fraud, and other socially engineered attacks. At Abnormal, he is responsible for threat hunting… Read moreRead less
Mick Leach is Field CISO of Abnormal Security, an AI-native email security company that uses behavioral AI to prevent business email compromise, vendor fraud, and other socially engineered attacks. At Abnormal, he is responsible for threat hunting and analysis, engaging with customers, and is a featured speaker at global industry conferences and events. Previously, he led security operations organizations at Abnormal, Alliance Data, and Nationwide Insurance, and also spent more than 8 years serving in the US Army’s famed Cavalry Regiments. A passionate information security practitioner, Mick holds 7 SANS/GIAC certifications, coupled with 20+ years of experience in the IT and security industries. When not digging through logs or discussing operational metrics, Mick can typically be found on a soccer field, coaching one of his 13 kids.
