Full Report
AI is making phishing attacks more personalized, convincing, and difficult for traditional email filters to detect. Kaseya explains how MSPs can monitor identity, email, and endpoint activity to detect and contain attacks that make it past the inbox. [...]
Analysis Summary
# Best Practices: Defending Against AI-Powered Phishing
## Overview
These practices address the shift from "identifying bad emails" to "detecting malicious behavior." As AI makes phishing emails indistinguishable from legitimate correspondence, organizations must move beyond traditional signature-based filters to a layered defense focusing on identity monitoring, endpoint activity, and behavioral analytics.
## Key Recommendations
### Immediate Actions
1. **Audit Mailbox Rules:** Scan all user accounts for new or suspicious "Forwarding" or "Delete" rules, which attackers use to exfiltrate data and hide their presence.
2. **Enable MFA Hardening:** Move away from SMS/voice MFA. Implement phishing-resistant MFA or, at minimum, enable "Number Matching" to prevent MFA fatigue/push bombing attacks.
3. **Review Public Footprints:** Advise high-value targets (Executives, HR, Finance) to tighten privacy settings on LinkedIn and company "About Us" pages to limit AI reconnaissance data.
### Short-term Improvements (1-3 months)
1. **Implement Impossible Travel Alerts:** Configure identity providers to alert security teams when a single account logs in from geographically distant locations in a short timeframe.
2. **Deploy Behavioral Email Security:** Supplement traditional Secure Email Gateways (SEGs) with AI-based tools that analyze communication patterns rather than just attachments or links.
3. **Update Incident Response (IR) Playbooks:** Ensure playbooks specifically address "Session Token Theft" and "QR Code Phishing," as these bypass traditional login protections.
### Long-term Strategy (3+ months)
1. **Zero Trust Architecture:** Transition toward a model where every access request is verified based on identity, device health, and location, regardless of the user's initial email authentication.
2. **Continuous Identity Monitoring:** Integrate Email, Identity (IdP), and Endpoint (EDR) telemetry into a centralized monitoring system (SIEM/XDR) to catch post-compromise lateral movement.
3. **Advanced Awareness Training:** Shift from generic phishing simulations to "AI-aware" training that teaches users to verify unusual requests via out-of-band communication (e.g., a phone call).
## Implementation Guidance
### For Small Organizations
- Focus on native security features in Microsoft 365 or Google Workspace.
- Enable basic "impossible travel" alerts and strictly enforce MFA for all users.
- Use a reputable Managed Service Provider (MSP) to monitor for anomalies.
### For Medium Organizations
- Implement a dedicated Behavioral Email Security layer (Integrated Cloud Email Security - ICES).
- Conduct quarterly audits of administrative permissions and third-party app integrations (OAuth tokens).
### For Large Enterprises
- Deploy a full XDR (Extended Detection and Response) stack to correlate email alerts with endpoint and network behavior.
- Use automated SOAR (Security Orchestration, Automation, and Response) to instantly revoke sessions when high-risk behavior is detected.
## Configuration Examples
- **Conditional Access Policy:** "Block access from outside of operating countries" + "Require Phishing-Resistant MFA for Global Admins."
- **Exchange Online Rule:** "Prepend a warning tag to emails where the 'From' name matches an internal executive but the 'Sender' address is external."
## Compliance Alignment
- **NIST Cybersecurity Framework (CSF) 2.0:** Aligns with "Protect" (Identity Management) and "Detect" (Continuous Monitoring).
- **CIS Controls (v8):** Supports Control 6 (Access Control Management) and Control 9 (Email and Web Browser Protection).
- **ISO/IEC 27001:** Maps to Annex A controls regarding information security incident management and operational security.
## Common Pitfalls to Avoid
- **Over-reliance on Signatures:** Do not assume an email is safe just because it passed a virus scan; AI-generated content is unique and has no known signature.
- **Ignoring "Impossible Travel":** Dismissing login alerts from strange locations as "VPN usage" without verification.
- **Static Training:** Relying on once-a-year training. AI threats evolve weekly; awareness must be continuous.
## Resources
- **NIST Phishing Guide:** [hXXps://www.nist.gov/itl/applied-cybersecurity/nice/resources/online-learning-content/phishing]
- **CISA MFA Best Practices:** [hXXps://www.cisa.gov/mfa]
- **Kaseya 2026 Email Security Report:** [hXXps://www.kaseya.com/resource/2026-kaseya-email-security-report/] (Defanged)