Generative AI can improve the language, localization, and iteration speed of phishing, but the defensive fundamentals remain concrete: authenticate mail, strengthen identity, verify sensitive requests out of band, detect post-click behavior, and rehearse response.
Current as of 2026-08-15
Microsoft’s 2026 threat analysis describes AI as improving the tempo, iteration, and precision of established attack techniques while noting that humans typically remain involved.
Decision summary
- Do not make a training-only program carry the full defense burden.
- Use phishing-resistant MFA where supported, starting with administrators and high-risk roles.
- Require a verified second channel for payment, payroll, credential, and access changes.
- Monitor mailbox rules, sessions, endpoints, and high-risk sign-ins after a suspected phish.
1. Authenticate and filter email
Configure SPF, DKIM, and DMARC deliberately, monitor failures, and move toward an enforcement policy only after legitimate senders are understood. Layer impersonation, attachment, link, and business-email-compromise protections rather than relying on message wording alone.
2. Strengthen the identity layer
CISA’s small-business MFA guidance recommends aiming for phishing-resistant MFA. Security keys and passkeys reduce exposure to credential replay and adversary-in-the-middle phishing compared with weaker methods.
3. Verify consequential requests
- Call a known contact using a directory number, not a number in the request.
- Require dual approval for bank, payroll, and vendor-master changes.
- Use a pre-agreed phrase or process for executive voice or video requests.
- Record the verification result with the transaction.
4. Detect and contain post-click activity
Centralize email, identity, endpoint, and cloud logs. Alert on new mailbox rules, impossible or unusual sign-ins, suspicious OAuth consent, token reuse, and remote-access tooling. Response should include session revocation and persistence review, not only a password reset.
5. Rehearse the response
Use CISA’s phishing guidance to build role-specific exercises and escalation paths. Measure reporting speed, containment quality, and whether financial verification controls were followed.
Next step for your environment
Map these five controls to owners and test one realistic identity-and-payment scenario end to end. If you need a documented baseline before changing production systems, start with an ITECS technology and security assessment.
Record the current baseline, accountable owner, source date, acceptance evidence, exceptions, and review trigger. Recheck assumptions before every consequential change, preserve rollback instructions, and close the work only when the intended result and unintended effects have been verified in the real environment. Keep the decision record with the system documentation so the next review starts from evidence rather than memory.
Sources and update trigger
- Microsoft Security — Threat actor abuse of AI
- CISA — Require multifactor authentication
- CISA — Phishing guidance
Review trigger: Refresh after material CISA identity guidance or a major change in email and token-theft techniques.
