Why the built-in filter is no longer enough
CERT-FR documents it: generative AI has removed the weak signals phishing detection used to rely on — the spelling mistake, the clumsy turn of phrase, the approximate translation. The message now arrives in flawless language, tailored to the target's context and org chart. What remains detectable lies elsewhere: the sending infrastructure, the age of the domain, the absence of any prior exchange.
The layers of protection
Link protection
URLs rewritten and re-analysed at click time, not only on delivery. That is essential: a clean link on arrival can turn malicious two hours later.
Attachment analysis
Detonation in an isolated environment before delivery, with the option to deliver a neutralised version immediately while analysis runs.
Impersonation detection
Identification of CEO fraud attempts and lookalike domains. This category contains neither link nor attachment: only context analysis catches it.
Archiving and continuity
Long-term evidential retention, and access to email even when the main platform is down.
User training
Calibrated simulation campaigns and short, targeted training for those who need it — not one annual session for everyone.
Our position on simulations
A simulation campaign whose purpose is to produce a click rate for a board meeting is useless. The one that matters measures reporting speed: how long between the first message of a campaign arriving and the first alert raised by a user. That figure predicts the severity of the real incident.
Other solutions we operate.
- METAsudoexec
Meta Orchestrator
The layer that sits above endpoint, SIEM, identity, email and network: every signal is enriched by all the others, and every response decision applies across the whole chain at once.
- EDRCrowdStrike
Falcon — Endpoint Detection & Response
Detection and response on endpoints, the foundation of any defence chain. One lightweight agent, one console, and the ability to isolate a machine before the attacker spreads.
- ITPCrowdStrike
Falcon Identity Threat Protection
Monitoring of Active Directory and cloud directories: privilege escalation, forgotten service accounts, abnormal authentication, and conditional blocking in real time.
A question? A project?
Our security specialists are available to you. A NextGen-SOC demonstration, an audit, or simply a conversation — start here.
