Business cost of phishing report – the post-AI update

IRONSCALES has just released the latest research report we undertook for them – The (Higher) Business Cost of Phishing – an update to the first edition we did in October 2022. That earlier report ended up being published a month before ChatGPT was unleashed on an unexpecting world. This new one, therefore, paints a picture of the post-AI impact on phishing, its dynamics within organizations, and the cost curve. You should get a copy.

Without reading the report, what would anticipate the impact to be – logically – based on the different realities at play with AI in the wild for both threat actors and security teams? Here’s some data points / net effects / consequences of AI to mull over:

  • Generative AI supercharges the ability of people to create text quickly, whether they are skilled in writing or not. It’s had a particular “beneficial” effect for threat actors in enabling the composition of near-perfect copy in whatever language is desired, hence eliminating the historical telltale signs of phishing (e.g., spelling mistakes, sloppy writing, grammatical errors, abnormal language patterns).
  • Generative AI greatly reduces the “time to market” for new threat campaigns, enabling the composition of hyper-personalized messages in a fraction of the time it would take a person to write the same message. Collapse of time to market per campaign means that a threat actor can develop and orchestrate a higher number of campaigns in the same amount of time – could be a 10X to 100X impact on the volume of phishing campaigns.
  • It’s easier for threat actors to embrace and deploy new AI capabilities for offensive / attack purposes than it is for organizations to go through a procurement process to assess and deploy defensive capabilities. In general, threat actors can move faster / pivot more quickly … and have greater short term rewards from product / platform volatility versus organizations that value long-term assurance. The differential in comparative decisional and assessment dynamics for AI adoption are significant between the two.
  • AI used by organizations as a defensive play in email security should expect to see faster detection of more threats. It is likely to nullify but not zero-sum / entirely cancel the offensive uplift.
  • Use of AI to create deepfake attacks amplifies the threat to people and organizations. Telling the difference between a phishing email and a real one is trending towards difficult, and once you add facial likeliness in a video call or vocal replication in a voice call, it’s even harder for a human to tell the difference.,

Mix those dynamics together, look at the interplay and interaction between them … and here’s what the research says:

  • Half of organizations now rate phishing as a high or extreme threat, up from one-third in 2022. The shift reflects the impact of AI-generated phishing campaigns that lack the traditional telltale signs employees were trained to spot.
  • AI-powered defenses cut per-incident handling time by 16% (27.5 minutes to 23.2 minutes) and reduced cost per phishing email by 12% ($31.32 to $27.51). Growth in attack volume overwhelmed those gains.
  • Phishing now costs $51,948 per security analyst annually, up 13.6% from $45,726 in 2022. Phishing also consumes 36.5% of security team working hours, up from 33.5% three years ago.
  • 62.5% of respondents say deepfake attacks are immediately disruptive. Deepfake voice and video technology carried the highest “extremely impactful” rating (31.3%) of the emerging threat trends surveyed, signaling that attacks have moved from theoretical to operationally disruptive.

Phishing is almost certainly an issue at your organization. Get a copy of the report for yourself or your security team.

Discover more from Osterman Research

Subscribe now to keep reading and get access to the full archive.

Continue reading