Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Automating Phishing Response: 90% MTTR Reduction Case Study

Palo Alto Networks
05/08/2026
19
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


TL;DR

  • A security team handling 1,000 phishing emails monthly spent 40 minutes per incident on manual investigation, consuming hundreds of analyst hours and preventing strategic security work.
  • Managed XSIAM automated the entire phishing response workflow—from context enrichment to enterprise-wide email deletion—reducing mean time to resolve by over 90% (from 40 minutes to 3 minutes).
  • During a 10-day holiday period with the SOC offline, MSIAM autonomously blocked 10 high-severity phishing attacks and processed 400 incidents without human intervention.
  • The shift from traditional MDR (which alerts analysts) to Managed XSIAM (which executes responses) removed an entire class of repetitive work from the SOC queue, freeing experts for higher-value security initiatives.
  • Building trust in automation occurred gradually, with the organization initially retaining manual response control before eventually granting full autonomous response authority after seeing consistent results.

The Manual Phishing Investigation Bottleneck

This case study examines a security organization struggling with approximately 1,000 user-reported phishing emails monthly, with each incident requiring an average of 40 minutes of manual analyst investigation. The five-step manual process—opening emails, checking headers and links, examining attachments, reviewing sender history, and documenting findings—consumed hundreds of analyst hours that could have been directed toward strategic security initiatives like data loss prevention (DLP) implementation. The volume created a dangerous dynamic where analysts faced repetitive, tedious work that increased human error risk while genuine high-severity threats could slip through unnoticed amid the noise of false positives and low-risk reports.

Automated Response with Managed XSIAM

Rather than treating user-reported phishing emails as tickets requiring human review, Managed XSIAM (MSIAM) transformed them into automated triggers that executed pre-designed playbooks. The system pulled context from Microsoft 365, evaluated user risk in real time, checked IP reputation, and calculated severity automatically—then took direct action by deleting high-risk messages from all inboxes across the enterprise without waiting for analyst confirmation. This approach reduced mean time to resolve (MTTR) by over 90%, dropping investigation time from 40 minutes to approximately 3 minutes per incident. The automation proved its value during a holiday period when the SOC was offline: MSIAM autonomously blocked 10 high-severity phishing attacks and processed 400 total incidents without any manual intervention.

Beyond Traditional MDR: Removing Work, Not Just Alerting

The fundamental difference between traditional managed detection and response (MDR) and Managed XSIAM lies in ownership of the response phase. Traditional MDR identifies threats and escalates them to human analysts for decision-making and action, while MSIAM executes the entire response workflow autonomously at machine speed and enterprise scale. This shift required building trust over time—the organization initially allowed automation only for enrichment while retaining manual response control, but eventually handed over full response authority after seeing consistent results. The outcome freed the SOC team to focus on strategic security projects rather than repetitive email analysis, fundamentally changing how the organization allocated its most valuable resource: expert analyst time.

Chapters

0:00 - The 40-Minute Phishing Problem
1:15 - Volume Makes Manual Review Grueling
2:10 - Real-World Stats: 1,000 Incidents Monthly
3:15 - Five Steps of Manual Investigation
4:45 - Analyst Time Slip and Human Error
6:10 - MSIAM Automates End-to-End Response
7:50 - Building Trust in Automation
9:40 - 90% MTTR Reduction Results
11:20 - Managed XSIAM vs Traditional MDR

Key Quotes

0:12 "From there, that analyst is going to spend, on average, about 40 minutes investigating that one email."
0:49 "So much so that they were dealing with roughly 1,000 phishing emails every single month. And at that level of volume, it's no longer a question of if something happens. It becomes a question of when."
2:10 "The fact that they had to manually review 30 to 40 incidents a day actually prevented them from focusing on some of the other security efforts that they deemed as more important, because they had to spend all this time manually investigating and attempting to decipher what is a spam, what is an actual phishing attempt, and what is just a user wrongly reporting one."
6:39 "Instead of these user-reported phishing emails being treated as a ticket, it registered it almost as a trigger."
10:31 "They came back after a week and a half out of the office and they see, I think it was around 10, 10 high severity incidents that we actually caught and completely been blocked automatically. And they essentially had no, they didn't have to do anything manually."
11:22 "The mean time to resolve dropped by more than 90%. This meant that hundreds of hours a month were being given back to the SOC."

Categories:
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Security Operations
  • Email Security
  • Security Automation
  • Technical Deep Dive
  • Customer Story
  • Phishing Automation
  • SOC Efficiency
  • Managed Detection and Response
  • Security Orchestration
  • Mean Time to Resolve
  • Analyst Burnout
  • Automated Response
  • Threat Intelligence
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Automating Phishing Response: 90% MTTR Reduction Case Study

              Upcoming Webinar Calendar

              • 06/10/2026
                11:00 AM
                06/10/2026
                Action1: Vulnerability Digest--Patch Tuesday & Other Updates
                https://www.truthinit.com/index.php/channel/1997/action1-vulnerability-digest-patch-tuesday-other-updates/
              • 06/10/2026
                02:00 PM
                06/10/2026
                Understanding the True Costs of DIY Data Classification vs. Buying Solutions
                https://www.truthinit.com/index.php/channel/1985/understanding-the-true-costs-of-diy-data-classification-vs-buying-solutions/
              • 06/23/2026
                10:00 AM
                06/23/2026
                Stay Informed on the Latest Keepit Partner Developments – June 23
                https://www.truthinit.com/index.php/channel/1990/stay-informed-on-the-latest-keepit-partner-developments-–-june-23/
              • 06/25/2026
                01:00 PM
                06/25/2026
                Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier
                https://www.truthinit.com/index.php/channel/1998/generative-ai-security-preventing-ai-from-becoming-a-data-breach-multiplier/

              Upcoming Events

              • Jun
                10

                Action1: Vulnerability Digest--Patch Tuesday & Other Updates

                06/10/202611:00 AM ET
                • Jun
                  10

                  Understanding the True Costs of DIY Data Classification vs. Buying Solutions

                  06/10/202602:00 PM ET
                  • Jun
                    23

                    Stay Informed on the Latest Keepit Partner Developments – June 23

                    06/23/202610:00 AM ET
                    • Jun
                      25

                      Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier

                      06/25/202601:00 PM ET
                      More events
                      Truth in IT
                      • Sponsor
                      • About Us
                      • Terms of Service
                      • Privacy Policy
                      • Contact Us
                      • Preference Management
                      Desktop version
                      Standard version