惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Jina AI
Jina AI
云风的 BLOG
云风的 BLOG
人人都是产品经理
人人都是产品经理
T
The Blog of Author Tim Ferriss
阮一峰的网络日志
阮一峰的网络日志
罗磊的独立博客
J
Java Code Geeks
博客园 - 聂微东
B
Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
WordPress大学
WordPress大学
腾讯CDC
L
LangChain Blog
Apple Machine Learning Research
Apple Machine Learning Research
Microsoft Azure Blog
Microsoft Azure Blog
D
DataBreaches.Net
The GitHub Blog
The GitHub Blog
美团技术团队
博客园 - Franky
Google DeepMind News
Google DeepMind News
V
V2EX
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
月光博客
月光博客
The Cloudflare Blog

Human Risk Management Blog

Future-Proofing Organizations in the Face of AI What Security Can Learn From Dinosaurs Inside the OS-Aware Phishing Kit Profiling Your Device CyberheistNews Vol 16 #30 [Protect Your Users] AI Hallucinations Are Fueling Phishing Attacks Majority of Organizations Hit by Targeted Impersonation Attacks The Open-Source Paradox: Navigating the New Frontier of AI Supply Chain Risk Introducing The Hybrid Nudge Experience: Outbound Email Security Built for Your Risk Appetite New Phishing Tools Enable Attackers to Easily Bypass Multifactor Authentication From Inbox to Encryption: How Ransomware Delivery Has Evolved Attackers Exploit AI Hallucinations to Send Users to Phishing Sites Warning: ARToken Phishing Kit Automates BEC Attacks The New Face of AI Risk Trust Nothing: Tips to Secure AI Tools and Agents CyberheistNews Vol 16 #29 ClickFix Social Engineering is Now the Leading Malware Delivery Method Beyond the Checkbox: How a Proactive Partnership Led to Turnkey Hazing Compliance Trust, Verify, Protect: Modernizing Email Security for the Cloud Report: Social Engineering Remains a Central Part of AI-assisted Attacks ClickFix Social Engineering is Now the Leading Malware Delivery Method CyberheistNews Vol 16 #28 Your 2026 Phishing by Industry Benchmarks: The Findings on Human Risk Scammers Can Use AI Tools to Pinpoint Your Location Based on a Photo Report: Attackers Are Using AI to Automate Social Engineering Your KnowBe4 Fresh Compliance Plus Content Updates from June 2026 From Awareness to Digital Workforce Security Your KnowBe4 Fresh Content Updates from June 2026 Threat Actor Uses Phishing to Breach Orgs for Ransomware Gangs Invoice Phishing Attacks Are Abusing the Shop App Phishing Campaign Impersonates Interpol to Deliver Ransomware Prompt Injection and the Rise of Agentic Risk Hyper-Targeted Social Engineering Needs Real-Time Video Response Your Email is Protected. Is Your Teams Chat?
Elevating the SOC Experience: Smarter Automation, Richer ...
Haylea Reiner, MBA · 2026-07-24 · via Human Risk Management Blog

Security operations teams face a constant balancing act: stopping sophisticated email threats, maintaining visibility across their attack surface and keeping administrative workflows running smoothly. When security tools operate in silos or rely on rigid, manual processes, friction builds up quickly. This friction consumes valuable time that analysts could spend on higher-priority initiatives.

At KnowBe4, we believe enterprise security should work for you, without the enterprise-grade costs. That’s why we’re introducing three major enhancements across Defend: automated Security Awareness Training (SAT) integration, redesigned Dashboard Intelligence and Natural Language Search.

Together, these updates deliver an ecosystem that automatically aligns awareness training with threat defense, elevates executive-level threat reporting and simplifies incident triage using AI.

1. Seamless Security Awareness and Email Defense

Managing phishing simulations and inbound email defense used to require constant administrative maintenance. Security teams spent valuable hours manually configuring allow/deny lists to ensure simulation emails reached inboxes without triggering security banners or accidental quarantine.

The Automated SAT-Defend Ecosystem

We’ve built a direct, automated connection between KnowBe4 SAT and Defend. When a phishing simulation campaign launches, SAT automatically signals Defend with the necessary metadata, including enrolled users, simulation indicators and campaign timelines.

Key Capabilities:

  • Zero Manual Allow/Deny Lists: Defend automatically identifies active simulation campaigns and configures handling rules for enrolled users on the fly.
  • Granular Handling Tiers: Admins can select exactly how Defend treats simulation emails during an active campaign, ranging from suppressing all banners to displaying benign or educational Teachable Moment alerts.
  • Automatic Expiration and Cleanup: As soon as the simulation window closes, Defend automatically reverts handling logic back to default policies.
  • User-Scoped Application: Rules apply exclusively to active campaign participants rather than affecting the entire tenant.

By connecting awareness training directly to real-time defense mechanisms, organizations ensure a precise, frictionless training experience without administrative overhead.

2. Defend Dashboard Intelligence: Actionable Context at a Glance

Threat volume metrics alone don't tell the whole story. Security leaders need clear context on who is targeting the organization, how authentication mechanisms are performing and what assets are at risk.

Our redesigned Dashboard Intelligence connects the dots across your entire email surface, revealing deep threat context in a visually streamlined console ready for executive review.

What's New:

  • Authentication Health Monitoring: Instant visibility into SPF, DKIM, and DMARC alignment to identify vector gaps before bad actors exploit them.
  • Geographic Attack Origins: Visual mapping of inbound attack sources and infrastructure trends.
  • Top Impersonated Brands: Clear telemetry showing which trusted brand identities attackers are leveraging to deceive end users.
  • Malicious File Type Trends: Breakdown of payload formats being actively stopped by Defend's behavioral AI engines.

Instead of spending hours manually compiling logs into slide decks, admins gain a polished, boardroom-ready display that highlights security ROI and operational posture in real time.

3. AI-Native Investigation with Natural Language Search

As email volume and attack complexity scale, speed is the key metric for effective incident response. Traditional investigation workflows often force analysts through complex, nested filtering menus to find a single message or threat pattern.

Defend now features an AI-native Natural Language Search interface, bringing conversational flexibility directly to your threat investigation workflows.

Why Natural Language Search Changes the Workflow:

  • Instant Filter Translation: Type queries naturally, such as "Show me all dangerous emails containing PDFs sent to Executives this week", and Defend automatically parses, formats and applies the precise search criteria.
  • Eliminated Cognitive Friction: Move seamlessly from detection to triage without navigating space-heavy dropdowns or manual logic toggles.
  • Faster Incident Response: Drastically reduces Mean Time to Triage (MTTT), enabling security teams to pinpoint, analyze and remediate threats in seconds.

The Unified Advantage

These updates reflect our ongoing commitment to building an intelligent, interconnected security ecosystem. By automating administrative tasks between training and defense, expanding visual threat intelligence, and streamlining investigations with AI-driven search, KnowBe4 Defend empowers your security team to stay ahead of evolving threats while operating at peak efficiency.

All three capabilities are rolling out to the KnowBe4 console this week. Contact your representative or explore the console today to see how these features transform your security operations.