The end of IOC fatigue: why CISOs need to think in campaigns, not emails
Cofense
- Published
- Cybersecurity, Technology

Modern phishing campaigns evolve faster than traditional detection models can respond. To close the gap, CISOs must shift from analysing individual emails to understanding coordinated attack campaigns. Here, Cofense explains why campaign-based detection is becoming essential to phishing defence
Cybersecurity leaders face a growing paradox. Organisations have more threat intelligence, more security tools, and more indicators of compromise (IOCs) than ever before, yet phishing attacks continue to succeed at scale. Security operations centres (SOCs) remain overwhelmed by alerts and manual investigations, while attackers increasingly outpace traditional detection methods.
The problem is not visibility. It is that most security operations are still built to identify isolated malicious artefacts, while modern attackers operate through coordinated, adaptive campaigns.
For years, phishing defence relied on IOC-driven detection. Security teams would identify malicious URLs, sender domain, or file hashes, then block them and quarantine associated emails. That approach worked on relatively static attacks. Today’s phishing is dynamic.
Modern attackers use polymorphic tactics, constantly evolving infrastructure and subject lines, compromising multiple sender accounts, and generating unique-looking emails all supporting the same objective. By the time defenders block one threat, it has shapeshifted.

This creates a critical operational gap: organisations defend phishing at the email level, while attackers operate at campaign scale.
The operational cost of IOC-centric security
Most SOC workflows remain reactive. A suspicious email is reported, analysts investigate it, extract IOCs, create detection rules, and manually search for additional variants. The process is slow, repetitive, and difficult to scale. Detection often resets every time attackers introduce a new variant, leaving security teams stuck in a constant cycle of catching up.
At the same time, attackers are benefitting from automation, generating hundreds of threat variants in hours while analysts still investigate and remediate individually. The result is analyst fatigue, delayed response times with increased breach risk, and fragmented visibility into broader attacks.
Why campaign-based detection changes the equation
The next evolution in phishing defence is campaign-based detection. Instead of asking whether an email contains a known malicious indicator, organisations should analyse whether it structurally resembles a coordinated campaign.
Campaign-based detection focuses on deeper behavioural similarities between messages. Whilst surface-level attributes, URLs or message content may change, campaigns often retain consistent patterns, including delivery behaviour, infrastructure, lure mechanics, and credential harvesting frameworks.
AI and natural language processing technologies are increasingly capable of identifying these relationships, enabling organisations to detect the “DNA” of phishing campaigns rather than relying solely on static indicators.
This shift changes both detection and response. Analysts gain visibility into coordinated attack behaviour, including how rapidly a campaign is spreading, how its infrastructure is evolving, and how broadly recipients are being targeted. More importantly, campaign intelligence enables organisations to respond at scale.
Instead of quarantining single phishing emails, one confirmed indicator can trigger remediation across all related variants simultaneously.
For CISOs, the value is strategic. Campaign-centric detection helps reduce attacker dwell time, improve operational efficiency, accelerate containment decisions, and prioritise analyst attention. Indicators of compromise will remain important, but they are no longer sufficient on their own. Increasingly, the real threat is not the individual phishing email – it is the campaign behind it.
Further information
Produced with support from Cofense. To find out more about Cofense’s AI-powered, campaign-based phishing detection and response solutions, visit www.cofense.com
READ MORE: ‘Burnham warned digital exclusion is now a national security risk‘. ISF chief Steve Durbin says the incoming Prime Minister must put cyber resilience, skills and access to technology at the heart of government or leave Britain exposed to hostile actors.
Do you have news to share or expertise to contribute? The European welcomes insights from business leaders and sector specialists. Get in touch with our editorial team to find out more.
TOP STORIES
-
The five pillars shaping technology-led entertainment platforms -
Ulugbek Mirzamukhamedov on how AI could power the 21st-century economy -
Burnham told to tackle Britain’s cyber weak spots on day one -
Doctors using AI before health systems set the rules -
Humanoid robots could become the next K-pop stars -
Burnham warned digital exclusion is now a national security risk -
GigaCloud and Cubbit launch sovereign cloud storage for Ukraine and Poland -
Scientists crack dinosaur egg mystery by building life-size nest -
WPSL golfers to receive global eSIM access in Yesim partnership -
Former Kyndryl Germany boss joins Infinigate in growth role -
Trump threatens 'immediate 100pc tariffs' on European countries over tech taxes -
Home routers named ‘Europe’s forgotten internet security risk’ -
AI lab says brain-like engine could slash chatbot bills by 98 per cent -
The board challenge: why security is no longer an IT problem -
The fist-bumping, selfie-taking humanoid guide that could usher sightseeing tours into the AI age -
EU says ‘time for change’ on child social media safety after survey links platforms to youth distress -
UK’s under-16s social media ban risks giving parents false comfort, experts warn -
Redefining optical gas detection: how Optronics Group is building the future of industrial safety -
Claude maker Anthropic valued at nearly $1tn after record AI funding round -
NASA to send rabbit-like drones to scout site for first Moon base -
Apollo, Artemis, Ali and Live Aid satellite station set for new Moon role in £37m deal -
Four forces reshaping cyber risk in 2026 -
Siemens expands rail technology arm with Italian deal -
Italy draws global tech investors as Europe races to build its own champions -
Opel turns to Chinese EV technology for new European-built SUV
The end of IOC fatigue: why CISOs need to think in campaigns, not emails
Cofense
- Published
- Cybersecurity, Technology

TOP STORIES
-
The five pillars shaping technology-led entertainment platforms -
Ulugbek Mirzamukhamedov on how AI could power the 21st-century economy -
Burnham told to tackle Britain’s cyber weak spots on day one -
Doctors using AI before health systems set the rules -
Humanoid robots could become the next K-pop stars -
Burnham warned digital exclusion is now a national security risk -
GigaCloud and Cubbit launch sovereign cloud storage for Ukraine and Poland -
Scientists crack dinosaur egg mystery by building life-size nest -
WPSL golfers to receive global eSIM access in Yesim partnership -
Former Kyndryl Germany boss joins Infinigate in growth role -
Trump threatens 'immediate 100pc tariffs' on European countries over tech taxes -
Home routers named ‘Europe’s forgotten internet security risk’ -
AI lab says brain-like engine could slash chatbot bills by 98 per cent -
The board challenge: why security is no longer an IT problem -
The fist-bumping, selfie-taking humanoid guide that could usher sightseeing tours into the AI age -
EU says ‘time for change’ on child social media safety after survey links platforms to youth distress -
UK’s under-16s social media ban risks giving parents false comfort, experts warn -
Redefining optical gas detection: how Optronics Group is building the future of industrial safety -
Claude maker Anthropic valued at nearly $1tn after record AI funding round -
NASA to send rabbit-like drones to scout site for first Moon base -
Apollo, Artemis, Ali and Live Aid satellite station set for new Moon role in £37m deal -
Four forces reshaping cyber risk in 2026 -
Siemens expands rail technology arm with Italian deal -
Italy draws global tech investors as Europe races to build its own champions -
Opel turns to Chinese EV technology for new European-built SUV



























