The end of IOC fatigue: why CISOs need to think in campaigns, not emails

Modern phishing campaigns evolve faster than traditional detection models can respond. To close the gap, CISOs must shift from analysing individual emails to understanding coordinated attack campaigns. Here, Cofense explains why campaign-based detection is becoming essential to phishing defence

Cybersecurity leaders face a growing paradox. Organisations have more threat intelligence, more security tools, and more indicators of compromise (IOCs) than ever before, yet phishing attacks continue to succeed at scale. Security operations centres (SOCs) remain overwhelmed by alerts and manual investigations, while attackers increasingly outpace traditional detection methods.

The problem is not visibility. It is that most security operations are still built to identify isolated malicious artefacts, while modern attackers operate through coordinated, adaptive campaigns.

For years, phishing defence relied on IOC-driven detection. Security teams would identify malicious URLs, sender domain, or file hashes, then block them and quarantine associated emails. That approach worked on relatively static attacks. Today’s phishing is dynamic.

Modern attackers use polymorphic tactics, constantly evolving infrastructure and subject lines, compromising multiple sender accounts, and generating unique-looking emails all supporting the same objective. By the time defenders block one threat, it has shapeshifted.



This creates a critical operational gap: organisations defend phishing at the email level, while attackers operate at campaign scale.

The operational cost of IOC-centric security

Most SOC workflows remain reactive. A suspicious email is reported, analysts investigate it, extract IOCs, create detection rules, and manually search for additional variants. The process is slow, repetitive, and difficult to scale. Detection often resets every time attackers introduce a new variant, leaving security teams stuck in a constant cycle of catching up.

At the same time, attackers are benefitting from automation, generating hundreds of threat variants in hours while analysts still investigate and remediate individually. The result is analyst fatigue, delayed response times with increased breach risk, and fragmented visibility into broader attacks.

Why campaign-based detection changes the equation

The next evolution in phishing defence is campaign-based detection. Instead of asking whether an email contains a known malicious indicator, organisations should analyse whether it structurally resembles a coordinated campaign.

Campaign-based detection focuses on deeper behavioural similarities between messages. Whilst surface-level attributes, URLs or message content may change, campaigns often retain consistent patterns, including delivery behaviour, infrastructure, lure mechanics, and credential harvesting frameworks.

AI and natural language processing technologies are increasingly capable of identifying these relationships, enabling organisations to detect the “DNA” of phishing campaigns rather than relying solely on static indicators.

This shift changes both detection and response. Analysts gain visibility into coordinated attack behaviour, including how rapidly a campaign is spreading, how its infrastructure is evolving, and how broadly recipients are being targeted. More importantly, campaign intelligence enables organisations to respond at scale.

Instead of quarantining single phishing emails, one confirmed indicator can trigger remediation across all related variants simultaneously.

For CISOs, the value is strategic. Campaign-centric detection helps reduce attacker dwell time, improve operational efficiency, accelerate containment decisions, and prioritise analyst attention. Indicators of compromise will remain important, but they are no longer sufficient on their own. Increasingly, the real threat is not the individual phishing email – it is the campaign behind it.



Further information
Produced with support from Cofense. To find out more about Cofense’s AI-powered, campaign-based phishing detection and response solutions, visit www.cofense.com



READ MORE: Burnham warned digital exclusion is now a national security risk‘. ISF chief Steve Durbin says the incoming Prime Minister must put cyber resilience, skills and access to technology at the heart of government or leave Britain exposed to hostile actors.

Do you have news to share or expertise to contribute? The European welcomes insights from business leaders and sector specialists. Get in touch with our editorial team to find out more.

TOP STORIES

The end of IOC fatigue: why CISOs need to think in campaigns, not emails

TOP STORIES