Skip to content
  • Home
  • Resources
  • Blog
  • Why are your employees reporting so many emails? And what to do.

Why are your employees reporting so many emails? And what to do.

Stick figure whose visibly stressed standing in a pile of reported emails as more fly at him from the abyss

A lot of MSPs have had the same thought at some point: "Our users report absolutely everything." A marketing newsletter. A calendar invite. An email from Microsoft. A legitimate DocuSign request. If it lands in an inbox, there's a good chance someone will click the "Report Phishing" button just to be safe.

This seems like a great problem to have, right? Wrong. More reported emails mean more investigations, more time spent on phishing analysis, and more pressure on already busy technicians. It can even make you wonder whether your Cybersecurity Awareness Training has gone a little too far. In reality, the opposite is usually true.

An employee who occasionally reports a legitimate email is demonstrating exactly the kind of cautious behavior you want to encourage. The real concern isn't users who report too much. It's users who never report anything at all. They may be confidently spotting every phishing attempt... or they may be confidently clicking every phishing attempt. Unfortunately, those two people can look exactly the same until something goes very wrong. Like that old riddle with identical guards standing in front of identical doors, but one leads to heaven and the other leads to a security breach and your boss calling you an idiot.

The challenge for MSPs isn't reducing the number of reported emails. It's finding a way to process them efficiently without creating an operational headache. Here's why high reporting rates are often a sign of success, and how you can manage the extra workload without discouraging the very behavior you've worked so hard to build.

 

Why Do Employees Report Legitimate Emails?

The goal of Cybersecurity Awareness Training isn't to turn every employee into a cybersecurity analyst. It's to help people recognize when something doesn't feel quite right and give them a safe, simple way to respond.

Most employees aren't expected to inspect email headers, verify SPF records, or investigate sender infrastructure. They're expected to pause, think critically, and ask for help when they're unsure.

As people become more security conscious, their tolerance for uncertainty naturally decreases. An email that they would have ignored six months ago might now prompt them to stop and think, "This looks a little unusual, but I don’t want to spend time digging so I’ll just report it." That's not a failure of training. It's evidence that the training is changing behavior, which is exactly what it should do.

The psychology behind this is pretty straightforward. Most employees understand that the consequences of missing a phishing email are far greater than the consequences of reporting a legitimate one (something that it will serve bosses well to remember, too!) Faced with uncertainty, choosing the safer option becomes the obvious decision. Like a smoke alarm that goes off when you’re making toast - it’s mildly annoying, but you know it’s never going to let you sleep through an actual fire.

 

Why More Phishing Reports Usually Mean Training Is Working

One of the biggest misconceptions around phishing reporting is that fewer reports automatically mean users are getting better at spotting threats. In reality, the opposite can often be true.

Effective Cybersecurity Awareness Training and regular phishing simulations don't simply improve recognition. They create habits. Employees learn to pause before clicking, question unexpected requests, and seek guidance when they're unsure. Reporting suspicious emails becomes part of their normal workflow rather than something they only do when they're absolutely convinced an email is malicious.

That's exactly what you want.

Think about the alternative. If nobody ever reports suspicious emails, there are only a few possible explanations. Perhaps your organization genuinely never receives phishing emails, which seems optimistic at best. More likely, employees are deleting suspicious messages without telling anyone, or worse, interacting with them without realizing there's a problem.

High reporting rates often indicate a healthy security culture. Employees know they're expected to speak up. They trust that reporting something "just in case" won't get them into trouble. Most importantly, they understand that security is everyone's responsibility, not just IT's.

Those reports can also provide valuable early warning signs. A phishing campaign that initially targets one employee rarely stays confined to a single inbox. The first reported email may give your technicians enough time to identify the threat and protect other users before anyone clicks a malicious link or opens a dangerous attachment.

 

The Hidden Cost of False Positives

Of course, none of this means false positives are free.

Every reported email requires time and attention. For MSPs managing multiple clients, those investigations quickly add up. Technicians may spend a significant portion of their day reviewing perfectly legitimate marketing emails, password reset notifications, invoices, or collaboration requests.

The operational impact is real. Time spent analyzing harmless emails is time that can't be spent resolving support tickets, strengthening client security, or responding to genuine threats. As reporting volumes increase, response times can also suffer if investigation processes remain entirely manual.

Your senior technicians didn't spend years learning about SPF, DKIM, and DMARC just to become the world's foremost expert on identifying harmless Mailchimp newsletters. The important thing to remember, however, is that the users aren't creating the problem. They're doing exactly what you've trained them to do. The bottleneck is the process used to investigate those reports.

 

Don't Solve the Wrong Problem

When investigation queues become overwhelming, it's tempting to look for ways to reduce the number of reported emails - but that’s the wrong approach. Some organizations unintentionally discourage reporting by reminding employees not to submit "obvious" legitimate emails or by making them feel guilty for creating extra work for IT. While that may reduce the volume of reports, it also increases the likelihood that genuinely suspicious emails go unreported.

Employees aren't security professionals. They don't always know what's obvious and what isn't. If someone hesitates because they're worried about bothering IT, you've introduced a new risk into your security program. It's always better to investigate several legitimate emails than to miss the one phishing email that leads to compromised credentials or ransomware.

 

What Healthy Phishing Reporting Looks Like

Many MSPs ask what a "normal" phishing reporting rate looks like, but there's no universal benchmark. Reporting volumes vary depending on the size of the organization, the types of attacks being received, the maturity of your training program, and even what's happening in the wider threat landscape.

Instead of focusing on a specific number, it's often more useful to look for behavioral trends. Healthy organizations typically see reporting increase after new Cybersecurity Awareness Training sessions or phishing simulations, followed by consistently steady reporting as security awareness becomes part of everyday behaviour. Employees report suspicious emails without hesitation, and technicians can review those reports quickly enough that users continue to receive timely feedback. So faster, more efficient analysis is your actual goal, rather than an overall reduction in reports.

“We want the user to feel like they can report any email and, even if it’s non-malicious, still get an answer… whether or not it’s malicious.” - Ethan Earl, Resonant Technology Partners

 

 

How to Reduce False Positive Workloads Without Reducing Reporting

Rather than discouraging reporting, MSPs should focus on reducing the amount of manual effort required to process each reported email. The first step is continuing to educate users. Training should help employees recognize common phishing indicators while reinforcing an important message: if you're unsure, report it anyway. Confidence is valuable, but overconfidence creates risk.

Providing feedback is equally important. When users report legitimate emails, let them know. When they correctly identify a phishing attempt, celebrate it. That feedback loop helps employees improve their judgement over time while reinforcing positive security behaviors.

Every false positive represents an employee who stopped, questioned what they were seeing, and chose the safer option. That's exactly the behavior security awareness training is designed to encourage. The goal isn't to eliminate those reports. It's to make reviewing them so quick and efficient that encouraging them becomes an easy decision.

Finally, look for opportunities to automate repetitive analysis. This is where tools like Phinbox IQ can make a significant difference. Rather than asking technicians to manually investigate every reported email from scratch, automated phishing analysis helps identify genuine threats more quickly while filtering out many of the harmless messages that would otherwise consume valuable engineering time. Instead of spending thirty minutes investigating every report, your team can focus their expertise where it's needed most.

“[Phinbox IQ and the report phishing button] adds to the end-users’ toolbox and gives them an opportunity to report more frequently, which ultimately helps them be more secure.” - Ethan Earl, Resonant Technology Partners

Better Reporting Deserves Better Analysis

The success of your security awareness program shouldn't be measured by how few emails employees report. It should be measured by whether employees know what to do when they're uncertain.

A visible, well-used phishing reporting button gives people confidence to act instead of ignoring something suspicious. It creates opportunities for earlier threat detection, reinforces positive security habits, and helps build a culture where security becomes everyone's responsibility.

Yes, that approach creates more reported emails. That's not a sign that your Cybersecurity Awareness Training is failing. It's often one of the clearest indicators that it's working. The challenge is making sure your investigation process can keep up.

If your technicians are spending hours every day sorting genuine threats from harmless newsletters, the answer isn't asking employees to report less. It's giving your team better tools to analyze reported emails faster.

Phinbox IQ helps MSPs reduce the noise by automating phishing analysis, allowing technicians to identify genuine threats more quickly while dramatically reducing the time spent investigating false positives. The result is a reporting culture you can actively encourage, without creating an investigation backlog that slows your team down.

Check out this case study where an MSP saved 50+ hours per week on reported email triaging with Phinbox IQ.





 

Leave a comment: