What problem does it solve?
Traditional email security tools and compliance frameworks (NIST 800-53, ISO 27001, SOC 2) are built for pre-2024 threat landscapes and fail to address mid-2026 AI-augmented phishing threats including voice-cloned vishing, deepfake video BEC, hyperpersonalized LLM-generated lures, and unenforced email authentication protocols that leave organizations exposed to billions in annual BEC losses.
Core Features & Use Cases
- Comprehensive Email Authentication Audit: Assess SPF, DKIM, DMARC, BIMI, ARC, MTA-STS, and TLSRPT deployment and enforcement status across all owned sending domains, with a 90-day migration plan to DMARC p=reject.
- Compliance Gap Analysis: Map modern phishing TTPs (T1566.*, T1078) to gaps in global regulatory frameworks including NIST, ISO, NIS2, UK CAF, AU Essential 8, and NYDFS to expose paper compliance versus real protection.
- End-to-End Anti-Phishing Assessment: Run a 10-step procedure covering phishing-resistant MFA rollout, BEC playbook validation, deepfake-aware policy creation, vendor email risk monitoring, and continuous DMARC report monitoring.
- Use Case: A mid-sized multinational enterprise uses this skill to identify that 40% of privileged users rely on phishable TOTP MFA, their primary sending domain is stuck at DMARC p=none, and their BEC playbook lacks out-of-band verification protocols, then generates a prioritized remediation queue aligned to real exploit risk rather than framework deadlines.
Quick Start
Use the email-security-anti-phishing skill to run a full email security and anti-phishing assessment for your organization and generate a prioritized remediation plan.