21 seconds.
That's the median time between someone opening a phishing email and clicking the link, in the simulation data behind Verizon's 2024 DBIR. Another 28 seconds and they've entered their data.
Under a minute for the user. Hours or days for the investigation. Here's how I actually work a phishing case:
- Read the headers like witness statements. Return-Path vs. From: who the envelope says sent it vs. who the message claims sent it. Then SPF, DKIM, DMARC and composite auth: which checks passed, which failed, and whether the domains actually align.
- Walk the path hop by hop. Received headers, bottom to top. Where it entered, what touched it, and where something doesn't add up.
- Pull the message trace. Who else got it. What the filter decided. What happened at delivery.
- Follow the click. Sign-in logs. New inbox rules. New app consents. Sessions from places that make no sense. This is where "a phishing email" becomes "a compromised account."
- Answer the question nobody wants to ask: why did our controls let it through?
Step 5 is where the real work lives. Anyone can say an email was bad. The job is proving exactly how it got in.