At a food company with more than 5,000 email users, the employees were doing what security teams keep asking employees to do. They were reporting suspicious messages. The trouble came afterward. According to a case study published by Cofense, the internal response team could not keep up. Reports accumulated. Feedback became inconsistent. The alarm worked; the people answering it were overwhelmed.
- The job: find and remove phishing that reaches employee inboxes.
- The method: connect reporting, expert review, AI and quarantine.
- The buyer: enterprise security teams, with managed services for stretched operations.
- The lesson: a reporting habit needs a response habit.
That small administrative problem is a good entrance to Cofense. Cybersecurity often presents itself as a contest between attackers and increasingly clever software. Here was something more familiar: a queue, too few people, and a good idea producing more work. The company’s proposition becomes easier to understand once the queue enters the picture.
01The employee as eyewitness
Cofense began in 2011 as PhishMe, co-founded by Rohyt Belani and Aaron Higbee. Its starting idea challenged the habit of treating people chiefly as security liabilities. Employees could practice recognizing phishing through simulations, then report suspicious real messages. Someone who might otherwise click could become an observer with useful evidence.
The name PhishMe was admirably direct: send me the imitation so I can learn to recognize the original. By February 2018, the company’s ambitions had outgrown the name. It became Cofense as a private-equity consortium acquired the business at a $400 million valuation. Detection and response had joined training in the product portfolio.
The financing helped fund that expansion. In July 2016, PhishMe announced a $42.5 million Series C led by Paladin Capital Group, with Bessemer Venture Partners joining the round. The later $400 million figure described the acquisition valuation. It belongs in the ownership story, rather than a running total of venture money raised.
02A button needs somewhere to go
The original workflow is easier to follow than the product names. PhishMe supplies simulations. Reporter gives an employee a way to flag an email. Triage helps analysts group and examine the reports. Vision searches for related threats and quarantines them. Intelligence adds expert-vetted information about phishing seen elsewhere. Each product handles a handoff that would otherwise consume someone’s time.
Consider a suspicious invoice. One person sees something odd and reports it. An analyst establishes whether the message is malicious. The next question is whether copies reached other inboxes. Removing only the reported copy would leave colleagues exposed. Searching and quarantine make the observation useful beyond the person who made it.
- 01 / REPORTAn employee flags a message
- 02 / INVESTIGATEReports are grouped and assessed
- 03 / REMOVERelated threats are quarantined
- 04 / REHEARSEVerified attacks inform training
Cofense Intelligence extends that process beyond an individual organization. It supplies phishing-specific context through ThreatHQ and machine-readable feeds that connect to existing security systems. The point is practical: an analyst should have something better to work with than a lonely URL and a hunch.
The company says its network includes more than 35 million trained users. That is a measure of the reporting and intelligence network, not a customer count. A large pool matters because real inboxes reveal attacks that filtering has already missed. The useful material arrives carrying evidence of the problem it is meant to solve.
03What failed was the follow-through
In the food-company case, Cofense’s managed operation addressed the response burden alongside training based on current threats. The revealing detail is the relationship between employee reporting and feedback. Asking somebody to raise an alarm, then leaving them without an answer, is an awkward way to encourage the next alarm. A reporting program needs an operated process behind it.
A separate 2025 manufacturing case study describes a particularly copyable practice: take the most-reported phishing attempt of the month and use it in a simulation. The lesson comes from an actual message that reached the organization. Training becomes a rehearsal for the local conditions, rather than a tour of every imaginable scam.
Average analysis and response time in January 2025, reported by the manufacturing customer in Cofense’s case study. One customer’s result, rather than a universal service promise.
Cofense’s customer pages include Mayo Clinic and the UK Nuclear Decommissioning Authority. Its latest announcement also names Mastercard, Accenture and Toyota. These are environments where email is ordinary infrastructure and investigating it is specialized work. The buyer is usually a security or awareness team purchasing a program that must function across many employees.
“We stopped a phishing attack in 10 minutes. It used to take days.”
Security Awareness Manager, national financial services company
Customer testimony published by Cofense
04The emails learned to change costumes
There is a complication with searching for the other copies: they may not be copies. An attacker can vary senders, subject lines, links and wording across a campaign. A response tied only to the exact indicator in one message can leave related variants behind.
In May 2026, Cofense described Vision AI in Vision 3.2. It groups messages by structural similarities, allowing analysts to investigate related emails despite surface differences. Once a threat signal is confirmed, quarantine can extend across the cluster, including older messages. The feature is opt-in, and cascading quarantine can require operator approval.
Those controls deserve attention. An incorrectly removed business email is a problem too. The purchasing question is therefore how the tool arrives at a decision, who can approve it, and how the action is recorded. A convincing demonstration should show the investigation and the controls as carefully as the removal.

The diagram expresses the company’s platform design. Its September 23 announcement adds an important timing detail: the new Competency Dashboard is available, while Triage and Vision data are scheduled to connect to Command Center in Q4 2026. Readiness measurement is already a product; the announced data connection is the next step.
05The price of answering the alarm
Cofense sells software subscriptions and licenses, managed services and professional assistance. A UK public procurement listing says pricing depends on license numbers, service type and level. That makes the scope of a quote consequential: simulations alone, an investigation workflow, and a fully operated program are different purchases.
A concrete reference point appears in Copper River’s 2024 Q4 commercial price list: $64,000 for a one-year PhishMe Enterprise renewal in the 15,001-20,000-user bracket. That is a dated reseller line item for a particular product and tier. A current deployment needs its own quote.
Managed Phishing Remediation puts Cofense analysts on the reported-email queue. Managed Phishing Training handles scenario design, delivery and reporting. These services give a lean security team a way to buy operating capacity along with tools. Somebody still has to investigate the suspicious invoice; a contract can determine whose somebody it is.
The 2021 purchase of Cyberfish added cloud-native protection using computer vision and machine learning. Cofense said it would combine those capabilities with its detection and response technology. CRN described the move as an expansion toward smaller businesses and managed service providers. It widened the route to market as well as the technology portfolio.
Buyers also encounter KnowBe4 and Proofpoint, both of which offer phishing simulations and awareness training. Cofense’s distinctive emphasis is the connection from inbox evidence to investigation, removal and subsequent practice. Evaluating that connection is more useful than assuming any vendor has exclusive possession of either AI or human judgment.
06Practice that proves something
Cofense’s September 2026 dashboard announcement asks whether employees demonstrate readiness, rather than merely finish training. Recognizing credential theft and recognizing invoice fraud need not be the same competence. The useful question is where additional practice is needed, and whether that practice changes what employees do when another message arrives.
The general lesson is an inference from these workflows and customer accounts: make reporting easy, assign responsibility for answering it, and let verified local attacks shape the next exercise. Measure the delay between a report and a response. Review the decisions that automation makes. These habits are portable even when the software budget is not.
The approach depends on access to the email environment, workable integrations and people authorized to act. If reports accumulate without review, the queue remains. If an account has already been compromised, removing a message does not finish the investigation. Cofense fits into a broader security operation with responsibilities beyond the inbox.
Its most persuasive idea remains pleasantly unglamorous. An employee notices something. Somebody takes the observation seriously. Other inboxes become safer, and the next lesson gets better. An entire software business can turn on whether that second step happens.