Know how many suspicious emails your people reported in a period, without opening the inbox one by one.
See how many of those reports are unattended, under review, or already closed — that is, measure your response team and not just your collaborators.
Show in a number that the report button is being used, which is the evidence that management usually asks for to justify the program.
Detect weeks with spikes in reports, which almost always coincide with a real phishing campaign against your company.
See what proportion of what was reported turned out to be a real threat and what proportion was spam or legitimate mail.
Navigation: Insights → Incident Analytics
The menu says "Incident Analytics" and the screen title says "Threat Analytics." It's the same screen.
The first time you enter, a notice appears, "We updated this report," which lets you know that the screen was redesigned and that the data and metrics are the same as before. It closes with Got it and doesn't appear again.
The Filters button opens a date range, with shortcuts for the last few days and for the previous calendar year, in addition to the option to set a range manually.
The period is the only thing that can be filtered here: there are no filters by department, group, or person. If you need to cut by area, the place is the incident inbox.
At the top there are three circles, one per resolution status, each with the count over the total of reported emails for the period and its percentage:
Received — it came in and no one has worked on it yet.
Under Review — someone is analyzing it.
Resolved — it's already closed.
Read together, they are the status of your response queue: a lot accumulated in Received means reports are waiting, not inactive collaborators.
A chart with the classification of the reported emails, and above it the total of analyzed emails. There are four categories:
Threat — it was confirmed to be a malicious email.
Spam — junk mail, annoying but not dangerous.
Clean — it turned out to be legitimate: the collaborator reported it as a precaution and it was fine to report it.
Unknown — it doesn't have a classification yet.
The category is the latest classification recorded in the history of each email. An email comes in unclassified and stays in Unknown until someone works on it from the incident inbox. So a large portion in Unknown doesn't say anything about the threats you received: it says there are reports that haven't been reviewed.
Clean being high is not a problem. It means your people report when in doubt, which is exactly the behavior the program is looking for. What's worth watching is that Threat doesn't grow without anyone attending to it.
The chart on the right distributes the reported emails by week, showing the status of each batch. It's useful for two things: finding the spike —a week well above the rest is usually a real campaign against your company— and seeing whether old reports were closed or remained open.
If the chosen period has no data, the card states this with "No weekly data available" instead of remaining empty.
The inbox is the workplace: there you open each reported email, analyze it, classify it, and close it. This screen is the summary of all that in numbers, for the period you choose. The data is the same, seen in two different ways.
No. Unknown is the emails that haven't been classified yet. It's the signal that there are reports waiting for review in the inbox, not a problem with the analytics.
Not from this screen: here the only filter is the period. To see who reported each email, go to the incident inbox.
Check the period: the indicators are calculated over the date range you have set in Filters, and the inbox may be showing you the entire history.
The email has to come in through the report button to be counted here. If someone manually forwards the suspicious email through another channel, it isn't included in this measurement.
Do you have feedback or want to request improvements? Let us know at roadmap.whalemate.com/roadmap