Skip to content
Reporting

Most report buttons just forward the message. This one answers the person.

A report that disappears into a mailbox teaches people not to bother next time. Cyberdise gives the reporter a real next step, whether that is confirmation, an explanation or an escalation, and gives the security team a signal it can act on.

Outlook and Gmail
Exchange on-prem too
Smart routing
exercises stay inside
Your branding
your name on it
Answers back
the reporter hears
An office worker with a laptop, about to click
Where it works

Works in the mailbox your people already use.

The Report-a-Phish Button sits in the Outlook ribbon and in Gmail.

  • Outlook with Microsoft 365, installed centrally from the admin center
  • Outlook with Exchange on premises, through EWS
  • Gmail and Google Workspace, as a Workspace add-on
  • Shared mailboxes, group addresses and extra accounts in Outlook
  • Any other mail system, by forwarding to one Cyberdise address

What happens to the report

A phishing message open in the mail client, with the report panel and Send Report beside it
What happens after a report

From one click to a closed case

  1. 01ReportOne click in Outlook or Gmail, or a forward to one address.
  2. 02CheckHeaders, domains and IP addresses are checked, and your own exercises are recognized.
  3. 03AnswerThe reporter gets an automatic reply in their own language.
  4. 04RouteExercises stay inside Cyberdise. Real threats go straight to your SOC.
  5. 05RespondYour team reviews the case, and the attack can become the next exercise.
The AI analysis of a reported email in the Incident Inbox: an AI score of 82 and a written explanation of the phishing indicators it found
Incident Inbox

Every report is checked before anyone opens it.

Reports land in the Incident Inbox and are analyzed on arrival. An AI model then reads the message and adds an AI score with a written explanation, so the analyst starts from a reason instead of a raw email.

  • Header analysis and blocklist checks on every domain and IP address
  • A threat score from 0 to 100, marked as real phishing when a check matches
  • Your own exercises recognized and labeled, with no rules to maintain
  • An AI score with the reasoning behind it
  • Operators review, reclassify and close each report
The feedback loop

A report should never vanish into silence.

Someone who reports a suspicious message has done real security work. If nothing comes back, they learn it was pointless, and the next report never arrives. Cyberdise answers automatically, in the person's own language: one reply when the message was an exercise, another when it was real or external. The reply can include the message's risk score, and you write every word of it. That is how a reporting culture starts, because people can see that reporting changed something.

The Report-a-Phish button in the mail client, and the instant feedback that the reported message was a simulation
The rest of the platform

What a report sets in motion.

Behavioral risk scoringScores built from what people do, updated continuously.Behavioral risk scoring
AI Campaign AutomatorDescribe the campaign you need and get a running program.AI Campaign Automator
Phishing and smishingMultichannel exercises built from the tactics attackers are using now.Phishing and smishing
Which mail systems does it work with?
Outlook with Microsoft 365, Outlook with Exchange on premises, and Gmail or Google Workspace. Any other mail system can report by forwarding the message to a Cyberdise address on your own system domain.
Does it need an app registration in Azure?
No. With Microsoft 365 it connects through Entra ID, and with Exchange on premises it needs nothing in Azure at all. Routing and replies work the same either way.
How does it reach our people?
Your admin rolls it out centrally to every mailbox, or people add it themselves. In Gmail it comes as a Google Workspace add-on.
Will our SOC be flooded with reported exercises?
No. Report routing keeps reported Cyberdise exercises inside Cyberdise and sends everything else to your SOC mailbox, or to both. The button recognizes Cyberdise's own exercises, so there are no rules to maintain.
In what form does the SOC receive the message?
In the form your tools read best, including the original message with its headers intact. You also decide what happens to the message in the reporter's mailbox.
Which editions include it?
The Report-a-Phish Button, the Incident Inbox and the AI analysis make up the Verify package. It is included in Behavioral Defense Engineering and available as an add-on to Awareness Plus.

Report a message on the call and watch what happens next.

Forward a suspicious email during the demo and watch the analysis, the reply and the routing.