{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/phishing-control-plane-defenses/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/phishing-control-plane-defenses/",
        "slug": "phishing-control-plane-defenses",
        "url": "https://update.dsesecurity.com/updates/phishing-control-plane-defenses/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/phishing-control-plane-defenses.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/phishing-control-plane-defenses/"
        },
        "title": "Stop phishing at the control plane, not only at the inbox",
        "summary": "Administrator-side phishing defense combines phishing-resistant authentication, secure defaults, message and web controls, endpoint protection, rapid reporting, evidence, and tested response.",
        "format": {
            "slug": "checklist",
            "name": "Checklist"
        },
        "priority": {
            "slug": "advisory",
            "name": "Advisory"
        },
        "featured": false,
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "microsoft-365-identity",
                "name": "Microsoft 365 & Identity",
                "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-07-19T21:27:10+00:00",
        "modified_at": "2026-07-19T21:27:10+00:00",
        "reviewed_on": "2026-07-19",
        "reading_minutes": 2,
        "word_count": 437,
        "potentially_affected": "Organizations protecting identities and devices from credential phishing and malware delivery through email, SMS, voice, collaboration platforms, websites, and other communication channels.",
        "dse_recommendation": "Map attack paths, prioritize phishing-resistant authentication, harden current platform controls, create one-action reporting, test detections safely, and investigate suspected success.",
        "primary_source": {
            "name": "CISA and partners: Phishing Guidance — Stopping the Attack Cycle at Phase One",
            "url": "https://www.cisa.gov/resources-tools/resources/phishing-guidance-stopping-attack-cycle-phase-one",
            "published_on": "2023-10-18",
            "authority": "Cybersecurity and Infrastructure Security Agency"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<article>\n  <p class=\"lede\">User awareness matters, but a security program should not make one person the final control between a convincing message and a compromised identity or device. Administrators can reduce opportunity, make reporting easier, and limit the value of a successful deception.</p>\n\n  <h2>What the joint guidance covers</h2>\n  <p><strong>Source fact:</strong> CISA, NSA, FBI, and MS-ISAC address phishing used to obtain login credentials and phishing used to deploy malware. Their publication provides recommendations for network defenders and software manufacturers, recognizing that user training, technical protections, and secure product design have related responsibilities.</p>\n  <p><strong>Source fact:</strong> The guidance explains that weaker multifactor methods can still be phished or abused. It identifies FIDO- and public-key-infrastructure-based authentication as phishing-resistant approaches. It also describes risk from push approval without number matching, repeated approval prompts, and SMS or voice methods.</p>\n  <p><strong>Source fact:</strong> The agencies recommend a standard user-awareness program and prompt incident reporting. Reporting supports faster investigation and can help defenders identify related messages, destinations, credentials, or devices.</p>\n\n  <h2>Design layered controls around real attack paths</h2>\n  <p><strong>DSE recommendation:</strong> map credential and malware delivery through email, SMS, voice, collaboration, social media, third-party applications, QR codes, attachments, links, and browser prompts. Record which identity, mail, web, endpoint, device, application, and recovery controls can interrupt each path.</p>\n  <ol>\n    <li>Prioritize phishing-resistant authentication for administrators and high-impact resources, then expand by user, device, and application readiness.</li>\n    <li>Use current platform guidance to configure message authentication, anti-phishing, impersonation, attachment, link, web, application, macro, and endpoint protections appropriate to the environment.</li>\n    <li>Provide a one-action reporting method in the tools people use and route submissions to a monitored response workflow.</li>\n    <li>Preserve original message, headers, sender, recipient, timestamps, URLs, attachments, identity events, device telemetry, and user observations where available.</li>\n    <li>Test reporting, filtering, detections, triage, containment, and communications with authorized safe scenarios.</li>\n  </ol>\n\n  <h2>Respond to suspected success, not just the message</h2>\n  <p><strong>DSE recommendation:</strong> when interaction may have occurred, validate the user through an independent channel and investigate the identity, sessions, device, mailbox or application rules, privileges, related recipients, and accessed resources. Contain affected identities and devices proportionately, revoke unauthorized sessions, preserve evidence, remove persistence, and correct the failed controls. Deleting the original message alone cannot establish containment.</p>\n\n  <h2>Applicability and limits</h2>\n  <p>Phishing techniques and product controls change. No filter, training program, authentication method, or vendor claim blocks every attack. Implementation steps must come from current supported platform documentation and be tested for business impact. FIDO and PKI deployments also require registration, device, recovery, emergency-access, and lifecycle planning. This article provides an administrative control model, not a guarantee or a claim that DSE monitors every reader&#8217;s environment.</p>\n\n  <h2>Official reference</h2>\n  <p><a href=\"https://www.cisa.gov/resources-tools/resources/phishing-guidance-stopping-attack-cycle-phase-one\" target=\"_blank\" rel=\"noopener noreferrer\">Phishing Guidance: Stopping the Attack Cycle at Phase One</a> — joint defender and manufacturer recommendations.</p>\n</article>",
        "content_text": "User awareness matters, but a security program should not make one person the final control between a convincing message and a compromised identity or device. Administrators can reduce opportunity, make reporting easier, and limit the value of a successful deception.\n\n What the joint guidance covers\n Source fact: CISA, NSA, FBI, and MS-ISAC address phishing used to obtain login credentials and phishing used to deploy malware. Their publication provides recommendations for network defenders and software manufacturers, recognizing that user training, technical protections, and secure product design have related responsibilities.\n Source fact: The guidance explains that weaker multifactor methods can still be phished or abused. It identifies FIDO- and public-key-infrastructure-based authentication as phishing-resistant approaches. It also describes risk from push approval without number matching, repeated approval prompts, and SMS or voice methods.\n Source fact: The agencies recommend a standard user-awareness program and prompt incident reporting. Reporting supports faster investigation and can help defenders identify related messages, destinations, credentials, or devices.\n\n Design layered controls around real attack paths\n DSE recommendation: map credential and malware delivery through email, SMS, voice, collaboration, social media, third-party applications, QR codes, attachments, links, and browser prompts. Record which identity, mail, web, endpoint, device, application, and recovery controls can interrupt each path.\n \n Prioritize phishing-resistant authentication for administrators and high-impact resources, then expand by user, device, and application readiness.\n Use current platform guidance to configure message authentication, anti-phishing, impersonation, attachment, link, web, application, macro, and endpoint protections appropriate to the environment.\n Provide a one-action reporting method in the tools people use and route submissions to a monitored response workflow.\n Preserve original message, headers, sender, recipient, timestamps, URLs, attachments, identity events, device telemetry, and user observations where available.\n Test reporting, filtering, detections, triage, containment, and communications with authorized safe scenarios.\n \n\n Respond to suspected success, not just the message\n DSE recommendation: when interaction may have occurred, validate the user through an independent channel and investigate the identity, sessions, device, mailbox or application rules, privileges, related recipients, and accessed resources. Contain affected identities and devices proportionately, revoke unauthorized sessions, preserve evidence, remove persistence, and correct the failed controls. Deleting the original message alone cannot establish containment.\n\n Applicability and limits\n Phishing techniques and product controls change. No filter, training program, authentication method, or vendor claim blocks every attack. Implementation steps must come from current supported platform documentation and be tested for business impact. FIDO and PKI deployments also require registration, device, recovery, emergency-access, and lifecycle planning. This article provides an administrative control model, not a guarantee or a claim that DSE monitors every reader’s environment.\n\n Official reference\n Phishing Guidance: Stopping the Attack Cycle at Phase One — joint defender and manufacturer recommendations.",
        "content_markdown": "User awareness matters, but a security program should not make one person the final control between a convincing message and a compromised identity or device. Administrators can reduce opportunity, make reporting easier, and limit the value of a successful deception.\n\n## What the joint guidance covers\n\nSource fact: CISA, NSA, FBI, and MS-ISAC address phishing used to obtain login credentials and phishing used to deploy malware. Their publication provides recommendations for network defenders and software manufacturers, recognizing that user training, technical protections, and secure product design have related responsibilities.\n\nSource fact: The guidance explains that weaker multifactor methods can still be phished or abused. It identifies FIDO- and public-key-infrastructure-based authentication as phishing-resistant approaches. It also describes risk from push approval without number matching, repeated approval prompts, and SMS or voice methods.\n\nSource fact: The agencies recommend a standard user-awareness program and prompt incident reporting. Reporting supports faster investigation and can help defenders identify related messages, destinations, credentials, or devices.\n\n## Design layered controls around real attack paths\n\nDSE recommendation: map credential and malware delivery through email, SMS, voice, collaboration, social media, third-party applications, QR codes, attachments, links, and browser prompts. Record which identity, mail, web, endpoint, device, application, and recovery controls can interrupt each path.\n\n- Prioritize phishing-resistant authentication for administrators and high-impact resources, then expand by user, device, and application readiness.\n\n- Use current platform guidance to configure message authentication, anti-phishing, impersonation, attachment, link, web, application, macro, and endpoint protections appropriate to the environment.\n\n- Provide a one-action reporting method in the tools people use and route submissions to a monitored response workflow.\n\n- Preserve original message, headers, sender, recipient, timestamps, URLs, attachments, identity events, device telemetry, and user observations where available.\n\n- Test reporting, filtering, detections, triage, containment, and communications with authorized safe scenarios.\n\n## Respond to suspected success, not just the message\n\nDSE recommendation: when interaction may have occurred, validate the user through an independent channel and investigate the identity, sessions, device, mailbox or application rules, privileges, related recipients, and accessed resources. Contain affected identities and devices proportionately, revoke unauthorized sessions, preserve evidence, remove persistence, and correct the failed controls. Deleting the original message alone cannot establish containment.\n\n## Applicability and limits\n\nPhishing techniques and product controls change. No filter, training program, authentication method, or vendor claim blocks every attack. Implementation steps must come from current supported platform documentation and be tested for business impact. FIDO and PKI deployments also require registration, device, recovery, emergency-access, and lifecycle planning. This article provides an administrative control model, not a guarantee or a claim that DSE monitors every reader’s environment.\n\n## Official reference\n\n[Phishing Guidance: Stopping the Attack Cycle at Phase One](https://www.cisa.gov/resources-tools/resources/phishing-guidance-stopping-attack-cycle-phase-one) — joint defender and manufacturer recommendations."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo.png"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/phishing-control-plane-defenses/",
                "url": "https://update.dsesecurity.com/updates/phishing-control-plane-defenses/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-07-19"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/phishing-control-plane-defenses/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Stop phishing at the control plane, not only at the inbox",
                        "item": "https://update.dsesecurity.com/updates/phishing-control-plane-defenses/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/phishing-control-plane-defenses/#article",
                "identifier": "https://update.dsesecurity.com/updates/phishing-control-plane-defenses/",
                "url": "https://update.dsesecurity.com/updates/phishing-control-plane-defenses/",
                "headline": "Stop phishing at the control plane, not only at the inbox",
                "description": "Administrator-side phishing defense combines phishing-resistant authentication, secure defaults, message and web controls, endpoint protection, rapid…",
                "abstract": "Administrator-side phishing defense combines phishing-resistant authentication, secure defaults, message and web controls, endpoint protection, rapid reporting, evidence, and tested response.",
                "articleBody": "User awareness matters, but a security program should not make one person the final control between a convincing message and a compromised identity or device. Administrators can reduce opportunity, make reporting easier, and limit the value of a successful deception.\n\n What the joint guidance covers\n Source fact: CISA, NSA, FBI, and MS-ISAC address phishing used to obtain login credentials and phishing used to deploy malware. Their publication provides recommendations for network defenders and software manufacturers, recognizing that user training, technical protections, and secure product design have related responsibilities.\n Source fact: The guidance explains that weaker multifactor methods can still be phished or abused. It identifies FIDO- and public-key-infrastructure-based authentication as phishing-resistant approaches. It also describes risk from push approval without number matching, repeated approval prompts, and SMS or voice methods.\n Source fact: The agencies recommend a standard user-awareness program and prompt incident reporting. Reporting supports faster investigation and can help defenders identify related messages, destinations, credentials, or devices.\n\n Design layered controls around real attack paths\n DSE recommendation: map credential and malware delivery through email, SMS, voice, collaboration, social media, third-party applications, QR codes, attachments, links, and browser prompts. Record which identity, mail, web, endpoint, device, application, and recovery controls can interrupt each path.\n \n Prioritize phishing-resistant authentication for administrators and high-impact resources, then expand by user, device, and application readiness.\n Use current platform guidance to configure message authentication, anti-phishing, impersonation, attachment, link, web, application, macro, and endpoint protections appropriate to the environment.\n Provide a one-action reporting method in the tools people use and route submissions to a monitored response workflow.\n Preserve original message, headers, sender, recipient, timestamps, URLs, attachments, identity events, device telemetry, and user observations where available.\n Test reporting, filtering, detections, triage, containment, and communications with authorized safe scenarios.\n \n\n Respond to suspected success, not just the message\n DSE recommendation: when interaction may have occurred, validate the user through an independent channel and investigate the identity, sessions, device, mailbox or application rules, privileges, related recipients, and accessed resources. Contain affected identities and devices proportionately, revoke unauthorized sessions, preserve evidence, remove persistence, and correct the failed controls. Deleting the original message alone cannot establish containment.\n\n Applicability and limits\n Phishing techniques and product controls change. No filter, training program, authentication method, or vendor claim blocks every attack. Implementation steps must come from current supported platform documentation and be tested for business impact. FIDO and PKI deployments also require registration, device, recovery, emergency-access, and lifecycle planning. This article provides an administrative control model, not a guarantee or a claim that DSE monitors every reader’s environment.\n\n Official reference\n Phishing Guidance: Stopping the Attack Cycle at Phase One — joint defender and manufacturer recommendations.",
                "datePublished": "2026-07-19T21:27:10+00:00",
                "dateModified": "2026-07-19T21:27:10+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/phishing-control-plane-defenses/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@id": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": "https://update.dsesecurity.com/assets/dse-updates-share.png",
                "articleSection": [
                    "Cybersecurity",
                    "IT",
                    "Microsoft 365 & Identity"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Microsoft 365 & Identity",
                    "Checklist",
                    "Advisory priority"
                ],
                "genre": "Checklist",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Microsoft 365 & Identity",
                        "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
                    }
                ],
                "wordCount": 437,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "CISA and partners: Phishing Guidance — Stopping the Attack Cycle at Phase One",
                    "url": "https://www.cisa.gov/resources-tools/resources/phishing-guidance-stopping-attack-cycle-phase-one",
                    "datePublished": "2023-10-18"
                }
            }
        ]
    }
}