Four Major Upgrades That Take Phishing Triage Off Your Team

CyberNut
September 9, 2026
5 min read

Ask a district technology director where the hours go and the reporting queue comes up fast. Staff report suspicious emails, which is exactly what you trained them to do. Then someone has to work through hundreds of them by hand, most of which turn out to be harmless, while the message that actually matters waits its turn.

Our back-to-school release is built around that problem. The goal was to move the queue off your team and onto the platform, so districts start the school year better protected without anyone taking on more work.

Here's what's live.

Reported threats classified and removed automatically

Automated Threat Terminator scores every reported email and decides whether it's a threat or safe. Our AI handles the classification, so confirmed threats can be automatically remediated from every inbox they reached, shortening the amount of time to remove a threat from hours to seconds. Recommended actions and threat indicators are surfaced for anything that still needs a human look.

Reported spam is labeled the same way, and that classification runs for every CyberNut district. With ATT, labeled spam is remediated automatically too. Because most of a district's queue ends up being spam rather than phishing, that is what actually clears the backlog.

Explore Automated Threat Terminator →

Compromised accounts caught in minutes

The hardest attack to spot is the one coming from inside your own domain. When a reported email from one of your own is classified as phishing, CyberNut flags that account as likely compromised and alerts your admins. That turns a compromised account from something discovered days later into something addressed the same morning. It takes one report, not a pattern. Districts can enable auto-suspend so the account is locked the moment it's flagged, and it is included for every district at no additional cost.

Explore Compromised Account Detection →

One case, one decision

Reported emails used to be grouped by domain, which scattered a single phishing wave into multiple actions that needed to be taken. The redesigned reporting queue groups them by sender and subject into a case, so a whole cluster of look-alike messages can be marked as phishing, spam, or legitimate in a single pass. Each case carries the full picture with it: who reported it, which inboxes it reached, a time-stamped log of every action taken, and a preview of the email and header info. Anything urgent can be escalated to the top of the review queue, so it doesn't slip down the list and a second pair of eyes can take a look.

Explore the Active Threat Manager →

Search your whole district from a single email

Advanced threat search starts from one reported message and looks across your entire school domain for everything else like it. When a staff member forwards something that looks like the leading edge of a campaign, you can find the rest of it in one move rather than waiting for more reports to come in.

Explore Advanced Threat Search →

See it for your district

CyberNut is built exclusively for K-12, and districts on the platform see an average 75% reduction in phishing click rates.

We’re demoing all four live at the Back-to-School Live Demo on Tuesday, September 15 at 2:00 PM ET.

Save your seat →

CyberNut
September 9, 2026