Box AI cuts security triage from 30 minutes to seconds

|
Share

Screenshots taken by employees as they depart companies tend to be pretty harmless: holiday photos, recipes, cats in costumes. That said, a user could just as easily capture personally identifiable information, or an entire product roadmap. 

Box’s Security Incident Response Team (SIRT) prioritizes reviewing offboarding screenshots for this exact reason. But manual sorting, coupled with a bottlenecked IT ticketing system, was creating massive operational headaches. With Box AI, the team found a way forward.

Key takeaways:

  • Box AI cut security investigations from 30 minutes to seconds, freeing analysts to focus on real threats instead of repetitive triage
  • SIRT now automates 20% of alert reviews, tackling 50-60% of total ticket volume 
  • Box AI reviews headers, screenshots, and email text from phishing emails for spoofing and suspicious links, then delivers analysts the results 
  • The team uses the time they’ve gained back to power a more proactive approach that stops incidents before they start

An avalanche of alerts

One hundred percent: That’s the rate of human review the team needed to cover everything from false positive phishing tickets to offboarding user alerts mistaken for stolen IP. On a team fielding hundreds of alerts a day, that time adds up. 

Phishing alone made up roughly 40% of their tickets. It was, by the team’s own account, their number one ticket type by volume.

Phishing alone made up roughly 40% of the teams tickets... Today, that manual review number has dropped by close to a third.

Today, that manual review number has dropped by close to a third. A meaningful slice of tickets now get triaged, investigated, and, where warranted, closed without ever taking up an analyst’s morning. Andrew Kim, Security Incident Response Analyst at Box, estimates roughly 30 minutes are saved per ticket on the investigative notes analysts used to have to write by hand.

“Our analysis references sensitive data types and can close a case or flag something that needs to be escalated,” Kim said.

How minutes became seconds

SIRT’s investigative process for a reported phishing email breaks into three parallel tasks: analyzing email headers, body HTML text, and any attached screenshots. 

Before automation, a single investigative report took about 30 minutes. Now, the team uses Box AI to run the analysis pieces concurrently rather than one after another. This cuts the header time to 13-25 seconds, the email-body time to 9-20 seconds, and the screenshot time to 8-20 seconds. And the entire process happens at once instead of in sequence.

Every minute clawed back from repetitive triage is a minute redirected toward judgment calls only a trained human can make.

Cloud environment monitoring tells a similar story. Investigating an alert used to mean an analyst logging into a monitoring console and hunting through the interface for context. It took five to 10 minutes just to gather relevant data and then up to an hour for analysis in total for an “easy” case.

Now, the analyst pulls the same data via an API directly into Box, cutting collection time to seconds, and Box AI prompts perform the required analysis in roughly 90 seconds. 

Box AI behind the scenes

The phishing analysis workflow relies on a security orchestration and automated response (SOAR) platform to pull emails, headers, and screenshots into a case management system, alongside an email security vendor’s own automated scoring layer that flags messages as low, medium, or high risk. If that first layer clears an email as low risk, it’s left alone; anything else routes to a security analyst — but before it does, Box AI has already done meaningful work.

Take email headers, traditionally a wall of unreadable metadata to anyone without deep security training. “To an unskilled analyst, or maybe somebody who’s brand new in email analysis, this looks like a bunch of junk,” Kim explained. 

Box AI is prompted to act as a security analyst and review the header for signs of spoofing, then hand back a plain-language verdict: suspicious or benign. Kim is careful to note it’s meant “to help you make a determination rather than serve as a stamp of approval.”

Box AI can automatically close clear-cut, low-risk cases but escalates anything referencing sensitive data categories for a human analyst to examine personally.

The same logic extends to screenshots and email body text. Box AI scans for brand abuse, suspicious links, and manipulative language and packages the findings for a human to review only when something doesn’t check out. Vendor-flagged phishing cases, for instance, are never auto-closed, even when confidence is high. 

The offboarding screenshot workflow works the same way: Box AI can automatically close clear-cut, low-risk cases (like a photo of someone’s pet) but escalates anything referencing sensitive data categories for a human analyst to examine personally.

Time reinvested into automation

The payoff is what analysts do with the time they get back. 

“We’re feeding it back into more automation,” Kim said, describing a compounding effect where saved hours go into building the next automation.

Since kicking off this push around February 2026, the team has moved its highest-volume alert types onto automated workflows — a little over 10% of total alert types, but enough to cover 50-60% of total ticket volume. 

With bandwidth returning, the team can explore another capability worth watching: a forensics file analysis tool built earlier this year that can automatically pull suspicious files from a compromised device, upload them to Box, and let Box AI analyze the forensic artifacts. It reports critical information such as what was installed, any changes to system configurations, or what actions a user performed. The solution stands to save hours of manual legwork.

Kyle Cheek, Team Manager, Security Incident Response, is moving toward more “hypothesis-driven threat hunts,” aligning with frameworks like the Mitre Attack Framework that map how an attacker moves through an environment. The goal is to intervene before an incident ever ignites, a philosophy the team calls “left of bang,” preventing shots from being fired rather than just responding to incidents. 

All told, the impact of SIRT initiatives is clear: Box AI helps automatically close 56% of phishing cases for the team, and they now only manually review about 30% of offboarding user screenshots.

For SIRT, the time saved on every phishing report marks a critical leap, from chasing alerts all day to identifying threats that matter.

Learn more about Box AI today.