



Phishing has always been the path of least resistance for cyber adversaries. But in 2026, the landscape has shifted dramatically. Generative AI has handed attackers a productivity engine: hyper-personalized spear-phishing emails written in flawless regional-language English, deepfake voice clips that impersonate a CFO on a call, and LLM-generated pretexts that reference real internal projects scraped from LinkedIn and conference slide decks. For Indian enterprise IT and security leaders, the question is no longer if your organisation will face AI-crafted social engineering — it is whether your detection and response infrastructure can keep pace.
This guide breaks down how the modern phishing threat works, why legacy defences are structurally underprepared, and what a layered Indian-enterprise-grade response programme looks like end-to-end.
The economics of phishing attacks used to favour volume over precision. Mass-spray campaigns with generic lures worked because even a fractional click rate across millions of recipients yielded a profit. AI has inverted this. Attackers can now run high-precision, low-volume campaigns at near-zero marginal cost. A well-prompted LLM produces a spear-phishing mail indistinguishable from a message genuinely authored by a colleague — correctly formatted, referencing real projects, arriving at psychologically optimal times.
Three AI-driven techniques are appearing repeatedly in 2026 incident data:
CERT-In advisories through 2025 and early 2026 have documented a consistent uptick in business credential theft attributed to sophisticated phishing operations, with Indian BFSI, logistics, and government-adjacent organisations as primary targets.
Traditional anti-phishing relies on three pillars: reputation-based URL filtering, signature-based attachment scanning, and sender policy enforcement (SPF/DKIM/DMARC). Each of these remains necessary but is no longer sufficient when facing AI-generated attacks:
The implication is clear: detection must shift from the perimeter inward, and response must be faster than the human-only review cycle allows.
PJ Networks deploys FortiMail as the enterprise email security gateway for clients across sectors. FortiMail’s AI/ML-based content analysis goes beyond signature matching — it evaluates structural anomalies in email headers, linguistic patterns, and domain relationship graphs to flag AI-generated pretexts that look legitimate on the surface.
Key FortiMail capabilities relevant to AI-augmented phishing:
At the network layer, FortiGate NGFW with Fortinet’s AI-powered threat intelligence feed enforces egress filtering to block command-and-control callbacks if a phishing payload does execute. SSL deep-inspection surfaces encrypted tunnels that a victim’s infected device might be using to exfiltrate credentials or stage further lateral movement.
Email security and perimeter firewalls handle the inbound attack vector, but the full lifecycle of a sophisticated phishing campaign — from initial click through credential harvest, lateral movement, and data exfiltration — plays out across multiple log sources and network segments. This is where a unified SecOps platform becomes operationally indispensable.
PrahiX Ora is a unified SecOps platform built by PrahiX Tech Pvt Ltd. PJ Networks is its primary field deployment and operations partner, running the platform for clients as part of managed security service engagements. Below is how each of Ora’s four operational pillars addresses the AI-phishing threat chain.
When a phishing mail lands and a user interacts with it, the resulting artefacts are scattered: a mail gateway alert, a DNS lookup for an unusual domain, an authentication event in Active Directory, a FortiGate egress connection. Ora’s SIEM ingests all of these sources simultaneously and applies correlation rules mapped directly to MITRE ATT&CK techniques — in this case, Initial Access (T1566 – Phishing), Credential Access (T1110 – Brute Force / T1555 – Credentials from Password Stores), and Lateral Movement (T1021). The graph-based attack storyline reconstruction joins these individual signals into a single incident narrative, dramatically reducing analyst triage time.
For Indian enterprises, CERT-In has directed organisations to retain logs in-country for a minimum of 180 days. Ora’s tiered retention model — hot storage for active investigation, cold storage for recent history, and archive for the compliance window — lets organisations meet this directive without paying for all data at hot-storage pricing.
After a credential harvest, attackers move laterally through the network. Ora’s Network Management System provides unified observability across FortiGate firewalls, managed switches, wireless access points, and WAN/SD-WAN links. LLDP/CDP topology discovery builds a live map of the network so that when an attacker pivots from a compromised workstation to an internal server, the NMS registers the anomalous traffic path and flags it for analyst review.
For enterprises with multi-vendor estates — a common reality in Indian IT environments assembled over years through multiple vendor relationships — this unified view is particularly valuable. ML-based anomaly detection identifies east-west traffic patterns that deviate from the established baseline, triggering alerts without requiring pre-defined signatures for each new attack technique.
Physical security matters alongside network security, especially for manufacturing plants, retail chains, and multi-site corporate campuses. Ora’s video surveillance (VMS) pillar manages ONVIF-compatible and major-brand IP cameras — including Hikvision and Dahua — with integrated video analytics. Operators running a security operations centre can correlate a physical access event (an employee badge-in at an unusual hour) with network events in the same timeline, giving a richer picture of whether an insider-threat scenario is developing alongside a phishing compromise.
For PJ Networks clients in manufacturing and retail with distributed sites, this consolidated view eliminates the operational blind spots that come from running physical security and IT security through entirely separate platforms.
CERT-In’s incident reporting direction requires organisations to report confirmed cyber incidents within six hours of detection. For a human-only SOC working through email, ticket systems, and manual firewall changes, this timeline is brutally tight. Ora’s SOAR pillar addresses this through playbook automation with pre-built connectors.
A confirmed phishing-related credential compromise, for example, can trigger an automated playbook that: disables the affected Active Directory account, pushes the attacker’s C2 IP and domain to FortiGate’s blocklist, creates a structured incident record with all correlated evidence, and generates a CERT-In-format preliminary report — all within minutes of analyst confirmation. The SOAR handles the repeatable mechanical steps; analysts focus on investigation and decision-making.
If your organisation needs to evidence its incident response capability under the DPDP Act or a regulatory audit, the automated playbook logs provide a timestamped, reproducible chain of custody for every action taken.
A structured playbook organises your response across three phases. Here is a practical checklist your team can adapt:
The Digital Personal Data Protection Act places explicit obligations on data fiduciaries to implement appropriate security safeguards. A successful phishing attack that results in unauthorised access to personal data of Indian residents triggers both notification obligations and potential enforcement action under the DPDP Act. A well-documented, timely response — supported by the kind of automated evidence chain that a SOAR platform provides — is your best defence in any regulatory conversation.
CERT-In’s 2022 directions remain in force and have been progressively reinforced: six-hour incident reporting, 180-day log retention in India, and mandatory vulnerability disclosure. Organisations that have not yet operationalised these requirements should treat the current phishing threat wave as a forcing function to do so — the cost of compliance infrastructure is far lower than the regulatory, reputational, and operational cost of a breach.
PJ Networks operates as a managed security service provider across India, running 24/7 NOC and SOC functions for enterprises that need enterprise-grade security without the overhead of building and staffing it in-house. Our managed security stack combines FortiGate NGFW, FortiMail, and FortiNet’s broader Security Fabric with the PrahiX Ora SecOps platform, giving clients a unified view of their threat landscape across email, network, and endpoint signals.
If your organisation is evaluating its readiness for AI-augmented phishing threats — or if a recent incident has made the question urgent — our team can conduct a rapid security posture assessment. We will benchmark your current email security, SIEM coverage, and incident response capability against the CERT-In and DPDP Act baseline, and identify the gaps that need closing first.
Reach out to PJ Networks to schedule an assessment. The sophistication of the attacks is rising; the tools to match them are available now.