FAQ

Clear Answers About ORQET

Learn how ORQET works, where it fits within the email security lifecycle, how the deployment models differ, and what happens after a suspicious email reaches the inbox.

Understanding ORQET

The Category, the Platform, and the Problem It Solves

Learn what ORQET is, where it operates, and how it strengthens the email security technologies your organization already uses.

ORQET is a Post-Delivery Email Threat Response platform. It operates after a suspicious email reaches the inbox. ORQET analyzes reported emails, delivers human-derived verdicts, automates remediation, and turns confirmed attacks into tactical and technical threat intelligence.

Post-Delivery Email Threat Response is the practice of delivering human-derived verdicts on reported emails, automating remediation of confirmed threats, generating threat intelligence, and continuously improving response after suspicious emails reach the inbox. It addresses the gap between a user asking whether an email is safe and a confirmed outcome: a clear verdict, remediation when a threat is confirmed, and intelligence applied to future investigations.

ORQET operates after an email has reached the inbox.

It begins when an employee reports a suspicious message. ORQET then analyzes the email, delivers a human-derived verdict, remediates confirmed threats, and captures tactical and technical threat intelligence that can inform future investigations.

ORQET is designed to work alongside existing email security investments.

Core and Advanced work alongside secure email gateways (SEG), integrated cloud email security (ICES), and related controls. Inline may replace an overlapping inline detection capability depending on the organization’s architecture and requirements.

How ORQET Works

What Happens After an Employee Reports an Email

ORQET connects suspicious email reporting, expert analysis, human-derived verdicts, automated remediation, and threat intelligence through a defined workflow.

When an employee reports a suspicious email, ORQET receives the submission for analysis.
 
When a reported email matches one that has already been reviewed, Cyrebrium applies the established human-derived verdict. When an email has not been seen before, it is routed to a security analyst for review. Every verdict traces back to human judgment.

AI-initiated detection will arrive with ORQET Inline. Inline will be able to initiate analysis without requiring an employee report. Confirmed malicious emails will trigger automated Search and Purge.

ORQET evaluates message characteristics, threat indicators, supporting evidence, context, and prior intelligence through a repeatable analytical process. New emails are reviewed by an ORQET analyst, while emails matching one already reviewed can receive the established human-derived verdict through Cyrebrium. Every verdict traces back to human judgment.

Once a verdict is reached, the employee who reported the email receives a response letting them know whether the email is safe or malicious, along with guidance based on the organization’s requirements. If the email is confirmed malicious, it can then move to automated remediation.

ORQET combines expert human analysis with Cyrebrium, its AI-assisted matching and automation engine. Analysts provide the judgment and context behind every verdict. Cyrebrium recognizes previously analyzed emails, applies established human-derived verdicts, and supports pattern recognition and enrichment, helping the process remain consistent as reporting volume grows.

Deployment Models

Choose the ORQET Deployment Model That Fits Your Organization

Each deployment model runs through the same Post-Delivery Email Threat Response process while supporting different intake, remediation, intelligence, and automation requirements.

ORQET offers three deployment models: Core, Advanced, and Inline. Core and Advanced are available today. Inline is in development.

The analysis and response workflow is identical across all three. What differs is how an investigation begins, who executes remediation, and which intelligence and automation capabilities are included.

Core provides analysis of user-reported emails, human-derived verdicts, purge requests, and indicator of compromise reporting.

When a malicious email is confirmed, the customer performs the remediation based on the purge request provided by ORQET.

Advanced includes the capabilities of Core and adds automated Search and Purge following a malicious verdict from a user-reported workflow.

It also provides customer-controlled Search and Purge via the dashboard and access to the ORQET Threat Intelligence Platform.

Inline is in development. It will include the capabilities of Core and Advanced and add AI-initiated detection.

It will automatically Search and Purge malicious emails identified through Inline, as well as those confirmed through user-reported workflows.

No. Core, Advanced, and Inline are deployment models, not required stages of progression.

Organizations can select the model that best fits their email environment, operational requirements, response objectives, and existing security investments.

Response, Remediation, and Intelligence

From Human-Derived Verdict to Remediation

For user-reported emails confirmed malicious, ORQET captures indicators and investigative context that can be used as tactical and technical threat intelligence. Remediation capabilities vary based on the selected deployment model.

ORQET communicates the malicious verdict, captures relevant indicators, and supports the appropriate remediation path.

With Core, the customer performs the remediation. With Advanced and Inline, malicious verdicts will trigger automated Search and Purge.

Search and Purge searches affected mailboxes to locate and remove matching malicious emails, including copies that were not originally reported by users.
 
With Advanced, security teams can also use Search and Purge directly to search for and remove malicious emails that may not have been submitted through ORQET.

The ORQET Threat Intelligence Platform is the intelligence publication and enrichment layer available with Advanced. It will also be included with Inline.

It provides access to IOCs and investigative context generated from confirmed malicious emails and investigation intelligence generated through human-derived, user-reported workflows, including relevant domains, URLs, IP addresses, sender information, and other observable evidence.

This intelligence can support broader security operations, future investigations, enrichment, reporting, and downstream integrations through ORQET’s API and STIX/TAXII feed.

ORQET produces tactical and technical threat intelligence from confirmed malicious emails. Technical intelligence includes IOCs such as domains, URLs, IP addresses, and file hashes. Tactical intelligence can include context around attacker methods and techniques identified during the investigation. ORQET may identify campaign attribution or threat actor activity when sufficient evidence is available, but attribution is not always possible.

IOCs and investigative context can be enriched and published through the ORQET Threat Intelligence Platform and shared through ORQET’s API and STIX/TAXII feed with security platforms capable of consuming them.

Integrations and Security Ecosystem

Built to Work Alongside Your Security Ecosystem

ORQET fits beside the defenses a security team runs today and extends visibility into what happens after email delivery.

ORQET works alongside the prevention and detection technologies already protecting the email environment by addressing suspicious emails that require analysis after they reach the inbox.
 
Core and Advanced support the user-reported email workflow by providing human-derived verdicts and visibility without requiring organizations to replace their existing email security technologies.
 
Inline extends ORQET beyond the user-reported workflow by adding AI-initiated detection without requiring an employee to report the email. Depending on the organization’s architecture and requirements, Inline can work alongside existing detection technologies or replace an overlapping inline detection capability.
 
ORQET threat intelligence, including IOCs, can also be shared through its API and STIX/TAXII feed with security platforms capable of consuming it.

Yes. Inline detection can reduce the number of malicious emails that reach users, but suspicious emails still reach the inbox. When an employee reports one, the organization still needs a way to determine whether it is safe or malicious and communicate that verdict back to the user.

ORQET provides a defined workflow for user-reported emails, delivering human-derived verdicts and giving employees a clear answer. With Advanced, confirmed malicious emails can also be automatically remediated through Search and Purge, while user-reported threats can generate tactical and technical threat intelligence, including IOCs and investigative context.

ORQET threat intelligence feeds can also be integrated with existing threat intelligence platforms to support broader threat hunting.

Yes. ORQET works with Microsoft 365, including Microsoft Defender for Office 365, and with Google Workspace. Core supports both platforms today. Advanced supports Microsoft 365 today, and Google Workspace support is in development. Inline will match Advanced.

The deployment approach depends on the selected ORQET model, the organization’s email environment, existing security controls, and requirements.

ORQET threat intelligence can be shared through its API and STIX/TAXII feed with security platforms capable of consuming it. This allows organizations to feed ORQET IOCs and threat intelligence into existing platforms to support broader threat hunting across the security environment.

No. ORQET does not inspect outbound email traffic and is not an outbound monitoring or data loss prevention platform.

ORQET focuses on analyzing reported suspicious emails, delivering clear verdicts, and remediating confirmed malicious emails after delivery.

Evaluation and Next Steps

Determine the Right ORQET Approach for Your Organization

Learn who ORQET supports, how to compare the models, and how to begin a conversation with the ORQET team.

ORQET is designed for organizations across all industries, from small and midsize businesses (SMBs) to large enterprises. It is a strong fit for organizations where employees report suspicious emails and security teams need a consistent way to analyze those submissions, provide users with clear safe-or-malicious verdicts, and respond when threats are confirmed.
 
Organizations managing higher reporting volumes, repetitive analysis, manual remediation, or limited visibility into reported emails can also benefit from ORQET’s different deployment models and capabilities.

The biggest consideration is the organization’s existing security stack and the investments already in place. ORQET is designed to complement those investments, so the right deployment model depends first on the capabilities the organization already has and where gaps remain.
 
From there, organizations can consider how suspicious emails enter the process, whether remediation is handled manually or should be automated, what threat intelligence capabilities are needed, and whether AI-initiated detection is already in place.

Schedule an ORQET walkthrough to see how reported emails move through analysis, verdict communication, remediation, intelligence, and reporting.

The demonstration can be tailored to your existing environment, operational priorities, and evaluation objectives.

ORQET pricing is based on the selected deployment model and the organization’s requirements.

Request a demo by completing the contact form to discuss your environment, requirements, and the appropriate ORQET deployment model.

Still Have Questions?

Find the Right Answer

Contact the ORQET team to discuss your existing email security environment, current security investments, and the ORQET deployment model that best fits your needs.