How I triaged a vendor invoice email alert without blocking finance
I recently handled an email security alert that looked serious enough to wake up our security channel. The message had a vendor-looking domain, an invoice-related subject line, and a link that our email gateway scored as unusual. The catch was that the recipient was expecting a document from that vendor, so blocking it without checking would have interrupted a real finance workflow. I pulled the …