unphish
unphish unphish

What Threat Operations Look Like at unphish

Meet Brendan Emmot

At unphish, the threat operations team is responsible for what happens after a threat is detected. From phishing sites to brand impersonation, this is the part of the business focused on actually taking action, enforcing removals, and making sure threats are dealt with properly.

Leading that is Brendan Emmott, Head of Threat Operations.

He oversees the end-to-end threat operations function within unphish, including enforcement workflows, analyst performance, SLA management, and the ongoing development of processes that improve speed, consistency, and scale.

Brendan’s growth within the business has been quick. In under two years, he moved from Client Services Administrator to leading the threat operations function. Along the way, he’s played a key role in shaping how the team works today, and laying the foundations for a more structured, scalable threat operations capability.

Brendan Emmott Headshot

One thing that stands out pretty quickly is how outcome-focused the role is. A core focus of the function is reducing time-to-takedown and ensuring threats are handled within strict operational SLAs.

“I love seeing quick outcomes for both the team and myself. Successfully closing a case and getting phishing or infringing sites removed promptly is incredibly satisfying.”

 
There’s a clear sense of momentum in the work. It’s not just about identifying threats, it’s about actually resolving them.

A common misconception is that this kind of work is straightforward. Report something, wait, and it gets taken down quickly.

In reality, it’s not that simple.

“People often think it’s just reporting content and waiting for action. In reality, it requires persistence, escalation, and adapting your approach depending on the registrar or platform involved.”

 
A lot of the work sits in that persistence. Following up, adapting approaches, and working through situations that don’t always have a clear or immediate outcome.

That mindset also shows up in how Brendan approaches problem solving more broadly.

“I analyse, research, and then take action, adapting known approaches to meet the specific issues at hand.”

 
It’s a methodical approach, but one that still allows for flexibility when things don’t go to plan.

His progression into the role has also been shaped by a pretty clear mindset.

“Grit and determination have been key. I’ve learned from the ground up, staying receptive to new information and always looking for ways to improve.”

 
There’s a strong focus on being proactive and curious, rather than waiting to be told what to do.

That carries through into how he leads the team today.

“I don’t like to micro-manage, so I focus on giving the team the tools and guidance they need to work independently.”

 
The goal is to create an environment where analysts feel confident making decisions and taking ownership of their work, while still having the support they need.

A big part of that has been the shift towards automation within the platform.

“The move to automation has been a game-changer. It allows us to scale threat detection and enforcement, handle significantly higher volumes, and maintain consistent outcomes without increasing manual workload.”

 

Some of the moments that stand out most aren’t necessarily individual wins, but how the team operates as a whole.

“I’m proud of how quickly my team adapts to new client needs and emerging issues. They share the same passion I do for getting content removed.”

 
That ability to adapt is critical in a space where threats are constantly changing and evolving.

For anyone starting out in this area, his advice is pretty simple.

“Be curious, detail-oriented, and proactive.”

 
Understanding how threats evolve, learning how different platforms work, and being willing to ask questions all play a big role in developing quickly.

Outside of work, things look a little different. Brendan’s a big traveller, with places like the Ha Giang Loop in Vietnam standing out as a highlight.

Brendan Emmott on a waterfall

“Riding on a motorbike for four days was a little risky, but the views were breathtaking.”

 
At the end of the day, threat operations at unphish isn’t just about detecting problems. It’s about solving them, often quickly, and in situations that aren’t always straightforward.

It’s a mix of persistence, problem solving, and a team that knows how to move fast when it matters.

About unphish

Protect Your Brand with unphish

unphish is a threat detection and disruption platform built to identify and take down phishingscams, and digital impersonation at scale. We combine intelligence-led detection with automated enforcement to help organisations protect their brand, customers, and digital ecosystem.

See unphish in Action

Detect, Validate, and Take Down Threats Automatically

unphish combines intelligence-led detection with automated enforcement so you can protect your brand, customers, and digital ecosystem without the manual effort.

Create your account