The point at which repeated phishing tests stop producing meaningful improvement because employees learn the template rather than the safer behaviour. It is a measurement failure, not proof that the organisation has become resilient.
Expanded Definition
A simulation plateau happens when a security awareness programme stops showing better phishing-test results because the test pattern becomes familiar. The metric improves at first, then flattens, even though the underlying risk may still exist. In practice, the plateau reflects measurement saturation, not a finished control environment.
In identity and email security programmes, the term is most often used for repeated phishing simulations, but the same pattern can appear in other recurring tests where people begin to recognise the exercise rather than internalise the safer behaviour. That distinction matters because a low click rate can be misleading if employees have simply learned the template, timing, or sender style. Guidance on security controls in NIST SP 800-53 Rev 5 Security and Privacy Controls supports awareness and training as an ongoing control, but it does not imply that repeated exposure alone guarantees behaviour change.
Definitions vary across vendors on whether the plateau is treated as a training problem, a metrics problem, or both. NHI Management Group treats it as a signal that the exercise design, audience segmentation, and follow-up actions need review. The most common misapplication is treating a flatter phishing metric as proof of resilience, which occurs when teams ignore whether users are responding to the campaign itself rather than to the malicious cues.
Examples and Use Cases
Implementing phishing simulations rigorously often introduces a realism versus predictability tradeoff, requiring organisations to weigh behavioural learning against the risk of users memorising the exercise pattern.
- A finance team sees click rates fall for three consecutive phishing campaigns, but post-test interviews show staff now watch for the same wording and ignore the exercise cues rather than verifying sender identity.
- An identity operations team rotates simulation templates, sender domains, and delivery times after noticing that employees have begun reporting the test based on formatting alone, not on suspicious behaviour.
- A help desk receives fewer phishing reports after a monthly campaign, yet incident response data shows the same credential-harvesting tactics still succeed when delivered through new lures or external channels.
- A security awareness lead pairs simulations with short reinforcement content, because the plateau indicates that testing alone is no longer changing user judgement or escalation habits.
- A governed programme benchmarks its training against control expectations in NIST SP 800-53 Rev 5 Security and Privacy Controls and adjusts the exercise design when repeated patterns stop yielding new insight.
In organisations with mature reporting channels, a plateau may still coexist with stronger resilience if employees escalate suspicious messages more reliably. The key question is whether the programme is measuring habit change or campaign recognition. If the latter dominates, the apparent improvement has limited operational value.
Why It Matters for Security Teams
Simulation plateau matters because security teams can make bad decisions from good-looking numbers. If leadership assumes that stable phishing metrics mean the workforce is safer, they may freeze training budgets, stop refreshing test design, or miss groups that still need targeted intervention. That creates blind spots in access protection, credential hygiene, and incident escalation.
For identity and NHI-adjacent programmes, the issue is especially important where a single compromised credential or token can lead to broader access abuse. Repeated simulations should inform a wider control strategy that includes reporting pathways, access review, conditional access, and privileged account protections. Awareness data should be read alongside control evidence from frameworks such as NIST SP 800-53 Rev 5 Security and Privacy Controls, rather than treated as a standalone proof point.
Organisations typically encounter the consequences only after a real phishing event bypasses the familiar simulation pattern, at which point simulation plateau becomes operationally unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack surface, NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST SP 800-63 set the technical controls, and ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AT | NIST CSF includes awareness and training outcomes relevant to repeated simulation fatigue. |
| NIST SP 800-53 Rev 5 | AT-2 | AT-2 defines security awareness training, the control area most affected by simulation plateau. |
| ISO/IEC 27001:2022 | A.6.3 | ISO 27001 addresses awareness, education and training as part of people-focused security controls. |
| NIST SP 800-63 | Digital identity assurance depends on human authentication behaviour, which simulations can indirectly influence. | |
| OWASP Non-Human Identity Top 10 | NHI governance depends on reducing credential misuse, which awareness plateaus can undermine. |
Align simulation programmes to awareness outcomes and revalidate effectiveness after each campaign cycle.
Related resources from NHI Mgmt Group
- How should teams govern access to digital twin simulation platforms?
- What breaks when simulation platforms are shared across contractors and internal teams?
- How do IAM teams evaluate the risk of AI or robotics outputs coming from simulation?
- How do you know if policy simulation is actually improving governance?