Simulation scores show who clicked or responded, but they do not explain who is at elevated risk, who has sensitive access, or whether an active threat campaign is targeting them. Identity and threat context turns raw training data into practical risk intelligence. That helps security leaders focus limited resources on the most exposed users and the most likely attack paths.
Why This Matters for Security Teams
Simulation scores are useful, but they are not a risk model. A user who clicks a phishing simulation and a user who clicks while holding finance approvals, admin rights, or access to sensitive systems are not equivalent. Security teams need identity context, threat context, and behavioural context to separate ordinary awareness metrics from operational exposure. That is especially true when real adversaries are adapting campaigns in parallel, which is why guidance from sources such as the CISA cyber threat advisories matters alongside internal telemetry.
NHIMG’s Ultimate Guide to NHIs shows why identity context changes the interpretation of risk: 80% of identity breaches involved compromised non-human identities such as service accounts and API keys. The same principle applies to human-targeted assessments. A low simulation score is not automatically the highest priority if the user has no meaningful access, while a moderate score can be far more urgent when paired with elevated privilege or active targeting. In practice, many security teams discover this only after a real campaign has already selected its next victim.
How It Works in Practice
Identity and threat context turns a training result into an actionable decision. The assessment score becomes one signal among several: role, privilege level, business function, location, recent authentication anomalies, sensitive system access, and current threat intelligence. This is consistent with broader identity guidance in NIST SP 800-53 Rev 5 Security and Privacy Controls, which treats access control and monitoring as part of ongoing risk management rather than one-time measurement.
In operational terms, mature teams usually enrich assessment results with:
- Identity attributes, such as executive status, finance access, privileged roles, or third-party sponsorship.
- Threat intelligence, such as active phishing themes, regional campaigns, or impersonation activity targeting specific departments.
- Access-path analysis, so the score is tied to the systems the user could actually affect if compromised.
- Behavioural change, including unusual logins, device shifts, or repeated credential prompts after the simulation.
This is where NHIMG research is especially useful. The 52 NHI Breaches Analysis and the Ultimate Guide to NHIs — Key Challenges and Risks both reinforce a core lesson: exposure is not just about whether an account is targeted, but what that identity can reach once trust is misplaced. When teams combine assessment data with current threat indicators, they can prioritize users who are both susceptible and operationally consequential. These controls tend to break down in organisations with fragmented identity inventories because risk scoring cannot be trusted when access ownership, privilege, and threat feed coverage are incomplete.
Common Variations and Edge Cases
Tighter scoring models often increase administrative overhead, requiring organisations to balance precision against the cost of enrichment and review. That tradeoff is real, and current guidance suggests a phased approach rather than a perfect model on day one. Some teams start with simple weighting for privileged users, while others add threat feeds only for active campaigns affecting their sector.
There is no universal standard for this yet, but several edge cases matter. Contractors and third parties may show low simulation failure rates while still representing high exposure because their access is limited but highly sensitive. Executives may need different scoring treatment because their identities are more frequently impersonated. High-frequency testers can also distort raw scores if training fatigue is not separated from real susceptibility. For that reason, practitioners should avoid using a single score as the final answer and instead treat it as an input to prioritisation, response, and coaching.
Where the evidence is strongest, teams should align assessment results with active threat intelligence and the identity inventory already used for access governance. External reporting such as Anthropic — first AI-orchestrated cyber espionage campaign report and the ENISA Threat Landscape both reflect the same operational reality: adversaries adapt quickly, so static scoring alone becomes stale. The best programs use context to decide who needs immediate intervention, not just who needs more training.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10, CSA MAESTRO and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | ID.AM-1 | Asset and identity inventories are needed to map scores to real exposure. |
| OWASP Non-Human Identity Top 10 | NHI-01 | Identity context prevents treating all access-bearing identities as equal. |
| NIST AI RMF | Risk context is required to turn signals into governance decisions. | |
| CSA MAESTRO | GOV-2 | Agentic-style governance also requires context-aware prioritization and oversight. |
| OWASP Agentic AI Top 10 | A2 | Dynamic adversary behavior makes static scoring insufficient for prioritization. |
Link assessment results to identity inventories and access paths before prioritizing response.
Related resources from NHI Mgmt Group
- Who should approve sensitive identity changes after a social engineering attempt?
- Why do traditional identity processes fail against social engineering and hiring fraud?
- How should security teams reduce social engineering risk in identity recovery workflows?
- Who is accountable when social engineering defeats identity controls?