Join our Newsletter — 33% off our NHI Course

Why do phishing and business email compromise continue to succeed even when organisations invest in awareness training?

Phishing succeeds because attackers exploit timing, trust, and human judgment, not just technical gaps. The report shows many organisations still experience successful attacks, even while training exists, which suggests awareness alone is insufficient. Security teams need layered controls such as email filtering, user reporting, rapid response, and consequence models that make risky behavior visible and correctable.

Why training alone does not stop phishing and business email compromise

Phishing and business email compromise keep working because they are designed to win a narrow decision window. Attackers use familiar brands, urgent requests, and timing that fits normal work habits, so even well-trained users can be hurried, distracted, or socially pressured into approving the wrong action. Awareness reduces risk, but it does not remove the attack path.

Training also tends to be weakest where real-world attacks are strongest: when the message looks routine, arrives through a trusted channel, or triggers an exception process such as invoice payment, password reset, or executive escalation. That is why the control question is not whether users know the signs, but whether the organisation can absorb a bad click, a false trust decision, or a compromised mailbox without losing containment.

When the attack succeeds, it usually reflects a control gap across the full email and account lifecycle, not a single missed lesson. A user may recognise the warning signs and still act under pressure if the message aligns with their job role, the sender looks credible, and the surrounding workflow does not add friction before money, credentials, or sensitive data move.

Why the same attack works across different teams and situations

Phishing and BEC succeed because they are adaptive, not static. Attackers vary the lure, the pretext, the target’s role, and the moment of delivery. Finance teams, executives, HR, and IT staff each face different prompts, but the underlying advantage is the same: the attacker is trying to make a legitimate process feel normal enough to bypass scrutiny.

This is why one-time awareness campaigns rarely create durable resistance. People do not make security decisions in a vacuum; they make them while handling deadlines, approvals, vendor disputes, password resets, travel, and inbox overload. The more the message resembles everyday business, the more training has to compete with habit and operational pressure.

Organisations also underestimate how often compromise starts after the initial interaction. A phished credential, a stolen session, or a mailbox rule can turn one mistaken response into ongoing access. In that sense, the success condition is not just opening the message, but allowing the attacker to convert attention into authenticated access, persistence, or payment fraud.

What layered defence has to do that awareness cannot

Awareness training is only one layer, so the better question is whether the rest of the control stack can catch what people miss. Strong programmes combine filtering, suspicious-message reporting, mailbox monitoring, multi-factor protection, payment verification, and fast containment so that a single human decision does not become a full incident.

Controls work best when they change the economics of the attack. If users can report a message quickly, security can quarantine similar mail. If high-risk actions require a second channel of verification, the attacker has to beat two trust checks instead of one. If compromised accounts are detected and isolated quickly, the attacker has less time to use the mailbox as a trusted platform for further deception.

The practical lesson is that BEC is often a workflow problem as much as a security problem. The business process itself should make unusual requests difficult to approve, easy to verify, and visible to defenders before funds move or access is abused. Training helps users notice suspicion; controls make suspicion actionable.

Risk and Threat Considerations

Phishing and BEC remain effective because they exploit trust relationships, executive authority, and hurried decision-making, then convert a single successful message into credential theft, fraudulent payment, mailbox abuse, or lateral movement. The risk is amplified when the organisation relies on human judgment alone for approvals or exception handling.

Failure mechanism: The attacker impersonates a trusted sender, times the message to a business process, and pressures the recipient into approving an action before verification or reporting can occur. Once access or payment is obtained, the attacker can persist through mailbox rules, session theft, or follow-on social engineering.

Impact: Successful BEC can lead to direct financial loss, data exposure, account compromise, and secondary fraud against customers, suppliers, or internal teams. Repeated success also erodes confidence in email as a trusted business channel.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while CIS Controls v8, NIST SP 800-53 Rev 5 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
MITRE ATT&CK T1566 — Phishing Phishing is the core attack pattern behind the question.
T1114 — Email Collection BEC often abuses mailbox access and inbox monitoring for persistence.
T1078 — Valid Accounts Successful phishing often converts deception into legitimate account use.
Recommendation — Map phishing lures and delivery vectors to T1566 and tune detections for user-targeted deception. Monitor mailboxes for rule creation, forwarding, and suspicious access linked to T1114. Hunt for valid-account abuse after credential or session compromise.
CIS Controls v8 CIS-5 — Account Management Account and mailbox protection limit how phishing becomes persistent access.
CIS-8 — Audit Log Management Detection of BEC depends on logging mailbox and authentication activity.
Recommendation — Harden account lifecycle and restrict privileged mailbox access paths. Centralize and review email, auth, and admin logs for suspicious takeover signals.
NIST SP 800-53 Rev 5 AU-6 — Audit Record Review, Analysis, and Reporting BEC detection depends on timely review of suspicious email and account activity.
IR-6 — Incident Reporting Fast user reporting is part of the control model for phishing containment.
IA-2 — Identification and Authentication (Organizational Users) Phishing often succeeds by abusing authenticated user access after deception.
Recommendation — Review suspicious email and account activity promptly to shorten attacker dwell time. Provide simple reporting paths so users can escalate suspicious messages immediately. Strengthen user authentication so stolen passwords alone do not enable access.
NIST SP 800-63 Digital Identity Guidelines Phishing resistance and authenticator strength are central to reducing account takeover.
Recommendation — Use phishing-resistant authenticators where account takeover risk is material.

Practitioner Guidance

What to prioritise: Treat awareness as a trigger for layered defence, not the main control. The most useful next investment is usually the one that reduces blast radius, such as stronger reporting paths, verification for payments or account changes, and rapid containment of suspicious mail or compromised accounts.

What to verify: Check whether the organisation can prove three things in practice: users report suspicious mail fast, security teams can act on those reports quickly, and business processes force out-of-band verification for high-impact requests. If any one of those is missing, training will not carry the control on its own.

Practitioner takeaway: The goal is not to make every user perfectly resistant, it is to make one mistaken click or one mistaken approval non-catastrophic by binding human judgment to technical and process controls.