Join our Newsletter — 33% off our NHI Course

What are the signs that TOAD phishing controls are not working well enough?

Weak TOAD controls usually show up as suspicious calls reaching employees, phishing emails still getting through, and repeated user reports of near-miss incidents. If filtering stops fewer malicious messages over time, or if awareness training does not reduce the number of users engaging with fraudulent requests, the control set needs adjustment. Dashboards should show whether attack volume is declining.

How TOAD control failure shows up in day-to-day operations

When TOAD phishing defences are working, employees should rarely even see the attack. Weak controls are usually visible first in the signal quality: suspicious calls keep reaching staff, malicious emails survive filtering, and the same people keep reporting near misses because the control stack is not stopping the lure early enough. If you are seeing that pattern, the issue is not just user behaviour, it is control effectiveness.

A second sign is consistency. A healthy defence stack should suppress the volume of fraudulent contact attempts over time, especially when the campaign pattern is stable. If the same style of phishing keeps arriving, or if it reaches the same business roles repeatedly, the control boundary is too porous or too slow to adapt. That often points to gaps in email filtering, call filtering, reporting triage, or the feedback loop between detection and blocking.

Control weakness also shows up when awareness activity does not change outcomes. Training by itself does not equal resilience, but if user engagement with fraudulent requests stays flat after repeated awareness campaigns, the organisation is not converting awareness into better decisions at the point of contact. In practice, that means the control set is leaning too heavily on human vigilance instead of reducing exposure upstream.

What the warning signals mean for filtering, reporting, and user behaviour

The most useful interpretation is to separate three layers: delivery, interaction, and learning. Delivery problems mean malicious messages or calls are still getting through. Interaction problems mean people are responding, clicking, replying, or escalating in ways that enable the attacker. Learning problems mean the organisation is hearing about incidents but not using those reports to improve prevention fast enough. A control can fail in one layer while still looking adequate in another.

Near-miss reports are especially important because they often reveal that blocking thresholds are too weak even when no confirmed breach has occurred. If many users are reporting the same pattern, the organisation already has evidence that the attack is surviving first-line controls. That should trigger review of mail rules, impersonation protections, call-handling procedures, and escalation paths, not just refresher training.

Dashboards need to answer a practical question: is attack volume declining, or are we just getting better at noticing it? If the reporting line rises while the prevention line stays flat, you may be improving visibility without improving resistance. That is useful, but it is not enough on its own. The control set should reduce exposure, not merely document it.

What practitioners should verify before they trust the control set

The first thing to verify is whether the signal is broad or concentrated. If a few users or one business unit are seeing most of the attempts, there may be a targeting or workflow issue that makes them easier to impersonate. If attempts are spread across the organisation, the problem is broader and usually points to weak baseline filtering, weak verification habits, or poor enforcement of out-of-band validation for sensitive requests.

It is also worth checking whether the organisation is measuring the right outcome. Counting blocked messages alone can hide weakness if the attacker simply shifts to channels that are less controlled, such as voice or SMS. A better view combines delivery, user interaction, report quality, and time to containment so you can see whether the control stack is shrinking the attacker’s practical options.

For teams that want a more structured view of control maturity, NIST Cybersecurity Framework 2.0 is useful for tying identify, protect, detect, respond, and recover outcomes together, and CIS Controls v8 is a practical benchmark for account management, logging, and defensive hygiene that often underpin phishing resistance. Where authentication strength matters, NIST SP 800-63 Digital Identity Guidelines helps frame phishing-resistant authentication expectations.

Risk and Threat Considerations

Weak TOAD controls create more than nuisance traffic. They increase the chance that a fraudulent request reaches a person at the moment they are least able to verify it, which raises the odds of credential theft, payment diversion, or sensitive data disclosure. The risk grows when the attacker can repeatedly test messages, calls, or workflows until one path works.

Failure mechanism: Delivery controls let malicious messages or calls through, and human-reporting loops do not close the gap quickly enough, so the same lure keeps finding reachable employees.

Impact: The organisation gets persistent exposure, more near misses, and a higher chance of a successful social-engineering event that bypasses technical controls and reaches business processes.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8, NIST SP 800-53 Rev 5 and NIST SP 800-63 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 DE.CM-01 — Monitoring for Unauthorized Personnel, Connections, Devices, and Software Repeated suspicious calls and emails require continuous monitoring of attack activity.
PR.AA-05 — Identity Management, Authentication, and Access Control are Managed Phishing succeeds when weak identity checks let fraudulent requests reach or influence users.
RS.CO-02 — Incidents Are Reported Consistent with Established Criteria Near-miss reports are a core signal that phishing controls are failing to stop reachability.
Recommendation — Track TOAD attempt trends so control failure is visible before incidents occur. Strengthen authentication and verification paths that phishing attempts try to exploit. Triage near-miss reports quickly and feed them back into prevention controls.
CIS Controls v8 CIS-9 — Email and Web Browser Protections Phishing emails that still get through indicate weakness in mail and web filtering controls.
CIS-14 — Security Awareness and Skills Training User interaction with fraudulent requests shows awareness outcomes are not improving enough.
Recommendation — Harden email and web protections against phishing delivery and link abuse. Measure whether awareness training reduces engagement with fraudulent requests.
NIST SP 800-53 Rev 5 SI-4 — System Monitoring Phishing control weakness is often detected through monitoring of repeated malicious attempts.
AU-6 — Audit Record Review, Analysis, and Reporting Dashboards and incident reports need analysis to show whether attacks are declining.
Recommendation — Monitor phishing delivery and interaction patterns for rising attack activity. Review phishing telemetry regularly and adjust controls based on trend evidence.
NIST SP 800-63 Phishing Resistance Phishing-resistant authentication is directly relevant when fraudulent requests target user sign-in and approvals.
Recommendation — Adopt phishing-resistant authentication where phishing pressure is persistent.
ISO/IEC 27001:2022 A.5.24 — Information security incident management planning and preparation Repeated near misses show incident handling and escalation need tighter preparation.
A.8.23 — Web filtering Email and link delivery controls are central when phishing messages continue to arrive.
Recommendation — Use incident preparation and reporting to shorten the time from near miss to control change. Tune filtering so malicious messages are blocked earlier in the attack chain.

Practitioner Guidance

What to prioritise: Treat repeated near misses and repeated delivery of suspicious calls as evidence of control weakness, not just user noise. Prioritise the channel where the attack is still getting traction, because the weakest channel usually determines real-world exposure.

What to verify: Confirm that your dashboards separate blocked attempts, user reports, and confirmed interactions. If all three move together, the control set is probably reducing only visibility, not attacker success.

Common mistake: Over-relying on awareness training while leaving filtering, caller verification, and escalation controls unchanged. Training is necessary, but it should not be the only line of defence against a repeatable phishing pattern.

Practitioner takeaway: A TOAD control set is not good enough when attackers still reach people often enough to create repeatable near misses, because that means the organisation is detecting social engineering without sufficiently preventing it.