By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: Horizons.aiPublished March 11, 2026

TL;DR: A university found that 84 phished credentials led to 482 verified impact paths, 257 compromised hosts, and domain compromise in 19 minutes, according to Horizons.ai. The result shows why phishing awareness metrics alone miss the security question that matters most: how far an attacker can go after one credential is exposed.


At a glance

What this is: A university used phishing impact testing to show that low click rates did not prevent domain-wide compromise and measurable blast-radius expansion.

Why it matters: IAM, PAM, and identity governance teams should care because credential compromise only becomes a programme-level failure when privilege, lateral movement, and data access are mapped to real impact.

By the numbers:

👉 Read Horizons.ai's analysis of phishing impact testing and blast-radius reduction


Context

Phishing remains an identity problem as much as a user-awareness problem. A click only becomes material risk when the submitted credential can reach privileged systems, data stores, or lateral movement pathways that change the organisation’s blast radius. This article is about measuring that consequence, not measuring participation in a simulation.

For IAM and identity governance teams, the practical issue is whether training, access scope, and remediation are connected. If controls are reported as successful while one account can still cascade into domain compromise, the programme is optimising for the wrong signal. The university is a strong example of how awareness gains can coexist with hidden identity exposure.

The article is also notable because it shows a small security team replacing opinion with proof. That is typical of environments where identity sprawl, legacy permissions, and limited staffing make traditional reporting too shallow to guide remediation priority.


Key questions

Q: How should security teams measure phishing risk beyond click rates?

A: Use layered behavioural signals instead of a single click metric. Track opens, credential submissions, replies, and tactic-specific susceptibility over time so you can segment risk by role and scenario. That gives security teams a more defensible basis for coaching, reporting, and board conversations than completion rates or one-off campaign results.

Q: Why do phished credentials still create major risk in well-trained organisations?

A: Because training improves user behaviour, but it does not automatically fix access design. If a submitted credential still has broad permissions, legacy access, or trust relationships that enable escalation, one click can still become a major incident. Identity governance must reduce the damage a valid credential can do.

Q: What breaks when identity sprawl is not continuously reconciled?

A: Dormant accounts, duplicate identities, orphaned service accounts, and unmanaged AI identities accumulate across the estate, driving cost and creating blind spots. The programme loses the ability to tell which identities are still legitimate and which are simply consuming budget or expanding attack surface. Over time, the gap becomes both financial waste and control failure.

Q: Who is accountable when phishing simulations reveal large blast radius?

A: Accountability sits with the teams that own identity, privilege, and remediation governance, not just awareness training. If a simulation shows that common accounts can reach critical systems, leaders must answer for entitlement design, access review quality, and remediation prioritisation. Awareness is only one part of the control stack.


Technical breakdown

Why phishing click rates do not measure identity risk

Click rate is a user-behaviour metric, not an exposure metric. It tells you who submitted a credential, but it does not show what systems those credentials can reach, whether the account is over-privileged, or how quickly an attacker can pivot after login. In identity terms, the risk comes from the combination of authenticated access and reachable privilege, not from the click itself. That is why phishing simulations often create a false sense of control when they are not paired with path analysis, entitlement review, and impact testing.

Practical implication: pair awareness metrics with tests that measure reachable privilege and downstream access paths.

How compromised credentials become domain compromise

Once an attacker or tester authenticates with a valid account, the next stage is privilege mapping. That means identifying write permissions, inherited roles, misconfigurations, and systems that allow escalation or lateral movement. In a mixed legacy and modern environment, even a standard user can often chain multiple weaknesses into privileged access. The article shows this clearly: one compromised identity led to many verified impact paths because the surrounding access model had accumulated too much leverage over time.

Practical implication: review the privileges attached to common user accounts as carefully as you review admin accounts.

Blast radius as an identity governance measure

Blast radius is the practical measure of how far one compromised identity can travel before containment stops it. For identity teams, this includes not only credentials and permissions, but also the data objects, systems, and trust relationships those permissions unlock. When a single account can expose thousands or millions of data resources, the issue is not awareness but entitlement design. This is where access governance becomes operational security: reducing leverage is more valuable than counting weakness totals.

Practical implication: prioritise remediation for accounts with the largest reachable blast radius, not the most findings.


Threat narrative

Attacker objective: The objective is to turn one credential into broad operational access that reaches domain-level compromise and sensitive data exposure.

  1. Entry occurred when phished users submitted credentials during the simulation, giving authenticated access to legitimate accounts.
  2. Escalation followed as the platform mapped permissions, chained exploitable weaknesses, and moved from user access toward domain control.
  3. Impact was demonstrated through domain compromise, compromised hosts, ransomware exposure, and access to PCI-classified data items.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Click rate is an awareness metric, not a control outcome. Phishing programmes that stop at user behaviour create an accounting illusion: they can show improvement while the reachable attack surface remains unchanged. The university’s result demonstrates that the real question is not whether someone clicked, but whether the submitted credential could still reach privileged systems and sensitive data. That is a governance failure because it measures participation instead of exposure.

Blast radius is the right unit of identity risk when credentials are compromised. A single account that opens hundreds of verified impact paths is not a minor weakness, it is a leverage point in the identity model. For practitioners, that means entitlement design, inherited privilege, and legacy access matter more than aggregate vulnerability counts. The security programme should be judged by how much damage one account can still do.

Identity sprawl turns routine phishing into institutional risk. The article shows how permissions accumulated, legacy systems stayed active, and access patterns expanded faster than visibility. That pattern is common in mid-sized environments where operational convenience outpaces governance discipline. The implication is straightforward: if identity sprawl is not continuously reduced, a phished credential becomes an organisational event instead of a contained incident.

Phishing impact testing creates a named concept worth adopting: identity blast radius. This is the measurable distance between initial credential compromise and meaningful business impact. It gives security teams a way to connect IAM, PAM, and remediation prioritisation into one field-ready metric. Programs that cannot express identity blast radius are still operating with incomplete risk visibility.

For a team of one, proof beats volume every time. The university did not need more alerts, more findings, or more click-rate dashboards. It needed a reproducible way to show which identities mattered most and which remediations collapsed the most attack paths. That is the governance lesson for lean teams: prove leverage, then spend effort where leverage is highest.

From our research:

  • Two-thirds of enterprises have endured a successful cyberattack resulting from compromised non-human identities, with a quarter encountering multiple attacks, according to 2024 ESG Report: Managing Non-Human Identities.
  • 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, including 46% that confirmed a breach.
  • For broader identity governance context, see Ultimate Guide to NHIs , Key Challenges and Risks for visibility gaps, sprawl, and over-privilege.

What this signals

Identity blast radius should become a standing metric in programmes that still report phishing through click rates alone. Once a credential is submitted, the meaningful question is not user error but how far that identity can travel before containment, which is why blast-radius mapping belongs alongside IAM review and remediation planning.

The governance pattern here mirrors what NHI teams see when standing access persists too long: the problem is leverage, not volume. When access can chain into critical systems, a small compromise becomes an enterprise event, and the only durable response is to reduce the reachable path set rather than count more findings.

With 72% of organisations already experiencing or suspecting a non-human identity breach, identity teams cannot afford reporting models that ignore consequence. That is why the same discipline used in NHI governance, including entitlement reduction and lifecycle control, should now inform how phishing exposure is measured across human identities as well.


For practitioners

  • Measure phishing by downstream impact, not click rate Run phishing simulations with follow-on validation that shows which credentials can reach privileged systems, sensitive data, and lateral movement paths. Use that output to replace awareness-only reporting with exposure-based reporting.
  • Rank identities by blast radius Identify the accounts that create the greatest number of verified attack paths and prioritise them ahead of lower-leverage findings. In practice, this means looking for write permissions, inherited roles, and legacy accounts that expand access.
  • Collapse the access paths that make phishing consequential Target excessive write permissions, over-broad domain user privileges, and lateral movement pathways first. Retest after each change so you can confirm that remediated identities no longer chain into domain compromise.
  • Treat identity governance as remediation prioritisation Map user accounts, service accounts, and legacy access together so the programme can distinguish harmless exposure from accounts that can actually pivot into critical systems. That is the point where identity governance becomes operational risk reduction.

Key takeaways

  • Phishing awareness improves behaviour, but it does not prove that compromised credentials cannot reach critical systems.
  • The university’s testing showed that a small number of credentials could still produce domain-wide impact, which is exactly why blast radius matters.
  • Identity governance should prioritise the accounts that can do the most damage, because that is where remediation reduces real risk.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4The article centres on access permissions and how they amplify compromise impact.
NIST SP 800-53 Rev 5AC-6Excessive permissions and leverage are the control failure shown in the post.
MITRE ATT&CKTA0006 , Credential Access; TA0004 , Privilege Escalation; TA0008 , Lateral Movement; TA0040 , ImpactThe attack path moves from phished credentials to escalation, movement, and domain impact.
OWASP Non-Human Identity Top 10NHI-03Identity sprawl and over-privilege are classic NHI governance failures even when humans trigger the entry point.

Treat over-privileged identities as NHI governance issues and reduce standing access that expands blast radius.


Key terms

  • Blast Radius: The potential scope of damage if a specific credential or identity is compromised. Identities with broad permissions have a larger blast radius and represent a higher priority for least-privilege enforcement and security controls.
  • Identity Sprawl: Identity sprawl is the uncontrolled growth of identities, entitlements, and credentials across an environment. For NHIs, it usually appears when automation creates accounts faster than governance teams can inventory, review, and remove them. The result is hidden access, weak accountability, and a wider attack surface.
  • Phishing Impact Testing: Phishing impact testing uses real or simulated compromised credentials to measure what an attacker could actually do after initial access. It moves beyond awareness metrics by validating escalation paths, lateral movement, and sensitive data exposure in a live environment or safe simulation.

What's in the full article

Horizons.ai's full blog covers the operational detail this post intentionally leaves for the source:

  • The full attack-path visualisation showing how compromised credentials chained into domain control.
  • The per-account exposure breakdown that identifies which identities created the most leverage.
  • The remediation sequence used to reduce excessive write permissions and lateral movement pathways.
  • The follow-up testing evidence that confirmed the blast radius had actually collapsed.

👉 Horizons.ai's full post shows the credential-to-impact chain, exposure counts, and remediation outcome in detail.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org