TL;DR: Exposed losses from business email compromise reached $44 billion over five years, the average data breach cost hit $9.44 million, and phishing attacks rose 35% last year, according to Abnormal AI. The underlying problem is not that prevention failed once, but that many security programmes still assume attackers are static while the threat landscape keeps changing.
At a glance
What this is: This is a webinar-based analysis arguing that cybersecurity myths are failing because attackers keep adapting, while exposed losses from business email compromise, breach costs, and phishing activity continue to rise.
Why it matters: IAM, security, and risk teams need to treat prevention as necessary but insufficient, because static control assumptions break down when attacker behaviour and phishing tactics continue to evolve.
By the numbers:
- $44 billion in exposed losses to business email compromise over the past five years.
- The cost of a data breach is now $9.44 million.
- There was a 35% increase in phishing attacks last year.
Context
The article is a webinar promotion framed around a simple security argument: attackers adapt faster than programmes built on the assumption that prevention alone can make an environment safe. The primary concern is not a single control failure but the governance gap created when teams treat resilience as proof of invulnerability.
For IAM and security leaders, the important issue is how quickly threat conditions invalidate static assumptions about phishing resistance, breach containment, and user trust. That matters across human identity programmes, because email abuse and social engineering still convert identity weakness into business loss.
The figures cited in the piece are there to support the broader warning that the threat landscape keeps changing. The practical question for practitioners is how to prepare programmes to absorb repeated attempts, not just block a single one.
Key questions
Q: What breaks when organisations assume phishing prevention makes them safe?
A: The main failure is complacency. Prevention lowers risk, but adaptive attackers keep finding new paths through trust, workflow, and user behaviour. When teams assume the environment is effectively impenetrable, they underinvest in verification, monitoring, and response. That leaves business email compromise and related fraud with room to succeed even when surface-level controls look strong.
A: Phishing succeeds because attackers only need one person to act under pressure. Once credentials are stolen, the impact can spread into account takeover, fraud, service disruption, and compliance exposure. The article also links phishing to identity fraud and regulatory penalties, showing that the cost is not just the initial click but the downstream loss of trust and control.
Q: What signs show that email identity controls are not keeping pace?
A: Watch for stale shared mailboxes, persistent delegated send permissions, accounts that remain active after role change, and alerts that show unusual sending behaviour from trusted identities. Those signals usually mean the organisation is protecting the inbox but not the identity behind it.
Q: How should security teams respond when phishing losses keep rising?
A: They should treat the issue as a programme-design problem, not a single-tool problem. That means tightening verification on high-risk requests, testing real trust paths, and reviewing whether current controls still match attacker behaviour. The goal is to reduce the chance that one deceptive message becomes a financial or identity incident.
Background and context
Why breach prevention does not end the threat model
Prevention controls reduce risk, but they do not remove the attacker’s incentive to keep probing for new paths. In practice, email security, user training, and layered filtering are all designed to lower success rates, not to guarantee invulnerability. The problem emerges when organisations translate better control coverage into the false belief that phishing and business email compromise can be treated as solved. That mindset weakens preparedness because it shifts attention away from detection, containment, and response. The article’s numbers reinforce that these attacks remain commercially attractive even when defences improve.
Practical implication: treat prevention as one layer in a broader identity and response programme, not as proof that the attack class has been neutralised.
How phishing and business email compromise turn identity trust into loss
Phishing works because it targets trust relationships, not just technical flaws. Once a user, mailbox, or workflow is deceived, attackers can pivot into payment fraud, mailbox access, or downstream impersonation. Business email compromise is especially damaging because it exploits ordinary business processes and authorised communication channels, which means controls must cover both authentication and the decisions made after authentication. The article’s focus on exposed losses shows that this is not a narrow email problem but an identity abuse problem with financial consequences.
Practical implication: align email security with identity verification and transaction scrutiny so fraudulent requests are challenged before value moves.
Why static security assumptions fail in a changing threat landscape
Security programmes often assume that a control set can be tuned once and then maintained with minor adjustments. Attackers do not operate on that schedule. They change lures, abuse new collaboration patterns, and exploit whatever trusted channel currently produces the best return. That means the real failure is not the existence of controls but the assumption that attacker behaviour stays stable long enough for defensive posture to remain valid. In governance terms, the control objective is continuous adaptation, not one-time completeness.
Practical implication: build review cycles that test whether your phishing, mailbox, and fraud controls still match current attacker behaviour.
NHI Mgmt Group analysis
Cybersecurity myth, not control absence, is the deeper governance failure: the dangerous assumption is that stronger tools can make an organisation effectively impenetrable. That assumption was never defensible against adaptive adversaries, and it breaks down further when phishing and BEC remain profitable at scale. The implication is that resilience must be designed around repeated intrusion attempts, not one-time prevention success.
Business email compromise is an identity governance problem disguised as an email problem: attackers exploit trusted communication, authority, and payment workflows, which means the loss pathway runs through human trust and business process legitimacy. This is why email security alone does not close the risk. Practitioners need to see BEC as a cross-domain control failure spanning authentication, verification, and financial approval.
Phishing resistance should be measured by adaptability, not by control count: more tools do not automatically produce more resilience if they are tuned to an outdated threat model. A programme can be heavily instrumented and still fail if attacker tactics evolve faster than policy, training, and response loops. The practitioner conclusion is that review cadence and behavioural testing matter as much as preventive coverage.
Exposed loss figures show that the market has not outgrown social engineering: the scale of the loss and the increase in phishing indicate that basic trust manipulation remains one of the most durable attack paths. That should push boards and security leaders away from myth-based assurance narratives and toward continuous validation of user, mailbox, and transaction controls. The practical outcome is a programme that assumes compromise attempts will recur.
Adaptive adversary pressure demands a living control model: the named concept here is a resilience gap created by control complacency. When a team believes the environment is already secure enough, it stops testing whether the controls still match current attacker behaviour. The field implication is that governance must treat phishing and BEC as moving targets, with each review cycle asking what changed in attacker tradecraft.
From our research library:
- The IBM/Ponemon 2025 Cost of a Data Breach Report found that phishing-initiated breaches cost an average of $4.8M each.
What this signals
Control confidence is not the same as control resilience: teams that have invested heavily in prevention can still be exposed if their operating model assumes the threat is static. The practical shift is to test whether phishing, mailbox abuse, and fraudulent approval paths still defeat your controls in today’s environment.
The most important programme question is whether your verification steps actually interrupt trust abuse before money, credentials, or sensitive access move. If they do not, the control stack is likely optimised for awareness reporting rather than loss prevention.
For practitioners
- Test email trust paths continuously Run regular simulations and scenario reviews that stress mailbox access, sender trust, and approval workflows, then compare results against actual incident patterns rather than training completion alone.
- Add verification to payment and approval flows Require independent confirmation for high-risk requests that arrive by email, especially where bank details, invoice changes, or urgent exceptions are involved.
- Monitor for business email compromise indicators Track anomalous forwarding rules, suspicious sign-in behaviour, and unusual payment requests as a combined fraud and identity risk signal.
- Rebaseline phishing response metrics Measure whether your controls reduce successful credential capture, fraudulent replies, and downstream business impact, not just click-through rates.
Key takeaways
- The article argues that cyber myths persist when organisations mistake preventive coverage for actual invulnerability.
- The cited figures point to a large and continuing impact from business email compromise, breach costs, and phishing growth.
- Practitioners should respond by testing trust paths, tightening verification, and measuring resilience against current attacker behaviour.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | ID.RA-01 — Asset Vulnerability | The article centres on changing threat conditions and risk assumptions. |
| PR.AA-05 — Access Permissions, Entitlements and Authorizations | Email abuse becomes harmful when trusted access and authorisation paths are misused. | |
| DE.CM-01 — Networks and Systems Monitored | Continuous monitoring is needed to detect trust abuse and anomalous mailbox behaviour. | |
| Recommendation — Reassess phishing and BEC risk regularly as attacker tactics change. Strengthen authorisation checks around mailbox and payment-related workflows. Monitor for suspicious forwarding rules, login anomalies, and payment fraud signals. | ||
| NIST SP 800-63 | SP 800-63B — Authentication | Phishing success depends on weaknesses in authentication and user verification. |
| Recommendation — Apply stronger authentication and verification wherever email trust leads to access or action. | ||
Key terms
- Business email compromise: A form of social engineering where an attacker impersonates a trusted person or domain to manipulate payment, change banking details, or extract sensitive information. It often succeeds without malware because the attacker targets process trust and human judgement instead of technical controls.
- Phishing Resistance: Phishing resistance is the ability of a user and an authentication process to withstand impersonation attempts and malicious requests. It depends on stronger verification habits, safer authenticators, and workflows that make it harder to accept fraudulent prompts.
- Trust Path: A trust path is the sequence of systems a request passes through before identity controls or service access complete. It includes resolution, routing, verification, and policy enforcement, so weak controls anywhere in the path can undermine the assurance of the final access decision.
- Control Complacency: A governance failure where teams assume that having security tools in place means the environment is effectively safe. This mindset is dangerous because attackers adapt, so the real test is whether controls still match current behaviour and loss patterns.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org