TL;DR: Enterprise phishing simulation programs often plateau because repeated templates train recognition, not safer behaviour, and Living Security’s guide argues that large organisations need Human Risk Management, multi-channel testing, and behavioural signals to predict where human error will appear next. Simple click rates are no longer a reliable proxy for risk, and the governance problem now is measuring exposure that evolves faster than awareness campaigns.
At a glance
What this is: This guide argues that enterprise phishing simulation only works when it moves beyond static templates and click-rate reporting into a broader Human Risk Management programme that tracks behaviour, identity signals, and multi-channel attack patterns.
Why it matters: That matters to IAM and security teams because phishing outcomes increasingly intersect with account takeover, identity misuse, and operational access decisions, so human-risk telemetry needs to inform broader identity governance.
By the numbers:
- 71% of working adults admit to taking risky actions even when they know the dangers.
- The ratio of non-human to human identities now exceeds 100:1 in enterprise environments.
- Only 5.7% of organisations have full visibility into their service accounts.
Context
Enterprise phishing simulation is not just a training exercise. It is a governance mechanism for testing whether people, processes, and identity-linked controls can absorb realistic social engineering pressure without turning a message into account compromise or data loss. The article’s core point is that template-based programmes often measure familiarity with the test rather than resilience against the threat, and that is why enterprise phishing simulation remains relevant to broader identity governance.
Static campaigns fail because attackers do not reuse the same shapes, channels, or timing. In a large workforce, phishing outcomes also intersect with IAM when a click becomes credential theft, session abuse, or delegated access misuse, which is why human-risk data should be read alongside identity telemetry rather than in isolation. The article’s starting position is typical for mature enterprise awareness programmes, but its critique of plateaued metrics is widely applicable.
Key questions
Q: How can teams keep phishing simulations from harming trust?
A: Be transparent about the existence of simulations, explain their educational purpose, and avoid public shaming or performance punishment. Employees are more likely to report genuine threats when they see the programme as a safe learning loop rather than a trap. Trust improves detection quality.
Q: Why do repeated phishing templates stop reflecting real risk?
A: Repeated templates teach employees the shape of the exercise, so the programme measures memory rather than resilience. Once that happens, declining click rates can mask the fact that real attackers are using different wording, channels, and timing. Mature programmes change the lure mix to preserve the quality of the signal.
Q: What signals show a phishing programme is not improving security?
A: Look for flat click-rate trends, low scenario diversity, poor correlation with actual incidents, and no behavioural change across repeat tests. If the same results keep appearing while incident patterns remain unchanged, the programme is probably measuring compliance behaviour instead of meaningful risk reduction.
Q: How should organisations connect human risk data to IAM decisions?
A: High-risk simulation outcomes should inform access review, step-up checks, and targeted intervention when risky behaviour repeats. That does not mean every click becomes an access event, but it does mean identity teams can use behavioural evidence to prioritise attention where exposure is persistent.
Technical breakdown
Why template-based phishing simulation plateaus
Static phishing templates create a learning loop that rewards recognition of the exercise rather than safe behaviour under pressure. Over time, users learn message structure, branding cues, and recurring wording, so click rates fall even when real-world susceptibility has not changed. That is why a low simulation click rate can be misleading. The underlying problem is measurement bias: the exercise is no longer close enough to adversary tradecraft to produce meaningful risk signal. The article correctly points to multi-channel and scenario diversity as a way to keep the test aligned with actual attack conditions.
Practical implication: rotate scenarios, channels, and difficulty so the programme measures response to real attacker variation, not pattern memory.
How human risk management changes the control model
Human Risk Management shifts the unit of analysis from the single click to a risk profile built from behaviour, identity context, and threat exposure. In practice, that means a simulation platform should feed signals into broader security operations, not sit as a standalone awareness dashboard. The useful question is whether a user’s actions correlate with broader exposure patterns, such as repeated failures, risky workflows, or identity-linked events. This is where IAM becomes relevant, because behavioural risk only matters operationally when it can inform access review, step-up controls, and targeted intervention.
Practical implication: connect simulation outputs to IAM and SOC workflows so high-risk behaviour can drive controls, not just coaching.
NIST Phish Scale and simulation difficulty as a governance signal
The NIST Phish Scale is useful because it helps teams think about how detectable a lure is, not just whether users clicked. That matters because phishing programmes often optimise for simplistic examples that are easy to spot, which inflates confidence and hides exposure to more subtle lures. Simulation difficulty should be treated as a governance variable, with easier and harder scenarios mapped to different population segments and business roles. Without that structure, the programme produces inconsistent data and weak audit evidence.
Practical implication: score scenarios by detectability and align test difficulty to business risk, role sensitivity, and programme maturity.
Threat narrative
Attacker objective: The attacker wants trusted access that looks like legitimate human activity, because that makes follow-on compromise easier to hide and harder to contain.
- Entry begins when a convincing phishing message reaches an employee through email, SMS, QR code, or voice, bypassing superficial awareness filters through realistic task context.
- Credential abuse or session capture follows when the user enters secrets, approves an MFA prompt, or forwards sensitive information, turning a human mistake into identity compromise.
- Impact occurs when the attacker uses the stolen access to move into business systems, exfiltrate data, or launch further social engineering from a trusted internal account.
NHI Mgmt Group analysis
Template fatigue is a governance failure, not a training success. When simulation results flatline, the problem is usually not that the workforce has become safer. It is that the exercise has become predictable enough to train the test rather than the behaviour. That makes click-rate reporting a weak proxy for true risk reduction, especially when attackers adapt faster than awareness calendars. Practitioners should treat repetitive testing as a measurement defect, not a maturity milestone.
Human Risk Management becomes more useful when it connects to identity governance. Phishing does not end at the inbox. It often becomes credential misuse, session abuse, or risky access patterns that IAM and PAM teams must ultimately contain. That creates a real intersection between human identity and security operations, and it is where behavioural telemetry can support access decisions, targeted controls, and escalation paths. Practitioners should pull simulation data into identity workflows instead of leaving it in a separate training silo.
Multi-channel simulation reflects the real attack surface better than email-only programmes. SMS, QR code, and voice-based lures change the control question from email hygiene to trust management across channels. That matters because modern enterprise risk sits in the overlap between communication channels, identity verification, and rapid decision-making under pressure. The organisations that need this most are the ones with distributed workforces and high-value access paths. Practitioners should design tests around the channel mix attackers actually use.
NIST Phish Scale-style difficulty scoring should become part of programme design. Security teams need a way to distinguish easy detection from meaningful resilience. If scenario difficulty is not tracked, executives may see declining clicks while the organisation remains vulnerable to more subtle lures. The named concept here is simulation plateau risk: the point at which the programme keeps producing reassuring numbers without improving resistance. Practitioners should use difficulty scoring to keep the control honest.
What this signals
Simulation programmes will increasingly be judged on how well they feed identity and access decisions. If a phishing test identifies repeat risky behaviour, the next control should not be another generic reminder. It should be a targeted response that links human behaviour to IAM, PAM, and verification steps, especially in roles with broad operational access.
Simulation plateau risk will matter more as attackers diversify channels. Email-only testing will look increasingly disconnected from how modern social engineering works across SMS, voice, QR, and collaboration tools. Practitioners should expect boards and auditors to ask whether the programme still mirrors the real attack surface or only the most convenient one.
Human-risk telemetry becomes more valuable when it can be paired with identity visibility gaps. Where organisations lack clear view of accounts, entitlements, or service identities, human error can become the entry point that exposes a wider control failure. That is why behavioural security, identity governance, and access visibility will keep converging in mature programmes.
For practitioners
- Define a simulation baseline by role and channel Measure phishing response separately for email, SMS, voice, and QR code scenarios, then segment results by business role and privilege level so the programme reflects actual exposure patterns rather than one company-wide average.
- Replace repetitive templates with scenario libraries Use a rotating library of realistic scenarios tied to common workflows, external threats, and current fraud patterns so employees are tested on decision-making, not memory of a familiar template.
- Connect simulation data to identity workflows Send high-risk user outcomes into IAM, PAM, and SOC processes so repeated risky behaviour can trigger access review, coaching, or step-up verification where appropriate.
- Track scenario difficulty as a governance metric Score each lure by detectability and maintain a record of what level of challenge each workforce segment can handle before you declare the programme effective.
Key takeaways
- The central problem is not that employees know phishing is risky, but that repetitive simulations can measure recognition instead of resilience.
- The evidence in the article supports a shift toward Human Risk Management, where behavioural signals, scenario diversity, and channel coverage replace simple click-rate reporting.
- The practical response is to connect simulation outcomes to identity workflows, because human error often becomes an access problem before it becomes a breach.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AT-1 | Training and awareness are central to phishing simulation programmes. |
| NIST SP 800-53 Rev 5 | AT-2 | AT-2 governs security awareness training and supports simulation programmes. |
| MITRE ATT&CK | TA0001 , Initial Access; TA0006 , Credential Access | Phishing simulation addresses the entry and credential theft stages of attacker tradecraft. |
| CIS Controls v8 | CIS-14 , Security Awareness and Skills Training | CIS Control 14 directly aligns with phishing awareness and simulation programmes. |
Measure phishing exercises against PR.AT-1 and use results to refine targeted awareness actions.
Key terms
- Enterprise Phishing Simulation: A controlled exercise that sends realistic fake phishing messages to employees to observe how they respond. The purpose is to measure susceptibility, improve awareness, and identify risky behaviours before a real attacker exploits them.
- Human Risk Management: The practice of managing how people interact with security controls, especially under pressure, distraction, or deception. It combines training, policy, and friction management so identity systems are still usable enough that users do not bypass them in day-to-day work.
- Simulation Plateau: The point at which repeated phishing tests stop producing meaningful improvement because employees learn the template rather than the safer behaviour. It is a measurement failure, not proof that the organisation has become resilient.
- Scenario Difficulty: A measure of how detectable or realistic a phishing test is, based on cues, channel, timing, and context. Tracking difficulty helps teams separate easy recognition from actual resilience and design programmes that stay close to real attacker tradecraft.
What's in the full article
Living Security Human Risk Management Platform's full blog covers the operational detail this post intentionally leaves for the source:
- The full scenario design guidance for building an enterprise phishing simulation library across email, SMS, QR code, and voice.
- The platform-specific approach to weighting behaviour, identity, and threat signals when scoring human risk.
- The monthly operating rhythm for reviewing outcomes, adjusting difficulty, and triggering targeted follow-up actions.
- The article’s examples of how Living Security positions automation for routine tasks inside a Human Risk Management workflow.
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It is designed for practitioners who need to connect identity controls to real operational risk across modern security programmes.
Published by the NHIMG editorial team on August 21, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org