By NHI Mgmt Group Editorial TeamBased on Abnormal AI: “The People Problem: Addressing Human Behavior to Build Better Email Security” (June 26, 2026)

TL;DR: Email security is increasingly a behavioural problem, with attackers using phishing, business email compromise, and AI-powered tactics to exploit the human element, according to Abnormal AI. That means resilience now depends on combining user education with technology rather than treating awareness as a separate programme.


At a glance

What this is: This webinar argues that email security is increasingly shaped by human behaviour, with phishing, BEC and AI-powered attacks exploiting user decisions as much as technical gaps.

Why it matters: For IAM and security teams, the message is that phishing resilience depends on aligning identity controls, user education and detection rather than treating awareness as a standalone programme.


Context

Email security is the discipline that protects users and organisations from malicious messages, impersonation and account abuse. In this webinar, Abnormal AI frames the problem as behavioural as much as technical, with attackers using phishing and business email compromise to exploit the human element.

That framing matters for identity programmes because email remains the entry point for credential theft, social engineering and downstream access abuse. The practical question is no longer whether training or technology is better, but how they work together to reduce human-driven attack paths.


Key questions

Q: How should security teams reduce phishing risk without relying only on awareness training?

A: They should combine user training with behavioural detection, vendor verification, and tighter controls on high-risk identity actions. Awareness helps users spot obvious lures, but it does not stop impersonation that looks routine. The stronger model is to detect trust abuse across mail, identity, and workflow layers before approval or credential use occurs.

Q: Why does AI-assisted phishing make human error harder to manage?

A: AI-assisted phishing produces messages that are grammatically clean, context-aware, and tailored to the target, which reduces the value of spotting obvious errors. That means security teams should rely less on user detection alone and more on technical controls that verify identity, reduce exposure, and speed up response when a credential is at risk.

Q: What are the warning signs that phishing controls are too message-focused?

A: If the programme measures blocked spam but not user actions, approval abuse or post-click compromise, it is probably too message-focused. A mature approach also tracks whether suspicious requests lead to credential entry, mailbox rule changes, delegated access or financial action.

Q: How should teams govern email access when an agent needs it to work?

A: They should govern it as a non-human identity boundary. That means assigning ownership, scoping what the inbox can reach, limiting default blast radius, and defining revocation criteria from the start. If the inbox is part of the workflow, then its access profile must be reviewed like any other privileged operational dependency.


Background and context

Why phishing and BEC are now identity problems

Phishing and business email compromise are not just content threats. They are identity attacks that manipulate trust, urgency and routine account behaviour to get users to approve, reveal or execute actions that create access risk. Once an attacker controls the conversation, the email channel becomes a launch point for credential capture, payment diversion or delegated access misuse. In practice, that means the security boundary is no longer the inbox alone. It extends into user decision-making, verification steps and the controls that detect abnormal sender, message and session behaviour.

Practical implication: treat email threats as identity abuse paths, not only message filtering problems.

How AI-powered attacks change the email defence model

AI-powered attacks increase scale, variation and believability. That makes static indicators and one-time awareness messaging less reliable because the attacker can adapt wording, timing and pretext faster than manual review can keep up. The real shift is that defenders have to evaluate whether controls can recognise behavioural anomalies, not just known malicious artefacts. Human judgment still matters, but it must be supported by detection that understands context, communication patterns and abnormal request sequences.

Practical implication: move from signature-first thinking to behavioural detection and verification controls.


NHI Mgmt Group analysis

Behavioural susceptibility is now a core email security control plane: Email defence fails when organisations treat user judgement as an external variable instead of part of the control design. Phishing and BEC succeed by shaping human decisions at the moment of action, which means the programme has to measure and influence behaviour as directly as it monitors messages. Practitioners should treat human response patterns as a governed security surface, not a soft edge.

Awareness training and detection only work when they are linked: Training alone decays into periodic memory, while technology alone misses social context and intent. The article’s central point is that resilience comes from combining user education with security technology so that each reinforces the other at the point of decision. That is a governance issue, not a training issue in isolation.

AI raises the volume and credibility of email deception: AI-assisted phishing does not change the basic identity problem, but it compresses the time available for humans to recognise suspicious requests. That increases the value of anomaly detection, policy-backed verification and workflow controls that reduce reliance on ad hoc human judgment. The implication is that teams must assume adversaries can personalise at scale.

Human behaviour is the named concept that email programmes need to operationalise: This article shows that email security cannot be managed as a mailbox problem alone because the decisive failure point is the user action the message is designed to provoke. Organisations that still separate awareness, detection and access governance leave an exploitable gap between seeing a message and authorising an outcome. Practitioners should align the email stack to the decision the user is being asked to make.

What this signals

Email security is becoming an identity governance problem: The practical risk is not only malicious content but the human action that content is designed to trigger. When phishing and BEC are the entry points, security teams need controls that validate the request path, not just the message.

Security programmes that separate awareness from enforcement leave a gap between user recognition and system protection. The stronger model is to connect training, detection and verification so that human decision points are backed by policy and telemetry.


For practitioners

  • Map high-risk user decisions Identify the email actions that create the most downstream risk, such as payment approvals, credential resets, vendor banking changes and mailbox delegation. Build controls and playbooks around those decisions rather than only around message blocking.
  • Link training to live detections Use targeted awareness exercises that mirror the actual phishing and BEC patterns your telemetry sees, then feed user-reported events and suspicious-message telemetry into response workflows.
  • Add verification to sensitive workflows Require out-of-band checks for requests that change money movement, credentials or delegated access, especially when the request arrives by email and claims urgency.
  • Monitor for behavioural anomalies Tune alerting for unusual sender patterns, reply-chain manipulation, new external forwarding rules and sudden changes in user interaction behaviour around high-risk requests.

Key takeaways

  • Email threats are increasingly successful because they target user behaviour as much as inbox controls.
  • Phishing, BEC and AI-powered deception create a blended risk where training and technology have to operate together.
  • Security teams should focus on the actions that email can trigger, especially payments, credential changes and delegated access.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKTA0001;TA0006;TA0040 — Initial Access; Credential Access; ImpactPhishing and BEC are attack paths that start with message delivery and end in abuse or loss.
Recommendation — Map phishing and BEC workflows to TA0001, TA0006 and TA0040 to prioritise detection and response coverage.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsEmail-driven approvals and credential abuse often succeed when authorisation controls are too weak.
Recommendation — Apply PR.AA-05 to verify that sensitive email-triggered actions require explicit, controlled authorisation.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementPhishing frequently targets credentials and authenticator handling, making lifecycle control relevant.
Recommendation — Use IA-5 to govern credential use, reset and recovery paths exposed through email attacks.
NIST SP 800-63SP 800-63B — AuthenticationEmail-based deception often leads to authentication abuse or session compromise.
Recommendation — Strengthen SP 800-63B-aligned authentication so users cannot satisfy high-risk requests with weak verification alone.

Key terms

  • Phishing: Phishing is a deceptive message or website designed to trick a person into revealing credentials or other sensitive information. In identity terms, it is an unauthorised collection method that turns human trust into downstream account access and potential privilege abuse.
  • Business email compromise: A form of social engineering where an attacker impersonates a trusted person or domain to manipulate payment, change banking details, or extract sensitive information. It often succeeds without malware because the attacker targets process trust and human judgement instead of technical controls.
  • Behaviour-based email security: A security approach that judges email risk by how messages and accounts behave over time, not only by content or sender reputation. It looks for unusual reply patterns, impersonation signals, and identity-linked anomalies that traditional perimeter filters often miss.
  • Out-Of-Band Verification: A confirmation step that uses a different channel or method than the original request. It reduces the chance that a single spoofed email, voice call, or video session can authorize privileged activity or financial transfer.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org