By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: Knowbe4Published June 2, 2026

TL;DR: Public sector organisations face phishing, business email compromise, credential theft and MFA fatigue as the human layer becomes the primary attack surface, according to Knowbe4. Fragmented tools and staffing shortages make resilience depend on unified human risk management, not isolated controls.


At a glance

What this is: This whitepaper argues that public sector security is being undermined by human-focused attacks and fragmented tooling, with human risk management positioned as the central response.

Why it matters: It matters because IAM, PAM and security teams in government and education must connect human identity, access governance and detection workflows if they want to reduce breach exposure without adding operational sprawl.

👉 Read Knowbe4's whitepaper on public sector human risk management and cyber resilience


Context

Public sector security programmes are being stretched by a familiar combination of threats and constraints: phishing, business email compromise, credential theft, MFA fatigue, tool sprawl and limited staffing. The core governance problem is not just more attacks, but the mismatch between human-focused threat patterns and fragmented control environments. In practice, that means identity assurance, access review and response coordination all need to work together rather than as separate silos.

The whitepaper frames the human layer as the primary attack surface, which is directionally right for agencies, schools and service providers that depend on email and cloud collaboration. That makes this more than a security awareness issue. It is an IAM and identity governance problem as well, because the attack paths described here often terminate in credential abuse, session takeover or misuse of trusted accounts.


Key questions

Q: How should public sector teams reduce human-risk exposure without adding more tools?

A: Start by connecting email security, IAM and behavioural telemetry into one response workflow. That lets teams see phishing, MFA fatigue and credential abuse as one attack chain instead of separate events. Prioritise high-risk users and privileged accounts, then automate containment actions such as step-up checks, access restrictions and ticketing so small teams can respond consistently.

Q: Why do phishing and MFA fatigue still lead to major breaches?

A: Phishing and MFA fatigue work because they exploit trust in the authentication flow, not because the attacker has stronger technology. When users can approve repeated prompts or open malicious content that leads to a valid session, the identity boundary is bypassed through behaviour rather than code. Security teams need to control the approval path, not just the password field.

Q: What breaks when human-risk signals stay split across separate security tools?

A: Investigations slow down because each tool sees only part of the story. Email security may flag the lure, IAM may flag the login, and compliance may log the outcome, but no single team can easily prove abuse end to end. That fragmentation weakens containment, raises analyst workload and makes accountability harder to defend.

Q: Who is accountable when a compromised identity system disrupts public services?

A: Accountability sits with the teams that own identity governance, incident response, and continuity planning together, because identity compromise crosses all three domains. Public sector frameworks such as Zero Trust and the NIST Cybersecurity Framework expect recovery and resilience to be part of the control design, not an afterthought.


Technical breakdown

Why phishing and MFA fatigue keep working

Phishing remains effective because it targets trust decisions, not just technical weaknesses. Business email compromise and MFA fatigue exploit the fact that users are trained to approve, click or respond under pressure, especially when messages mimic real workflows. In identity terms, these attacks abuse authentication prompts, helpdesk processes and delegated trust rather than breaking cryptography. The issue is compounded when identity assurance is weak and conditional access signals are not tied tightly enough to behavioural risk.

Practical implication: connect phishing defence to identity controls such as step-up authentication, token protection and risky sign-in response.

How tool sprawl creates human-risk visibility gaps

Fragmented security tools create blind spots because each system sees only part of the human risk picture. Email security may detect the lure, IAM may see the login, and compliance tooling may see the audit trail, but none of them alone can tell you whether the account was abused end to end. Unified human risk management tries to correlate those signals so security teams can prioritise high-risk users, accounts and behaviours. Without that correlation, response becomes slower and investigations become harder to defend.

Practical implication: consolidate identity, email and behavioural telemetry into a workflow that can score and act on human risk across the attack chain.

What staffing shortages mean for resilience operations

Short staffing changes the control model because teams cannot rely on manual review, ticket-heavy escalation or bespoke investigations at scale. In public sector environments, the volume of low-friction social engineering attempts means analysts need repeatable prioritisation, not just more alerts. HRM aims to reduce noise by focusing on the accounts and behaviours most likely to lead to compromise. That makes automation and policy consistency part of resilience, not just efficiency.

Practical implication: automate triage, containment and reporting for the account types most likely to be targeted, especially privileged and high-access users.


Threat narrative

Attacker objective: The attacker wants to exploit trusted human identities to gain access that looks legitimate long enough to steal data, move laterally or disrupt public services.

  1. Entry typically begins with phishing, business email compromise or MFA fatigue that persuades a user to reveal credentials or approve a malicious prompt.
  2. Credential access then gives the attacker a trusted session or account path that bypasses stronger perimeter controls and enables use of legitimate identity surfaces.
  3. Impact follows when the abused account is used to access citizen data, student records, financial workflows or internal service systems under a trusted identity.

NHI Mgmt Group analysis

Human risk management is becoming an identity governance problem, not just a security awareness problem. The article is right to centre the human layer, but the governance implication is broader than phishing training. When attackers rely on credential theft, MFA fatigue and business email compromise, the control challenge moves into authentication assurance, privileged access review and user behaviour telemetry. Practitioners should treat human risk as a measurable identity programme issue, not a soft-awareness initiative.

Tool sprawl is now a resilience defect because it breaks the attack narrative into disconnected signals. Public sector environments often have separate email, IAM and compliance workflows, which makes it harder to prove what happened quickly enough to contain it. This is where NIST CSF 2.0 and NIST 800-53 style control mapping matter: visibility, response and access control have to be coordinated. Practitioners should prioritise cross-domain correlation over another point tool.

High-friction human attacks expose the verification trust gap. MFA fatigue, impersonation and compromised inboxes work because many organisations still assume that an authenticated user is a safe user. That assumption collapses when the attacker is operating through legitimate prompts, familiar channels and trusted identities. The practical conclusion is that identity assurance must be continuous, contextual and tied to risk signals, not treated as a one-time login event.

Public sector cyber resilience will increasingly be judged by how well organisations suppress account abuse at scale. The combination of staffing shortages and rising attack volume means agencies cannot win through manual intervention alone. The better programmes will align behavioural risk scoring, conditional access, privileged account controls and incident response into a single operating model. Practitioners should view human risk reduction as a resilience architecture decision.

What this signals

Public sector programmes should expect human-focused attacks to keep outpacing isolated controls, which means the next improvement cycle is about correlation, not more point solutions. A practical operating model is to treat identity, email and behavioural data as one risk fabric, then use it to drive conditional access, privileged access review and response workflows.

Verification trust gap: when organisations assume authenticated users are safe users, MFA fatigue and credential theft become more effective. That assumption is increasingly incompatible with modern attack patterns, so teams need continuous identity assurance and higher confidence signals before granting or sustaining access.


For practitioners

  • Map human-risk telemetry to identity controls Correlate phishing, MFA fatigue, sign-in anomalies and helpdesk abuse with IAM and PAM events so high-risk accounts can be stepped up or restricted before misuse expands. Build the workflow around trusted identity signals, not isolated alert queues.
  • Unify email, identity and compliance operations Create one response path that joins email security, identity monitoring and audit reporting, especially for agencies handling citizen data or student records. The goal is faster containment and cleaner evidence, not more dashboards.
  • Prioritise privileged and high-access users Focus behavioural controls, training and step-up checks on accounts whose compromise would expose the widest operational blast radius, including administrators, finance users and service desk personnel.
  • Reduce manual dependence in triage Automate detection, prioritisation and escalation for recurring human-targeted attacks so lean teams can respond consistently even when staffing is constrained.

Key takeaways

  • The article's central point is that human-focused attacks now define public sector cyber risk, especially where phishing and credential abuse meet weak identity governance.
  • Fragmented tools and short staffing do not just slow response, they create the visibility gaps attackers need to blend trusted identity misuse into normal operations.
  • Public sector resilience improves when identity, email and behavioural signals are managed as one control system rather than separate security problems.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-1The paper centres on human identity, authentication and access risk in public sector environments.
NIST SP 800-53 Rev 5IA-2Strong authentication is directly relevant to the credential theft and MFA fatigue threats discussed.
CIS Controls v8CIS-6 , Access Control ManagementAccess control management is central to limiting account abuse after human-targeted compromise.
MITRE ATT&CKTA0006 , Credential Access; TA0001 , Initial AccessThe article focuses on phishing, credential theft and MFA fatigue as entry and abuse techniques.

Review privileged and high-access accounts first, then narrow access before attackers can reuse it.


Key terms

  • Human Risk Management: The practice of managing how people interact with security controls, especially under pressure, distraction, or deception. It combines training, policy, and friction management so identity systems are still usable enough that users do not bypass them in day-to-day work.
  • MFA Fatigue: MFA fatigue is the behavioural pressure created when repeated login prompts make a person more likely to approve access without checking carefully. It is a control failure in the authentication experience, and it becomes dangerous when the approved session carries broad privilege or long-lived access.
  • Business email compromise: A form of social engineering where an attacker impersonates a trusted person or domain to manipulate payment, change banking details, or extract sensitive information. It often succeeds without malware because the attacker targets process trust and human judgement instead of technical controls.
  • Activation Trust Gap: The activation trust gap is the difference between trusting data because it is protected and governing it because it is being reused. It appears when organisations move data from backup or archival systems into AI pipelines without reapplying access, sensitivity, and consumer controls.

What's in the full article

Knowbe4's full whitepaper covers the operational detail this post intentionally leaves for the source:

  • Practical guidance on operationalising Human Risk Management across agencies and schools
  • More detail on strengthening Microsoft 365 while reducing human-driven risk
  • The paper's own framing of why fragmented security tools slow response and create visibility gaps
  • The specific security and compliance outcomes the vendor associates with a unified human-centric approach

👉 Knowbe4's full whitepaper expands on the human-risk model, public sector use cases and the operational benefits of unifying security and compliance.

Deepen your knowledge

NHI Mgmt Group covers identity security, NHI governance, and agentic AI through independent research, practitioner guides, and the NHI Foundation Level course. Explore nhimg.org for resources that connect identity governance to the broader security disciplines your programme depends on.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org