TL;DR: The SANS 2022 Managing Human Risk report puts people at the centre of the current attack frontier, with phishing, business email compromise, and ransomware all driven by credential theft or weak passwords, according to Axiad’s analysis. Passwordless, phishing-resistant MFA is now a baseline control, but it still needs to be paired with ongoing user training and coverage across people, machines, and interactions.
At a glance
What this is: This is an analysis of people-centric attacks that argues phishing-resistant authentication should extend beyond users to machines and email interactions.
Why it matters: IAM teams need to treat authentication as a people, machine and interaction problem because phishing, BEC and ransomware all exploit weak identity assurance somewhere in the chain.
Context
The core security gap is not just phishing, but the way password-based authentication keeps creating reusable trust that attackers can intercept, reuse, or socially engineer around. In this article, people-centric exposure is treated as the dominant identity problem, with the authentication model itself becoming part of the attack surface.
For IAM teams, the important shift is that phishing-resistant authentication is no longer a niche hardening measure. It is being framed as a baseline identity control for end users, administrators, devices, virtual workloads, email, and attached documents.
Key questions
Q: How should security teams implement phishing-resistant MFA in existing IAM environments?
A: Start with the most exposed and highest-value access paths, then phase in device-bound methods such as passkeys, FIDO2 keys, or smart cards. Keep the rollout tied to use case, user population, and assurance needs so you can replace replayable secrets without breaking operations or creating unmanaged exceptions.
Q: Why do email attacks remain effective even when organisations use MFA?
A: MFA protects the login step, but many email attacks exploit the trust placed in a compromised or impersonated mailbox after authentication. Once an attacker is inside, they can abuse forwarding, delegation, and social trust. Identity assurance has to extend beyond sign-in to message-driven business actions.
Q: What breaks when authentication is not phishing-resistant?
A: The trust boundary between the user and the system becomes easy to impersonate. Attackers can collect credentials through fake login pages or reuse stolen passwords to enter accounts, which then undermines downstream controls such as access reviews, monitoring, and conditional access.
Q: What is the difference between strong MFA and phishing-resistant MFA?
A: Strong MFA means more than one factor is used, while phishing-resistant MFA means the factor cannot be easily captured and replayed by an attacker. A code sent by text may count as MFA, but it is not resistant enough for high-risk accounts because the secret can be stolen outside the application itself. Resistance is the higher standard.
Technical breakdown
Why password-based authentication still fails under social engineering
Password-based authentication fails because the factor the user knows can be tricked out of them, copied from a reuse pattern, or intercepted through a fake login flow. Even second factors can be weakened if they rely on shared secrets or codes that travel through a vulnerable channel. Phishing-resistant authentication reduces that exposure by removing the reusable secret from the exchange and binding the credential to a stronger authenticator and a trusted device or key. The technical point is not that MFA is useless, but that some MFA designs still preserve the same interception path as passwords. Practical implication: treat phishable factors as an architectural weakness, not a user-behaviour problem alone.
Practical implication: prioritise authentication methods that do not expose reusable secrets to phishing or interception.
How phishing-resistant MFA differs across people, machines and email
The article distinguishes three authentication targets: people, machines, and interactions such as email and attachments. Those are not interchangeable. Human authentication needs strong authenticators and user presence, while machine and workload authentication depends on certificate-based trust and PKI at scale. Email and document authentication use the same cryptographic trust layer to verify origin and integrity rather than a human login flow. The important design lesson is that one control does not cover all three identity contexts. Practical implication: build separate authentication patterns for each identity class instead of forcing one factor combination everywhere.
Practical implication: map each identity class to the correct authenticator and trust model rather than standardising on one login pattern.
Why training still matters after strong authentication
Stronger authentication reduces the number of successful phishing paths, but it does not eliminate manipulation, urgency, or workflow abuse. The article notes that human risk management remains necessary because social engineering can still target decisions, approvals, and exception handling even when passwords are no longer the weakest link. That makes authentication a control boundary, not a complete defence. Practical implication: pair phishing-resistant authentication with recurring user awareness and role-specific guidance so that the remaining attack paths are still visible and challenged.
Practical implication: keep human-risk training in scope because strong authentication alone does not stop every social engineering path.
Threat narrative
Attacker objective: The attacker wants to steal credentials or authenticate through a weaker path so they can move into fraud, extortion, or broader account compromise.
- Entry begins with phishing, smishing, vishing or other social engineering that steers a user toward revealing a password or approving a malicious flow.
- Credential access follows when the attacker captures reusable credentials or a weaker second factor that can be intercepted or replayed.
- Impact occurs when the attacker uses that identity compromise to support BEC, ransomware initial access, or broader account abuse.
Breaches seen in the wild
- Co-op cyber attack 2025: Attackers linked to Scattered Spider tricked their way into a Co-op employee account and stole personal data of all 6.5 million members.
- EmeraldWhale Git config credential theft: Tokens in exposed .git/config files let EMERALDWHALE clone private repositories and steal more than 15,000 cloud credentials.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
People-centric attack exposure is now an identity governance problem, not just a security awareness problem. The article correctly frames phishing, BEC and ransomware as part of the same credential-driven attack economy. That means authentication design, not just user education, sits at the centre of risk reduction. For IAM teams, the issue is whether the authentication stack still assumes users can reliably distinguish legitimate from malicious requests.
Phishing-resistant authentication is a control boundary that changes the economics of human compromise. When passwords and phishable second factors disappear, attackers lose the easiest route into user and admin accounts. That does not end social engineering, but it removes the reusable secret as the default prize. For practitioners, this makes the remaining gap less about login friction and more about where high-trust actions are still exposed to human error.
People, machine, and interaction authentication should be governed as one programme with different control patterns. The article’s strongest point is that end users, workloads, and email all need authentication models that fit their trust profile. Certificate-based authentication and PKI belong in the same governance conversation as MFA because the identity surface now includes devices and documents, not only people. For IAM leaders, siloed ownership of these authentication modes leaves coverage gaps.
Human risk management remains necessary because better authentication does not eliminate behavioural exploitation. The article makes a realistic point: technology can reduce exposure, but it cannot fully suppress well-executed social engineering. That means the programme goal is not perfect prevention, but reducing the number of phishable paths and narrowing where human judgement can be manipulated. For security architects, the discipline is layered control rather than a single-control answer.
Certificate-backed and passwordless patterns are becoming the durable baseline for trustworthy access. Passwords continue to create an avoidable interception surface, while cryptographic authenticators shift the burden onto possession of a stronger factor. That matters not just for user sign-in but for workload and message trust as well. For identity programmes, the architectural direction is clear: reduce shared secrets wherever identity assurance must withstand phishing.
From our research library:
- Roughly 1 in 3 phishing payloads are delivered outside email, through channels such as social media, search ads and messaging apps.
What this signals
Phishing-resistant authentication is now a governance baseline, not an advanced option. IAM teams should expect the authentication programme to cover people, machines, and email trust together, because attackers do not respect those category boundaries. A fragmented approach leaves the weak factor in place and simply moves the attack path around the stack.
Identity programmes still need to account for the last mile of human decision-making. Even when reusable secrets are removed, social engineering can redirect approvals, payment changes, and exception handling. The practical response is to pair stronger authentication with controls that verify the legitimacy of high-risk requests before the user action completes.
For practitioners
- Implement phishing-resistant MFA for privileged users Start with administrators, help desk accounts and other high-impact users who are prime targets for phishing and BEC. Use strong authenticators that do not rely on codes delivered over easily intercepted channels.
- Extend authentication governance to workloads and devices Treat machine certificates and PKI as part of identity architecture, not a separate infrastructure task. Ensure physical devices and virtual workloads have their own lifecycle, issuance and revocation processes.
- Remove shared-secret dependencies from login flows Identify places where shared secrets, OTP codes or fallback methods still travel through channels that attackers can intercept. Replace them with phishing-resistant flows wherever business risk is highest.
- Keep monthly human-risk touchpoints in place Use short, regular training and role-specific reminders so users can spot social engineering attempts that bypass technical controls. Focus on high-risk workflows such as payment changes, approvals and inbox-based requests.
- Map email and document trust to cryptographic controls Apply certificate-based authentication or PKI to verify email origin and protect attached documents where message integrity matters. This reduces reliance on user judgement alone for trust decisions.
Key takeaways
- People-centric attacks remain effective because they exploit the weakest identity assurance point, which is often still password-based or phishable authentication.
- The article’s core recommendation is to use phishing-resistant, passwordless MFA across users, machines and email-related interactions, not just for login screens.
- Strong authentication narrows the attack surface, but IAM programmes still need human-risk training and lifecycle coverage to close the remaining social engineering paths.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5, NIST CSF 2.0 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | The article centres on phishable authentication paths and stronger login assurance for non-human and human access. |
| NHI-10 — Human Use of NHI | The article links people-facing authentication with machine and email trust, where human handling still creates exposure. | |
| Recommendation — Replace phishable login flows with cryptographic or device-bound authentication methods that attackers cannot replay. Separate human interaction points from machine trust flows so users never mediate machine authentication manually. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Credential and authenticator lifecycle management underpins the move away from reusable secrets and weak second factors. |
| Recommendation — Manage authenticators so passwords, OTPs and fallback secrets are removed where higher-assurance methods are available. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is fundamentally about strengthening how identities are authenticated before access is granted. |
| Recommendation — Align authentication strength with access sensitivity and enforce stronger assurance for privileged actions. | ||
| NIST SP 800-63 | SP 800-63B — Authentication | The article discusses phishing-resistant and passwordless authentication patterns directly tied to digital identity assurance. |
| Recommendation — Apply NIST authentication guidance to prefer phishing-resistant methods for accounts exposed to social engineering. | ||
Key terms
- Phishing-Resistant Authentication: Phishing-resistant authentication proves identity without relying on a user to approve a prompt or reveal a reusable secret. It typically binds access to a device, key, or cryptographic proof that an attacker cannot easily reuse or coerce. This approach reduces reliance on human judgment at login time.
- Passwordless Authentication: An authentication approach that removes passwords and uses a device-bound cryptographic key plus local user verification. It reduces phishing and replay risk, but it only improves assurance when enrollment, recovery, and revocation are tightly governed.
- Business email compromise: A form of social engineering where an attacker impersonates a trusted person or domain to manipulate payment, change banking details, or extract sensitive information. It often succeeds without malware because the attacker targets process trust and human judgement instead of technical controls.
- Human Risk Management: The practice of managing how people interact with security controls, especially under pressure, distraction, or deception. It combines training, policy, and friction management so identity systems are still usable enough that users do not bypass them in day-to-day work.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org