TL;DR: Nearly 77% of all email attacks contain a phishing link, according to Abnormal AI, underscoring why phishing remains the primary delivery path for account compromise and downstream fraud. The real control gap is not awareness alone but whether email, identity, and response workflows can stop bait before users act.
At a glance
What this is: This webinar looks at why phishing links still dominate email attacks and argues that traditional email defences miss the full path from bait to compromise.
Why it matters: It matters because email security, human behaviour, and identity response now need to be treated as one control plane rather than separate programmes.
By the numbers:
- Nearly 77% of all email attacks contain a phishing link.
Context
Phishing remains an email delivery problem, but it becomes an identity problem the moment a user clicks, enters credentials, or authorises access. Traditional email controls can reduce exposure, yet they do not fully address the social engineering path that turns a message into account compromise.
This webinar frames phishing as an evolving attacker method rather than a static email nuisance. For IAM and security teams, the practical question is whether detection, user training, and incident response are linked tightly enough to interrupt the attack before it becomes a credential or session compromise.
Key questions
Q: How should security teams reduce the risk of phishing links in email attacks?
A: Combine email filtering with identity controls that limit damage after a click. The most effective approach includes strong MFA, conditional access, fast message reporting, suspicious login detection, and automated token revocation. If a phishing link gets through, the programme should still prevent easy reuse of the compromised identity.
Q: Why do traditional email security tools still miss modern phishing campaigns?
A: Traditional email security relies heavily on reputation checks, URL scanning, and automated detonation, but attackers now design phishing infrastructure to frustrate those methods. Turnstiles block scanners, redirect chains obscure the final destination, and trusted platforms make malicious links look legitimate. The gap is not awareness alone, it is that the attack path now extends beyond inbox-based controls.
Q: What are the signs that phishing awareness training is not working well enough?
A: Training is failing when employees still click, reply, or escalate suspicious messages without checking basic details first. Other warning signs include repeated responses to urgent language, weak reporting rates, and inconsistent use of verification steps for unexpected links or attachments. If people can describe threats but do not change behavior, the program is informative but not operationally effective.
Q: What should security teams do when a phishing link has already been clicked?
A: Act immediately. Disconnect the device from the internet if possible, avoid entering any further information, and change affected passwords from a separate trusted device. Run a malware scan and report the incident to the IT or security team so they can monitor for compromise, contain any spread, and review whether other accounts were exposed.
Background and context
Why phishing links still bypass email security controls
Phishing links succeed because detection tools often inspect known indicators, while attackers adapt lures, sender infrastructure, and landing pages faster than static rules can keep up. Email gateways can block obvious malicious content, but they are weaker when the message is context-aware, impersonates trusted workflows, or routes users through benign-looking redirects. The weak point is not only the inbox filter. It is the combination of message delivery, user trust, and post-click containment that determines whether the attack reaches identity compromise.
Practical implication: pair email filtering with user risk controls and rapid containment so a clicked link does not become a credential event.
Security awareness training as an identity control
Security awareness training matters because phishing is designed to trigger human action, not just technical execution. Training is most effective when it is tied to realistic simulations, timely feedback, and clear reporting paths that let users escalate suspicious messages quickly. On its own, training is not a substitute for technical controls, but it is a front-line identity defence because the user is often the first decision point in the attack chain. The control fails when organisations treat it as annual compliance theatre instead of behavioural risk reduction.
Practical implication: measure reporting speed, click rates, and escalation quality rather than treating training completion as proof of resilience.
Why email, identity, and response must work together
Phishing becomes materially more dangerous when email security, IAM, and incident response operate in silos. If a malicious link reaches a user, the next control should not be another static filter alone. It should be identity-aware detection, rapid token revocation where needed, and response playbooks that assume the message may already have created session or credential risk. That integrated model matters because the attack often ends in account takeover, not at the email gateway.
Practical implication: connect email telemetry to identity and response workflows so suspicious clicks can trigger containment across the account lifecycle.
NHI Mgmt Group analysis
Phishing is now an identity control failure as much as an email problem. Email filtering can reduce exposure, but the decisive failure occurs when a message is able to induce authentication, authorisation, or trust transfer from the user. That shifts phishing out of the narrow inbox category and into IAM governance, where identity assurance and response speed become part of the same control surface.
Security awareness training is only useful when it changes reporting behaviour. The point is not completion metrics but whether staff recognise suspicious messages early enough to interrupt the attack chain. In practice, that means training must feed into detection and response workflows, or it remains a compliance artefact rather than a security control.
Phishing creates a control-plane gap between message delivery and identity compromise. Organisations often separate email protection from account protection, yet attackers exploit the handoff between the two. The result is a widened exposure window where a malicious link can survive long enough to become credential theft or session abuse, so practitioners need integrated governance across email, identity, and response.
Cross-domain linkage is now the differentiator in phishing defence. Email security, IAM, and SOC response each see only part of the attack unless they share signals and automate containment. That is why phishing resilience is increasingly measured by how quickly the organisation can translate inbox suspicion into identity protection and user-level response.
Phishing remains the primary delivery path because it targets trust, not just infrastructure. Attackers do not need to defeat every control when they can persuade one user to supply the missing piece. For practitioners, that means the most important question is whether the organisation can reduce trust at the point of click and recover it before identity is misused.
From our research library:
- Roughly 1 in 3 phishing payloads are delivered outside email, through channels such as social media, search ads and messaging apps.
What this signals
Phishing defence now depends on how quickly organisations can move from inbox detection to identity containment. The message is simple: if a suspicious click does not trigger an identity-aware workflow, the attack still has time to succeed. That makes reporting, session control, and account review part of the same operational chain, not separate functions.
Training only pays off when it produces security telemetry. A workforce that can spot and report lure patterns gives the SOC an earlier signal than email filtering alone. The programme value comes from shortened response time and better containment decisions, not from awareness metrics in isolation.
For practitioners
- Tighten link inspection and URL rewriting Inspect destination reputation, redirect chains, and impersonation cues before the user reaches a login page or credential prompt.
- Connect email alerts to identity response Trigger account review, token revocation, or session invalidation when a phishing message is reported or a suspicious click is detected.
- Make reporting the fastest path Give users a single, low-friction way to report suspicious email and ensure the SOC can triage those reports in real time.
- Test training against realistic lure patterns Use simulations that reflect current phishing tactics, including trusted-brand impersonation and link-based credential capture, then track click and report behaviour.
Key takeaways
- Phishing remains a delivery mechanism that turns email into an identity problem once a user engages with a malicious link.
- The control weakness is usually the gap between message delivery, user action, and containment, not awareness alone.
- Effective defence links email security, reporting, and IAM response so a click can be contained before it becomes account compromise.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | TA0001; TA0006 — Initial Access; Credential Access | Phishing links deliver the initial entry and often lead to credential theft. |
| Recommendation — Map phishing telemetry to Initial Access and Credential Access to prioritise containment paths. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article centers on preventing malicious user-driven identity compromise. |
| Recommendation — Link email reporting to access-permission review so suspicious clicks can trigger containment. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Phishing aims to capture authenticators, tokens, and login credentials. |
| Recommendation — Apply authenticator management controls to limit reuse and force revocation after suspected theft. | ||
| CIS Controls v8 | CIS-5 — Account Management | Phishing becomes damaging when stolen access is still valid across accounts. |
| Recommendation — Use account management controls to detect and revoke compromised access after a phishing event. | ||
Key terms
- Phishing Link: A phishing link is a malicious or deceptive URL designed to induce a user to reveal credentials, approve access, or run an unsafe action. In practice, the link is only the delivery mechanism. The real risk is the identity compromise that follows when the user interacts with the destination.
- Identity-aware response: An incident response model that uses live identity context to shape containment decisions. It treats risk, policy state, and account behaviour as operational inputs, so analysts can act on the identity layer without leaving the response workflow.
- Security Awareness Training: Security Awareness Training is the practice of teaching people how to recognize and respond to security risks in daily work. It covers phishing, password hygiene, data handling, social engineering, device safety, and reporting procedures. Effective training changes behavior, supports policy compliance, and reduces human error as an attack path.
- Session revocation: The ability to invalidate active sessions so access ends immediately instead of waiting for tokens or browser state to expire. For identity governance, this is the control that determines whether authentication still matters after a compromise is detected.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org