By NHI Mgmt Group Editorial TeamBased on Abnormal AI: “Hackers vs. Defenders: The Evolving Threat Landscape and What’s Next in 2025” (June 26, 2026)

TL;DR: Attackers are evolving tactics faster than many traditional defenses can absorb, while social engineering remains a dominant entry method and defender lesson source, according to Abnormal AI’s Innovate 2025 webinar with Sherrod DeGrippo. The practical takeaway is that security programmes must treat human decision paths, not just technical controls, as part of the attack surface.


At a glance

What this is: This on-demand webinar from Abnormal AI explores how attackers adapt faster than traditional defenses and why social engineering remains a core attack method.

Why it matters: It matters because IAM and security teams must account for human decision-making, not just technical control points, when building resilience against modern attack paths.


Context

Traditional defensive programmes often assume attacker behaviour changes slowly enough for controls, training, and detection logic to catch up. This webinar argues the opposite: adversaries iterate their tactics quickly, and social engineering remains effective because it targets the human decision layer rather than only technical weaknesses.

For IAM, PAM, and security awareness teams, the practical issue is not whether phishing or impersonation still works in theory. It is how quickly those tactics adapt to bypass established controls, which is why human judgement, escalation paths, and verification steps have to be part of the governance model.


Key questions

Q: How should security teams reduce social engineering risk in identity recovery workflows?

A: They should treat recovery as a privileged control path, not a customer service process. That means verifying the person through independent proof, restricting who can approve resets, logging every step, and separating account recovery from routine support. Where possible, use phishing-resistant authentication so an attacker cannot simply move the second factor onto a new device.

Q: Why do social engineering attacks still defeat mature IAM programmes?

A: Because many programmes secure the login event but leave recovery, escalation, and exception handling under-governed. Attackers target the human trust layer, where staff are expected to restore access quickly and may rely on incomplete evidence. When those workflows are weak, the programme can look mature on paper and still fail in practice.

Q: What are the signs that social engineering controls are failing?

A: Common failure signals include repeated clicks on suspicious links, staff bypassing verification steps, unexpected credential sharing, and approval of urgent requests through unapproved channels. If phishing simulations show persistent weakness or behavior analytics repeatedly flag unusual logins and transactions, the control environment is not absorbing pressure. Those patterns indicate awareness and response procedures need tightening.

Q: How can organisations verify identity when the request itself may be malicious?

A: Use out-of-band confirmation, stronger authentication for sensitive actions, and tightly scoped approval authority for resets or privilege changes. The goal is to make the request harder to trust than the channel it arrived through.


Background and context

Why social engineering still bypasses layered controls

Social engineering works because it does not need to defeat every technical control in sequence. It only needs one persuasive message, one convincing pretext, or one rushed decision to create an entry point. Once trust is manipulated, even mature controls can be sidestepped through help desk requests, credential capture, or fraudulent approvals. The technical weakness is often not encryption, authentication, or logging. It is the assumption that users and operators will reliably recognise deception in time.

Practical implication: build verification steps into high-risk requests instead of relying on user judgement alone.

How attacker adaptability changes defender detection

Attackers do not need a new technique every time they innovate. They often recombine familiar lures, delivery channels, and timing to evade pattern-based detection and awareness training. That means defenders who only tune for known phishing templates or static playbooks will lag behind the next variation. The challenge is less about a single control failure than about control drift, where attacker behaviour changes faster than policies, simulations, and alerting rules are updated.

Practical implication: refresh detection logic and awareness scenarios based on observed attacker adaptation, not annual review cycles.


NHI Mgmt Group analysis

Social engineering is no longer a perimeter problem, it is an identity governance problem. Once attackers can shape human decisions, the effective attack surface includes approval paths, recovery processes, and exception handling. That shifts the control question from simple awareness to governance over who can authorise what, when, and under which verification conditions.

Hacker mindset analysis is most useful when it exposes the decision points defenders treat as safe. The value is not in celebrating attacker creativity, but in identifying where normal workflows create predictable openings. Help desks, delegated approvals, and urgent escalation paths often become the real control boundary, and that boundary is where defenders need tighter policy design.

Social engineering succeeds when organisations trust process more than proof. Attackers exploit environments where requests are considered legitimate because they look familiar, arrive through expected channels, or arrive during business pressure. The lesson for practitioners is that governance must require stronger proof at the points where business convenience and adversary persuasion intersect.

Named concept: decision-path exposure. This article reinforces a pattern where attackers target the human and procedural path to access, not just the authentication event itself. Decision-path exposure is what happens when identity governance focuses on login success but underestimates the risk embedded in approvals, resets, and exception handling.

What this signals

Decision-path exposure: Security teams should treat approvals, resets, and escalation channels as governed access paths because adversaries increasingly target the human route to privilege. That means policy design, not only alerting, becomes the control surface that matters most.

Awareness programmes remain useful only when they reflect current attacker behaviour. When social engineering evolves faster than training content, the organisation ends up rehearsing old lures while attackers exploit the newest ones.


For practitioners

  • Harden high-risk human workflows Require step-up verification for password resets, privileged approvals, and account recovery so that a persuasive request cannot bypass identity checks.
  • Review delegated decision points Map which teams can approve exceptions, override controls, or validate identity claims, then reduce ambiguity in those escalation paths.
  • Rework awareness around attacker tactics Use current social engineering scenarios in simulations and briefings so training reflects how attackers actually change pretexts and delivery methods.

Key takeaways

  • Social engineering remains effective because it targets trust, urgency, and routine decision-making rather than only system weaknesses.
  • The article's core message is that attacker adaptation can outrun traditional defence cycles, especially when controls are tuned to static threat patterns.
  • Teams need stronger governance over recovery, approval, and exception workflows so human decision points are harder to abuse.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsHuman decision paths in approvals and recovery create entitlement risk in this article.
Recommendation — Tighten approval and recovery permissions so social engineering cannot redirect access decisions.
NIST SP 800-63SP 800-63B — AuthenticationThe webinar centres on identity decisions being manipulated through human workflows and verification gaps.
Recommendation — Strengthen authentication steps around sensitive actions to reduce trust in request content alone.
CIS Controls v8CIS-5 — Account ManagementSocial engineering often targets account recovery and access changes, both core account management issues.
Recommendation — Review account recovery and exception handling so social engineering cannot drive unauthorised access changes.
MITRE ATT&CKTA0001;TA0006 — Initial Access; Credential AccessThe article discusses adversaries using social engineering to gain entry and capture credentials.
Recommendation — Map social engineering scenarios to initial access and credential access techniques to improve detection coverage.

Key terms

  • Social Engineering: Social engineering is the use of deception, urgency, and authority to persuade a person to reveal information or take a risky action. It targets human decision-making rather than software defects, and often turns legitimate identity workflows into the attack path.
  • Decision-Path Exposure: The risk created when an attacker can influence the human or procedural path to access, not just the authentication event itself. This matters when approvals, escalation routes, and exception handling are easier to manipulate than the systems they protect.
  • Account Recovery: Account recovery is the process used to restore access when a user cannot authenticate normally. In mature IAM programmes, recovery is treated as part of the trust chain because a weak reset path can bypass stronger login controls and become the easiest route to account takeover.
  • Identity Governance: Identity governance is the set of controls that defines who approves access, who owns it, how it is reviewed, and when it is removed. In practice, it turns identity management from a deployment task into a durable control system that can withstand audits, organisational change, and operational growth.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org