Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

AI-driven social engineering: are IT admin controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18004
Topic starter  

TL;DR: AI-generated phishing, vishing, deepfakes, and impersonation are making social engineering more convincing and scalable, and Living Security Human Risk Management Platform argues that annual awareness training is no longer enough for privileged IT administrators. The practical shift is from measuring clicks to measuring reporting speed, role-based exposure, and correlated human risk signals.

NHIMG editorial — based on content published by Living Security Human Risk Management Platform: Effective Social Engineer... A Guide to Social Engineering Training for IT Admins

By the numbers:

Questions worth separating out

Q: How should security teams stop AI-powered social engineering from leading to privileged access?

A: Security teams should harden the approval path, not just the inbox.

Q: Why do privileged accounts make social engineering more dangerous?

A: Because they turn one successful deception into broad operational reach.

Q: How do you know if social engineering training is actually working?

A: Look beyond click rates and measure whether people report suspicious activity quickly and consistently.

Practitioner guidance

  • Rebuild privileged verification paths Require out-of-band confirmation for password resets, access grants, payment changes, and infrastructure actions that affect privileged accounts.
  • Measure reporting speed instead of only click rates Track time-to-report for suspicious email, voice, and chat events, then use that metric to identify roles that need more intensive intervention.
  • Target training by privilege and exposure Prioritise admins, help-desk staff, and executives who can authorise access or change infrastructure.

What's in the full article

Living Security Human Risk Management Platform's full blog post covers the operational detail this post intentionally leaves for the source:

  • Role-by-role training examples for IT administrators, help-desk staff, and other high-risk users
  • Behavioural metrics and reporting workflows used to measure whether social engineering training is changing outcomes
  • Examples of AI-driven phishing, vishing, smishing, and pretexting scenarios the vendor uses in its programme
  • Human Risk Management framing that links behaviour, identity systems, and threat intelligence into one view

👉 Read Living Security Human Risk Management Platform's guide to social engineering training for IT admins →

AI-driven social engineering: are IT admin controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 17593
 

AI-generated social engineering is becoming an identity governance problem, not just an awareness problem. When attackers can mimic executives, colleagues, and support staff convincingly, the control gap is no longer whether users understand phishing in theory. The gap is whether privileged workflows have enough verification, approval separation, and monitoring to survive a believable human deception. Identity programmes need to treat the human decision layer as part of access governance, not as an external training issue.

A question worth separating out:

Q: Who should get the most intensive anti-social-engineering training?

A: Start with roles that combine high privilege, frequent external contact, and approval authority. That usually means IT administrators, help-desk teams, finance staff, and executives. These groups are both more targeted and more capable of causing damage if deceived, so they need tailored scenarios and more frequent refreshers.

👉 Read our full editorial: AI-driven social engineering is outpacing IT admin training



   
ReplyQuote
Share: