Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

AI-powered phishing and human risk: what should teams change now?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: AI-enabled phishing is rising sharply, including a 41% increase in teams-based attacks, a 449% surge in vishing, and a 92% jump in polymorphic attacks, according to KnowBe4 research. Human risk management, not awareness alone, is now the control gap that matters most.

NHIMG editorial — based on content published by KnowBe4: Why Email Security Is Failing and How to Close the Gap in the Age of AI-Powered Phishing

By the numbers:

Questions worth separating out

Q: How should security teams reduce phishing risk when AI makes scam messages more convincing?

A: Teams should stop relying on obvious spelling mistakes and train people to verify the sender, destination, and request through a separate channel.

Q: Why do human-risk programmes matter if email security tools already block threats?

A: Email security tools reduce volume, but they do not eliminate deception, platform abuse, or user decision failures.

Q: Why do collaboration platforms complicate phishing defence?

A: Collaboration platforms blend internal staff, vendors, and guests into one trusted-looking interface, which makes malicious requests look routine.

Practitioner guidance

  • Measure human-risk outcomes, not just training completion Track click-through, credential submission, reporting latency, and repeat susceptibility by team and workflow.
  • Extend phishing detection into collaboration tools Monitor chat, shared workspaces, and file-sharing channels with the same seriousness as email.
  • Add verification steps for high-risk approvals Require step-up validation for payment changes, password resets, and delegated access requests.

What's in the full report

KnowBe4's full whitepaper covers the operational detail this post intentionally leaves for the source:

  • Benchmark data on human-risk programme maturity, including how organisations measure behaviour change across the workforce
  • Practical guidance for reducing phishing susceptibility through coaching, simulations, and response workflows
  • Implementation detail for integrating human risk metrics with email security and incident response
  • Specific tactics for improving reporting, triage, and verification across collaboration tools

👉 Read KnowBe4's whitepaper on why email security is failing in the age of AI-powered phishing →

AI-powered phishing and human risk: what should teams change now?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

AI-powered phishing has become an identity governance problem, not only an email security problem. Once attackers can reliably imitate language, urgency, and business context, the control question shifts from message blocking to trust verification. That means IAM, verification, and email workflows have to be aligned so user actions are treated as access decisions with consequences. Practitioners should expect phishing defence to sit closer to identity governance than to perimeter filtering.

A question worth separating out:

Q: Who is accountable when stolen credentials from a phishing email are used for fraud?

A: Accountability sits with the organisation that controls the affected identity, the approval workflow, and the downstream business process. Security, IAM, and finance teams all share responsibility because the damage often occurs after authentication succeeds. Frameworks that govern access, verification, and workflow approval all become relevant once the stolen identity is used.

👉 Read our full editorial: AI phishing and human risk are colliding with email security



   
ReplyQuote
Share: