Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Phishing attacks and human risk: are your controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18936
Topic starter  

TL;DR: Phishing succeeds by combining social engineering, urgency, and impersonation with delivery channels that bypass technical filters, according to Living Security Human Risk Management Platform. The real governance gap is visibility: organisations need risk signals tied to behaviour, identity, and access, not just awareness training and inbox controls.

NHIMG editorial — based on content published by Living Security Human Risk Management Platform: How Phishing Attacks Commonly Breach Defenses

By the numbers:

  • Phishing is a leading cause of data breaches, which now cost companies an average of $4.88 million per incident.
  • A new cyberattack occurs every 39 seconds, overwhelming manual response and creating blind spots in human risk programmes.

Questions worth separating out

Q: How should security teams reduce phishing risk without relying only on awareness training?

A: They should combine user training with behavioural detection, vendor verification, and tighter controls on high-risk identity actions.

Q: Why do phishing attacks still lead to major breaches when email filters are in place?

A: Email filters reduce exposure, but they do not stop a convincing lure that reaches a human and captures credentials or MFA approvals.

Q: What do teams get wrong about measuring phishing awareness?

A: They often measure completion rates or click rates and assume that means risk has improved.

Practitioner guidance

  • Implement behaviour-linked phishing risk scoring Correlate click behaviour, reporting behaviour, identity attributes, and access level so the highest-risk users receive the most relevant interventions.
  • Replace annual awareness with continuous simulations Run recurring phishing simulations that vary by role, channel, and lure type, then use the results to adjust training and follow-up interventions.
  • Connect phishing signals to IAM workflows Feed risky user behaviour into access review, step-up verification, and privileged session controls so identity risk changes action, not just reporting.

What's in the full article

Living Security Human Risk Management Platform's full blog post covers the operational detail this post intentionally leaves for the source:

  • Role-specific phishing simulation patterns and how they map to different employee populations
  • The signal model behind predictive human risk scoring across behaviour, identity, and threat data
  • Examples of targeted preventative actions that reduce risk after a high-risk user is identified
  • How the human risk approach is positioned for organisations trying to measure behaviour change over time

👉 Read Living Security Human Risk Management Platform's analysis of how phishing attacks commonly breach defenses →

Phishing attacks and human risk: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 18527
 

Human risk is now an identity governance problem, not just an awareness problem. The article correctly shifts the focus from message filtering to the conditions that make a user vulnerable. Once phishing success is treated as a function of identity signals, access level, and behavioural context, it becomes part of IAM governance rather than a standalone training metric. That is the right frame for security teams that need to reduce real compromise, not just click rates.

A question worth separating out:

Q: Who is accountable when phishing leads to account compromise?

A: Accountability is shared, but security leadership owns the control environment that made impersonation succeed. Email authentication, browser trust configuration, access scoping, and incident reporting are governance responsibilities, not just end-user habits. If phishing can repeatedly turn into compromise, the control model is failing at the organisational level.

👉 Read our full editorial: Phishing defenses fail when human risk stays invisible



   
ReplyQuote
Share: