Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Phishing defence gaps: what IAM and security teams need to fix


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 13010
Topic starter  

TL;DR: Spear phishing remains a top initial access path because most organisations still lack an effective defence-in-depth strategy, leaving business email compromise, session hijacking and ransomware exposure, according to Knowbe4. The real failure is not awareness training alone, but weak identity and session controls that let stolen trust become usable access.

NHIMG editorial — based on content published by Knowbe4: eBook, Comprehensive Anti-Phishing Guide

By the numbers:

Questions worth separating out

Q: What breaks when phishing controls stop at user awareness alone?

A: Awareness without identity enforcement leaves the attacker free to reuse stolen credentials, hijack sessions, or pivot through recovery workflows.

Q: Why do phishing attacks so often lead to broader identity compromise?

A: Phishing succeeds because it captures trust that the organisation already accepts.

Q: What do security teams get wrong about anti-phishing programmes?

A: Many teams overinvest in warning users and underinvest in the access paths that a phished user can reach.

Practitioner guidance

  • Harden mailbox and SSO session controls Require step-up authentication for high-risk actions, bind sessions to device or risk signals where possible, and shorten the lifetime of privileged browser sessions so a stolen token has less value.
  • Extend anti-phishing scope into privileged access Review whether email compromise can reach admin consoles, password reset paths, help desk approvals, and break-glass accounts, then remove standing privilege from those routes where feasible.
  • Inventory secrets reachable from user workspaces Search collaboration tools, inboxes, code repositories, and shared drives for API keys, tokens, and certificates that a phished user could expose, then rotate anything that does not need long-term persistence.

What's in the full article

Knowbe4's full eBook covers the operational detail this post intentionally leaves for the source:

  • Technical control patterns for reducing phishing impact across email, identity, and endpoint layers
  • Guidance on building a defence-in-depth anti-phishing programme for users and administrators
  • Considerations for security awareness training and policy design that support operational response
  • Discussion points on cyber insurance and practical risk trade-offs in phishing-heavy environments

👉 Read Knowbe4's eBook on comprehensive anti-phishing defence →

Phishing defence gaps: what IAM and security teams need to fix?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 12594
 

Phishing is now an identity governance problem, not just a user behaviour problem. Awareness matters, but it does not stop session replay, delegated trust abuse, or credential reuse once an attacker has the first foothold. The control failure is usually in the path from human trust to enforceable access policy. Practitioners should therefore treat phishing resilience as part of IAM and PAM governance, not an isolated security-awareness exercise.

A question worth separating out:

Q: How should organisations respond when a phishing alert is confirmed?

A: Contain the account, revoke active sessions, reset affected credentials, and check for delegated access, mailbox rules, and secret exposure before restoring trust. Then review whether the compromised identity had paths into admin functions, automation tokens, or cloud consoles. The objective is to stop the attacker from converting one phish into a wider identity event.

👉 Read our full editorial: Phishing defence still fails where identity trust is weakest



   
ReplyQuote
Share: