TL;DR: Generative AI has made phishing, vishing, and smishing more convincing and more coordinated, pushing Living Security Human Risk Management Platform’s analysis toward multi-vector simulation, identity-aware risk scoring, and continuous reinforcement rather than annual email-only training. The practical shift is from compliance-led awareness to measurable behavior change across the people and access paths attackers actually exploit.
NHIMG editorial — based on content published by Living Security Human Risk Management Platform: Your Guide to Enterprise Phishing Vishing Smishing Training
By the numbers:
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage.
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface.
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security.
Questions worth separating out
Q: How should security teams train users for phishing, vishing, and smishing together?
A: Train them as one connected attack path, not three separate awareness topics.
Q: Why does identity context improve human-risk decisions?
A: Because the same risky action has different consequences depending on privilege, system reach, and data sensitivity.
Q: What do organisations get wrong about measuring security awareness?
A: They overvalue completion rates and underweight behavioural change.
Practitioner guidance
- Build multi-vector simulation campaigns Test phishing, vishing, and smishing as one linked scenario so employees learn to recognise the handoff between channels.
- Prioritise users by access context Rank simulation targets using identity signals such as privileged access, payment authority, and workflow permissions, not click rate alone.
- Deploy just-in-time micro-training Attach short remediation modules immediately after a failed simulation or risky report so the lesson lands while the event is still fresh.
What's in the full article
Living Security Human Risk Management Platform's full article covers the operational detail this post intentionally leaves for the source:
- Simulation design guidance for phishing, vishing, and smishing across coordinated attack sequences.
- Risk-scoring approaches that combine employee behavior with identity and access signals.
- Examples of automated micro-training and reinforcement workflows after risky user actions.
- Board-facing metrics that move beyond completion rates and basic click tracking.
Phishing, vishing and smishing: are awareness programmes keeping up?
Explore further
Single-vector training is now a control failure, not just a maturity gap. The article describes a threat environment where email, text, and voice are used together to create one continuous deception sequence. That means a programme that only tests phishing leaves obvious blind spots in vishing and smishing. The security issue is not whether employees can recognise a bad email, but whether the organisation can resist a multi-channel persuasion campaign.
A question worth separating out:
Q: How should teams respond when a user engages with a suspicious message?
A: Treat it as a coaching and containment moment, not just a training fail. Confirm whether credentials, approvals, or device actions were exposed, then reinforce the lesson immediately with short remediation. If the user has sensitive access, route the event through your security and IAM processes so downstream risk is assessed quickly.
👉 Read our full editorial: AI-native phishing training is replacing email-only awareness models