Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Phishing, vishing and smishing: are awareness programmes keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19382
Topic starter  

TL;DR: Generative AI has made phishing, vishing, and smishing more convincing and more coordinated, pushing Living Security Human Risk Management Platform’s analysis toward multi-vector simulation, identity-aware risk scoring, and continuous reinforcement rather than annual email-only training. The practical shift is from compliance-led awareness to measurable behavior change across the people and access paths attackers actually exploit.

NHIMG editorial — based on content published by Living Security Human Risk Management Platform: Your Guide to Enterprise Phishing Vishing Smishing Training

By the numbers:

Questions worth separating out

Q: How should security teams train users for phishing, vishing, and smishing together?

A: Train them as one connected attack path, not three separate awareness topics.

Q: Why does identity context improve human-risk decisions?

A: Because the same risky action has different consequences depending on privilege, system reach, and data sensitivity.

Q: What do organisations get wrong about measuring security awareness?

A: They overvalue completion rates and underweight behavioural change.

Practitioner guidance

  • Build multi-vector simulation campaigns Test phishing, vishing, and smishing as one linked scenario so employees learn to recognise the handoff between channels.
  • Prioritise users by access context Rank simulation targets using identity signals such as privileged access, payment authority, and workflow permissions, not click rate alone.
  • Deploy just-in-time micro-training Attach short remediation modules immediately after a failed simulation or risky report so the lesson lands while the event is still fresh.

What's in the full article

Living Security Human Risk Management Platform's full article covers the operational detail this post intentionally leaves for the source:

  • Simulation design guidance for phishing, vishing, and smishing across coordinated attack sequences.
  • Risk-scoring approaches that combine employee behavior with identity and access signals.
  • Examples of automated micro-training and reinforcement workflows after risky user actions.
  • Board-facing metrics that move beyond completion rates and basic click tracking.

👉 Read Living Security Human Risk Management Platform's analysis of phishing, vishing, and smishing training →

Phishing, vishing and smishing: are awareness programmes keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 18973
 

Single-vector training is now a control failure, not just a maturity gap. The article describes a threat environment where email, text, and voice are used together to create one continuous deception sequence. That means a programme that only tests phishing leaves obvious blind spots in vishing and smishing. The security issue is not whether employees can recognise a bad email, but whether the organisation can resist a multi-channel persuasion campaign.

A question worth separating out:

Q: How should teams respond when a user engages with a suspicious message?

A: Treat it as a coaching and containment moment, not just a training fail. Confirm whether credentials, approvals, or device actions were exposed, then reinforce the lesson immediately with short remediation. If the user has sensitive access, route the event through your security and IAM processes so downstream risk is assessed quickly.

👉 Read our full editorial: AI-native phishing training is replacing email-only awareness models



   
ReplyQuote
Share: