Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Smishing simulations and HRM: what security teams need to change


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18004
Topic starter  

TL;DR: Smishing attacks are now bypassing email controls and targeting employees directly on mobile devices, with one report cited in the article saying 76% of businesses were targeted and attack volume rose 328%, according to Living Security Human Risk Management Platform. Human Risk Management only becomes meaningful when simulation data is linked to identity, behavior, and threat context, not just click rates.

NHIMG editorial — based on content published by Living Security Human Risk Management Platform: 5 Best SMS Phishing Simulation Platforms of 2026

By the numbers:

Questions worth separating out

Q: How should security teams run smishing simulations without creating fear?

A: Use simulation as a learning loop, not a punishment mechanism.

Q: Why do SMS phishing campaigns create a bigger risk than email phishing alone?

A: SMS phishing bypasses many email-specific controls and reaches users in a more personal, time-sensitive channel.

Q: How do you know if a phishing simulation programme is actually working?

A: Do not stop at click rates.

Practitioner guidance

  • Expand phishing tests beyond email Include SMS, voice, and other channels in simulation programmes so the control set reflects how attackers actually reach staff on mobile devices.
  • Correlate simulation results with identity data Join click, report, and response telemetry to identity entitlements, role criticality, and access scope so risk scoring reflects who can be harmed if compromise occurs.
  • Target high-risk cohorts first Prioritise users whose access to finance, customer data, admin workflows, or privileged systems makes a successful smish more consequential than average.

What's in the full article

Living Security Human Risk Management Platform's full article covers the operational detail this post intentionally leaves for the source:

  • Platform selection criteria for realistic SMS and multi-channel simulations
  • Compliance reporting patterns for HIPAA, PCI DSS, SOC 2, and ISO 27001
  • Examples of feedback loops and micro-training workflows after a failed simulation
  • How to connect human-risk telemetry to employee behaviour and identity systems

👉 Read Living Security Human Risk Management Platform's guide to SMS phishing simulation platforms →

Smishing simulations and HRM: what security teams need to change?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 17593
 

Mobile phishing is now an identity governance problem, not just a security-awareness problem. Smishing succeeds when organisations treat mobile lures as a training issue and not as a governed access risk. Once an employee response can lead to credential exposure, MFA fatigue, or approval abuse, the boundary between awareness and identity control disappears. Practitioners should treat mobile-channel social engineering as part of IAM and risk governance, not a separate comms exercise.

A question worth separating out:

Q: Who should own mobile phishing risk when it affects access and identity?

A: Ownership should sit across security awareness, IAM, and risk governance. Awareness teams manage training, IAM teams manage the access consequences of compromise, and risk owners decide which roles need tighter monitoring or stronger verification. That shared model prevents smishing from becoming only a training metric.

👉 Read our full editorial: Smishing simulation platforms expose the human risk gap in mobile attacks



   
ReplyQuote
Share: