TL;DR: Automated smishing simulations turn text-message scams into measurable human-risk signals by pairing realistic mobile lures with identity and behaviour data, according to Living Security Human Risk Management Platform. The article argues that click rates alone are too narrow, and that mature programmes need continuous, role-aware testing linked to broader risk governance.
NHIMG editorial — based on content published by Living Security Human Risk Management Platform: Reduce Risk with Automated Smishing Simulation Campaigns
By the numbers:
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage.
- Only 5.7% of organisations have full visibility into their service accounts.
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security.
Questions worth separating out
Q: How should security teams run smishing simulations without creating fear?
A: Use simulation as a learning loop, not a punishment mechanism.
Q: Why does this kind of kernel flaw matter to identity and access teams?
A: Because it compromises the host material that identity systems rely on.
Q: What signals show that a smishing programme is actually working?
A: Look for declining click rates, rising report rates, fewer credential submissions, and better performance in high-risk groups over time.
Practitioner guidance
- Build role-aware smishing scenarios Design lures around the actual communications your workforce sees, such as delivery notices, executive requests, and IT alerts, then vary them by department and privilege level.
- Correlate simulation data with identity signals Join click, report, and credential-entry outcomes to identity attributes such as role, privilege, and authentication strength so teams can prioritise the users whose behaviour creates the greatest access risk.
- Use reporting rate as a maturity metric Track how often users report suspicious messages, not just whether they click.
What's in the full article
Living Security Human Risk Management Platform's full blog covers the operational detail this post intentionally leaves for the source:
- Campaign setup guidance for role-based smishing simulations across large employee populations
- Examples of adaptive micro-training flows tied to click, report, and credential-entry outcomes
- Operational detail on integrating smishing telemetry with identity and threat data
- Programme design ideas for linking human-risk findings to broader security workflows
Smishing simulations: what security teams need to change now?
Explore further
Smishing is an identity problem, not just an awareness problem. The article correctly frames mobile lures as behaviour-led attacks, but the governance issue is what happens after the click. When credentials, MFA prompts, or device sessions are exposed, the incident becomes an access-control failure that touches IAM, fraud, and account protection. Teams should treat smishing telemetry as identity risk input, not training vanity metrics.
A question worth separating out:
Q: How should organisations prioritise users after smishing simulation failures?
A: Prioritise users whose failed simulations align with meaningful access, such as finance, support, or administrator functions. The point is not to rank everyone equally, but to focus remediation where human error could quickly become identity compromise or business-impacting access abuse.
👉 Read our full editorial: Automated smishing simulations expose the gap in human risk defense