TL;DR: Generic social engineering training still leaves organisations exposed because attackers exploit human psychology, role-specific access, and live threat context, according to Living Security Human Risk Management Platform. Annual awareness checkboxes are no longer enough; effective programmes need continuous, data-driven interventions tied to behaviour and measurable risk reduction.
NHIMG editorial — based on content published by Living Security Human Risk Management Platform: 6 Steps: Social Engineering Awareness Training for Employees
By the numbers:
- 90% of data breaches start with a phishing attack, according to industry reporting cited by Living Security Human Risk Management Platform.
- 88% of data breaches involve a human element, according to industry reporting cited by Living Security Human Risk Management Platform.
- Attackers attempt access within an average of 17 minutes when AWS credentials are exposed publicly, according to Entro Security.
Questions worth separating out
Q: How should security teams reduce the impact of social engineering on human accounts?
A: Use layered controls that assume a person can be fooled.
Q: Why do social engineering attacks still succeed in well-defended organisations?
A: They succeed because attackers target human judgement, not just technical weaknesses.
Q: What should organisations measure instead of review completion rates?
A: They should measure unowned access, standing privilege, and the time between entitlement change and governance action.
Practitioner guidance
- Implement risk-based audience segmentation Group employees by role, access, prior simulation behaviour, and exposure to sensitive workflows so training reflects real attack likelihood rather than job title alone.
- Correlate human and identity signals Connect simulation results, reporting rates, identity system events, and behavioural telemetry to identify where social engineering is most likely to succeed and where privileged workflows are most exposed.
- Replace annual training with continuous interventions Deliver short, timely nudges and scenario-based refreshers after risky actions, suspicious clicks, or changes in threat patterns.
What's in the full article
Living Security Human Risk Management Platform's full article covers the operational detail this post intentionally leaves for the source:
- Role-based training segmentation examples for different employee cohorts and risk levels
- Phishing simulation and micro-training workflow details that support continuous reinforcement
- Practical measurement ideas for reporting rates, click behaviour, and behavioural change
- Platform-specific discussion of Human Risk Management features and AI-assisted nudging
Social engineering awareness: why generic training still misses risk?
Explore further
Generic awareness is a governance failure, not a training failure. The core issue in social engineering programmes is that many organisations still treat human risk as a communications problem instead of an operational control problem. That leaves identity, access, and behaviour data disconnected, so interventions arrive too late or at the wrong audience. For IAM and security leaders, the lesson is that human risk must be governed with the same discipline applied to privileged access and authentication.
A question worth separating out:
Q: How should IAM and PAM teams respond to social engineering risk?
A: Treat social engineering as a front-end access problem, not only an awareness issue. Tighten approval workflows, verify high-risk requests out of band, and make it harder for a single manipulated user to trigger privileged action. The aim is to reduce the chance that one compromised conversation becomes an identity event.
👉 Read our full editorial: Social engineering training fails when human risk stays generic