TL;DR: Adaptive phishing training uses behavior, identity, and threat data to tailor interventions, and Living Security cites Cyentia Institute findings showing a 50% reduction in risky users and a 98% drop in data-loss exposure. The underlying shift is that human risk programs now need identity-aware, context-driven controls rather than fixed simulations and generic awareness cycles.
NHIMG editorial — based on content published by Living Security Human Risk Management Platform: Adaptive Phishing Training: Personalize Intervention by Risk
By the numbers:
- Research from the Cyentia Institute shows that risk-based models reduce risky users by 50% and decrease data-loss exposure by 98%.
- 82% of data breaches involve a human act like clicking a bad link.
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, with 46% confirmed and 26% suspected.
Questions worth separating out
Q: How should security teams implement adaptive phishing training in enterprise environments?
A: Start by linking phishing simulations to live risk signals, not calendar dates.
Q: Why do generic phishing campaigns fail to reduce real breach risk?
A: Generic campaigns fail because they measure participation rather than exposure.
Q: What do security teams get wrong about user awareness training for browser threats?
A: They assume training can keep pace with attacker creativity.
Practitioner guidance
- Tie phishing risk scores to access review cycles Use behaviour and threat signals to prioritise users whose compromise would affect privileged accounts, finance workflows, or identity administration.
- Personalise simulations by role and privilege Build phishing scenarios that reflect the actual workflows users touch, such as finance approvals, developer sign-in flows, or admin portal lures.
- Connect awareness telemetry to IAM and PAM signals Correlate failed simulations, repeated risky clicks, and suspicious sign-ins with IAM logs and privileged access events.
What's in the full article
Living Security Human Risk Management Platform's full article covers the operational detail this post intentionally leaves for the source:
- How the platform builds behaviour-based risk profiles from employee activity and threat context.
- Examples of role-specific phishing simulations across finance, IT, and other high-risk functions.
- The automation workflow behind rapid intervention after a failed simulation or risky action.
- The article's explanation of the Livvy intelligence engine and its risk-signal inputs.
Adaptive phishing training: what it means for IAM and HRM teams?
Explore further
Adaptive phishing is really human access risk management in disguise. Once training is driven by behaviour, identity, and threat context, it stops being a pure awareness exercise and becomes a control over who is most likely to expose credentials or approve malicious actions. That makes it relevant to IAM and PAM teams as well as security awareness leads. The governance lesson is simple: the programme should be measured by access-risk reduction, not by campaign completion rates.
A question worth separating out:
Q: How do you know if adaptive phishing training is actually working?
A: Look for fewer risky users, lower repeat-failure rates, and reduced exposure in the accounts that matter most. If the programme is effective, you should see better outcomes in privileged cohorts and fewer incidents where a click turns into credential abuse or downstream data loss.
👉 Read our full editorial: Adaptive phishing training exposes the gap in human risk governance