Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

AI-driven smishing: are your human risk controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18004
Topic starter  

TL;DR: AI-generated smishing has removed the visual red flags employees were trained to spot, pushing organisations beyond annual awareness training toward continuous, role-specific Human Risk Management, according to Living Security Human Risk Management Platform. The core issue is not employee failure but a control model built for a slower, less convincing threat environment, and that gap now demands behaviour-based governance.

NHIMG editorial — based on content published by Living Security Human Risk Management Platform: Rethink AI-Powered Smishing Awareness Training

Questions worth separating out

Q: How should organisations reduce the risk of AI-driven smishing attacks?

A: Organisations should move from annual awareness training to continuous, role-specific simulations and coaching.

Q: Why does AI-generated smishing undermine traditional employee awareness programmes?

A: Because traditional programmes depend on users spotting obvious mistakes such as bad grammar, odd formatting, or generic language.

Q: What do security teams get wrong about smishing?

A: They often treat it as a user-awareness problem instead of an identity and fraud problem.

Practitioner guidance

  • Deploy continuous smishing simulations Replace annual phishing modules with frequent, role-specific SMS simulations that mirror current lures, urgency cues, and executive impersonation patterns.
  • Build separate verification paths for text-based requests Require out-of-band confirmation for any text message that asks for credentials, payment, or urgent action.
  • Correlate identity and behaviour signals Tie click activity, reporting rates, and role context into a single human risk view so security teams can see where exposure is concentrated.

What's in the full article

Living Security Human Risk Management Platform's full blog post covers the operational detail this post intentionally leaves for the source:

  • Examples of role-specific AI-powered smishing simulations and how they are tuned for different job functions.
  • Detailed guidance on using micro-learning and real-time nudges after risky user behaviour.
  • The platform’s explanation of how it correlates behaviour, identity, and threat signals to identify at-risk employees.
  • Practical framing for measuring reporting rates, repeat clicks, and human risk trends over time.

👉 Read Living Security Human Risk Management Platform's analysis of AI-powered smishing awareness training →

AI-driven smishing: are your human risk controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 17593
 

AI-driven smishing is not an awareness problem first. It is a control-design problem. The old model expects users to notice errors, hesitations, or odd formatting, but AI removes those tells. That means the security programme is asking people to perform a task the attacker has already neutralised. Practitioners should treat the shift as a governance failure in detection design, not a user discipline issue.

A question worth separating out:

Q: Who is accountable when an employee falls for a convincing smishing message?

A: Accountability is shared across security awareness, identity governance, and fraud response because the failure usually spans message delivery, user decision-making, and access abuse. The right metric is not just whether the user clicked, but whether the organisation reduced repeat exposure and shortened response paths.

👉 Read our full editorial: AI-driven smishing is exposing the limits of awareness training



   
ReplyQuote
Share: