Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

AI-powered phishing and employee risk: are your controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 12754
Topic starter  

TL;DR: A 33.1% industry-wide phishing susceptibility rate and AI-generated attacks evading more traditional defences are highlighted in KnowBe4’s 2025 benchmarking report, based on 14.5 million users, 62,400 organisations and 67.7 million simulated phishing tests. The governance issue is no longer awareness alone, but whether human identity controls can keep pace with adaptive social engineering, with training reducing risk materially over time.

NHIMG editorial — based on content published by KnowBe4: 2025 Phishing By Industry Benchmarking Report

By the numbers:

  • 33.1%, ndustry-wide baseline Phish-prone Percentage was 33.1%, meaning about one in three employees remained susceptible to phishing and social engineering attacks.
  • Security awareness training reduced phishing risk by over 40% in 90 days and by up to 86% within a year.
  • 82.6% of phishing emails now leverage AI-generated content, while attacks evading Microsoft’s native defenses and secure email gateways rose by 47%.

Questions worth separating out

Q: What breaks when phishing controls stop at user awareness alone?

A: Awareness without identity enforcement leaves the attacker free to reuse stolen credentials, hijack sessions, or pivot through recovery workflows.

Q: Why do AI-generated phishing attacks change human identity controls?

A: They reduce the value of message inspection as a control because attackers can now generate persuasive, context-aware lures at scale.

Q: How do security teams know if security awareness training is actually working?

A: Look for reductions in susceptibility over time, improved reporting behaviour, and fewer successful phish-to-access events.

Practitioner guidance

  • Measure phishing susceptibility as a live risk metric Track phish-prone percentage by business unit, role, and region, then tie it to identity controls such as MFA, conditional access, and reporting rates.
  • Pair training with stronger authentication controls Use phishing-resistant MFA where possible, step-up checks for risky transactions, and session monitoring after authentication.
  • Build reporting into the human identity control loop Make it easy for employees to report suspicious messages and feed those reports directly into SOC and mailbox triage workflows.

What's in the full report

KnowBe4's full report covers the operational detail this post intentionally leaves for the source:

  • Industry-by-industry phishing benchmark tables that let you compare susceptibility across sectors and company sizes
  • Regional breakdowns showing where phishing risk is highest and how that varies by geography
  • Simulation results and methodology details behind the 14.5 million user benchmark dataset
  • Practical guidance on how to strengthen security awareness programmes over a 90-day and 12-month horizon

👉 Read KnowBe4's 2025 Phishing By Industry Benchmark Report →

AI-powered phishing and employee risk: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 12338
 

AI-powered phishing is now a human identity governance problem, not just a user-awareness problem. The report’s core signal is that attackers are industrialising deception with AI-generated content, which means static training alone cannot keep pace. IAM teams need to think about how people authenticate, verify, and report suspicious requests across email, chat, and workflow tools. The practitioner conclusion is simple: human identity assurance must be measured as a control, not assumed as behaviour.

A question worth separating out:

Q: Why do phishing campaigns often become IAM problems after the first click?

A: Because the attacker is usually trying to gain a trusted identity foothold, not just send spam. Once credentials, session approvals, or reset workflows are captured, the incident becomes an access problem involving account takeover, privileged workflows, and potentially non-human identity exposure. That is why phishing needs to be governed as part of IAM, not only email security.

👉 Read our full editorial: AI-powered phishing is widening the human identity risk gap



   
ReplyQuote
Share: