TL;DR: AI-powered phishing simulation platforms are being used to move beyond static awareness tests by correlating behavior, identity, and threat signals, according to Living Security Human Risk Management Platform. The shift matters because click rates alone do not show who is actually exposed, who has privileged access, or where a human-risk program can reduce real attack likelihood.
NHIMG editorial — based on content published by Living Security Human Risk Management Platform: AI-Powered Phishing Simulation Software: How It Works
Questions worth separating out
Q: How should security teams measure human risk in phishing simulations?
A: They should measure more than clicks.
Q: Why do identity and access systems matter in phishing simulation programmes?
A: Because a click only becomes material when the account has meaningful access.
Q: What do security teams get wrong about human risk management?
A: They often treat it as a training completion problem instead of a resilience problem.
Practitioner guidance
- Weight simulation results by access scope Prioritise users with privileged or sensitive access when simulation failures occur, and route them into targeted intervention paths rather than generic retraining.
- Extend phishing testing beyond email Include smishing, vishing, and impersonation scenarios that reflect the channels attackers actually use against your workforce.
- Feed simulation outcomes into IAM workflows Connect repeated risky behaviour to access review, step-up verification, or manager review where the account has meaningful privilege.
What's in the full article
Living Security Human Risk Management Platform's full blog covers the operational detail this post intentionally leaves for the source:
- Campaign design guidance for multi-channel simulations across email, SMS, voice, and deepfake scenarios
- Operational examples of how simulation scoring is tied to behaviour, identity, and threat intelligence
- Reporting and analytics detail for tracking risk trajectories rather than simple click rates
- Examples of adaptive micro-training and automated intervention workflows used after simulation failures
AI-powered phishing simulations: are your awareness controls keeping up?
Explore further
AI phishing simulation is becoming an identity governance problem, not just a training problem. The article correctly moves beyond click rates and treats simulation output as risk intelligence. Once identity data is part of the scoring model, the question shifts from who clicked to whose access would make that click material. That is a governance boundary IAM teams should recognise. If simulation results do not feed access review, privileged-user prioritisation, and response workflows, the programme is still measuring awareness rather than reducing exposure.
A question worth separating out:
Q: Who should be accountable when phishing simulation findings reveal repeated risky behaviour?
A: Accountability should sit with both the security programme owner and the identity governance process that can act on the result. If a repeated failure does not change access review, verification requirements, or targeted intervention, then the organisation has measured risk without governing it.
👉 Read our full editorial: AI-powered phishing simulations expose the limits of static awareness