Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Phishing impact testing: are your controls proving blast-radius reduction?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: A university found that 84 phished credentials led to 482 verified impact paths, 257 compromised hosts, and domain compromise in 19 minutes, according to Horizons.ai. The result shows why phishing awareness metrics alone miss the security question that matters most: how far an attacker can go after one credential is exposed.

NHIMG editorial — based on content published by Horizons.ai: From Patch Tuesday to Pentest Wednesday®: A University’s Journey to Measure Blast Radius

By the numbers:

Questions worth separating out

Q: How should security teams measure phishing risk beyond click rates?

A: Use layered behavioural signals instead of a single click metric.

Q: Why do phished credentials still create major risk in well-trained organisations?

A: Because training improves user behaviour, but it does not automatically fix access design.

Q: What breaks when identity sprawl is not continuously reconciled?

A: Dormant accounts, duplicate identities, orphaned service accounts, and unmanaged AI identities accumulate across the estate, driving cost and creating blind spots.

Practitioner guidance

  • Measure phishing by downstream impact, not click rate Run phishing simulations with follow-on validation that shows which credentials can reach privileged systems, sensitive data, and lateral movement paths.
  • Rank identities by blast radius Identify the accounts that create the greatest number of verified attack paths and prioritise them ahead of lower-leverage findings.
  • Collapse the access paths that make phishing consequential Target excessive write permissions, over-broad domain user privileges, and lateral movement pathways first.

What's in the full article

Horizons.ai's full blog covers the operational detail this post intentionally leaves for the source:

  • The full attack-path visualisation showing how compromised credentials chained into domain control.
  • The per-account exposure breakdown that identifies which identities created the most leverage.
  • The remediation sequence used to reduce excessive write permissions and lateral movement pathways.
  • The follow-up testing evidence that confirmed the blast radius had actually collapsed.

👉 Read Horizons.ai's analysis of phishing impact testing and blast-radius reduction →

Phishing impact testing: are your controls proving blast-radius reduction?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Click rate is an awareness metric, not a control outcome. Phishing programmes that stop at user behaviour create an accounting illusion: they can show improvement while the reachable attack surface remains unchanged. The university’s result demonstrates that the real question is not whether someone clicked, but whether the submitted credential could still reach privileged systems and sensitive data. That is a governance failure because it measures participation instead of exposure.

A few things that frame the scale:

  • Two-thirds of enterprises have endured a successful cyberattack resulting from compromised non-human identities, with a quarter encountering multiple attacks, according to 2024 ESG Report: Managing Non-Human Identities.
  • 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, including 46% that confirmed a breach.

A question worth separating out:

Q: Who is accountable when phishing simulations reveal large blast radius?

A: Accountability sits with the teams that own identity, privilege, and remediation governance, not just awareness training. If a simulation shows that common accounts can reach critical systems, leaders must answer for entitlement design, access review quality, and remediation prioritisation. Awareness is only one part of the control stack.

👉 Read our full editorial: Blast radius beats click rate in phishing risk measurement



   
ReplyQuote
Share: