Deterrence is working when attackers abandon the target, not just when individual attempts fail. Look for rising attacker effort, lower success rates across repeated sessions, reduced reuse of the same infrastructure, and evidence that the platform is no longer a low-friction target.
What to Measure Beyond Failed Attempts
Fraud deterrence is not proven by a single blocked login, declined payment, or cancelled account takeover. The better question is whether the attacker still sees the target as worth the effort. That means measuring changes in attacker behaviour over time, not just control outcomes at the transaction level.
Look for signals such as repeated failures across separate sessions, rising cost for the attacker, shorter dwell time, fewer successful pivots, and less reuse of the same tools, proxies, devices, or delivery paths. When deterrence is real, the fraud operation starts to look unstable or unattractive rather than merely interrupted.
It also helps to distinguish deterrence from suppression. Suppression reduces the success rate of individual attempts; deterrence changes the attacker's decision-making. A control can be effective at stopping bad actions and still fail to deter if the attacker immediately adapts and keeps treating the target as a profitable route.
What Attacker Adaptation Tells You
Adaptation is one of the clearest signs that deterrence is working in practice. If the same campaign has to rotate infrastructure, vary tooling, slow down, change targeting patterns, or switch to softer targets, the original environment has become harder to abuse. That shift is often more meaningful than a raw drop in incident volume.
On the other hand, steady reuse of the same infrastructure or the same abuse pattern can indicate that controls are inconvenient but not materially discouraging. A fraud team should watch for whether attackers are spending more effort to reach the same outcome, because friction alone is only useful if it changes attacker economics.
For practitioners, the key is to compare behaviour before and after a control change, not just to count outcomes after the fact. If you deploy a control and the attacker immediately reuses the same path with similar success, you have evidence of containment, but not yet evidence of deterrence.
How to Tell Friction from Real Deterrence
Not every obstacle is a deterrent. Strong deterrence typically shows up as a combination of lower success, higher operating cost for the attacker, and reduced willingness to keep pressing the target. That can appear as fewer retries, less persistence across accounts or sessions, and a shift toward less defended targets.
Useful evidence includes stable decline in repeat abuse from the same campaign family, fewer correlated incidents across channels, and less concentration of attacks on the same high-value workflow. When those patterns move together, the control is affecting attacker strategy rather than just one point of failure.
Fraud programs should also avoid over-reading short-term noise. Attackers often probe, pause, and return. The question is whether your control changes the long-run pattern of abuse, not whether a few attempts still get through while the attacker is testing the boundary.
Practitioner Guidance
What to measure: Track repeat attempts by campaign, infrastructure reuse, session-to-session persistence, and conversion rate across comparable abuse windows. Pair those metrics with a simple review of whether the attacker is changing tools, tactics, or target selection.
Decision rule: If attempts fall but the same actor patterns keep reappearing with similar economics, treat the control as suppressive rather than deterring. If attempts become more expensive, less repeatable, and less concentrated on your environment, you have stronger evidence of deterrence.
What good looks like: The platform becomes a poor value proposition for abuse. Attackers either abandon it, slow down materially, or move to weaker targets because the expected payoff no longer justifies the effort.
Practitioner takeaway: The best deterrence signal is not “we blocked it again,” but “the attacker changed course because attacking here stopped being worthwhile.”
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 10, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org