Organisations should treat high-value users as special targets and combine training with stronger identity controls. The most effective approach is to verify requests through a second channel, use phishing-resistant MFA, and limit what executives can approve alone. That reduces the chance that a single convincing message turns into credential theft, fraud, or unauthorized access.
Why This Matters for Security Teams
Spear phishing against executives works because the attacker is not trying to breach every account at once. They only need one convincing request to reach a person who can approve payments, reset access, authorize vendors, or bypass normal checks. That makes high-value users a control-plane problem, not just an awareness problem. Current guidance from the NIST Cybersecurity Framework 2.0 emphasises stronger identity assurance and governance, but the practical challenge is that executives often sit outside standard workflows.
NHIMG’s research on identity compromise shows how quickly identity failures compound in real environments, including the findings in The 2024 ESG Report: Managing Non-Human Identities, where compromised identities were often not isolated incidents. The same pattern appears in executive phishing: a single successful lure can turn into credential theft, payment fraud, mailbox takeover, or downstream access abuse. In practice, many security teams encounter the breach after the executive inbox has already been used as a trusted launch point for broader fraud.
How It Works in Practice
The most effective programme combines phishing-resistant authentication, request verification, and tighter approval boundaries. That starts with MFA that resists replay and token theft, then moves to process design. If an attacker can impersonate a CEO by email, the organisation should assume that email alone is never enough to authorise sensitive action. For high-risk requests, a second channel such as a known phone number, authenticated collaboration tool, or in-person callback should be mandatory.
For identity controls, the goal is to make stolen credentials less useful. Stronger policies should be applied to mailbox access, password resets, device enrollment, and privileged approvals. Executives should not be able to approve bank changes, payroll edits, or supplier onboarding alone if those actions can be triggered by email. This is where many organisations adopt a mix of Top 10 NHI Issues thinking and classical privilege control: limit standing access, require step-up verification, and bind approvals to context rather than sender identity.
- Use phishing-resistant MFA for executives and assistants who manage sensitive workflows.
- Route payment, legal, and access-change requests through a separate verification path.
- Restrict executive authority in email, chat, and ticketing systems to narrowly defined actions.
- Monitor for mailbox forwarding, OAuth abuse, impossible travel, and unusual consent grants.
- Train assistants and finance teams as primary targets, not just executives.
The operational lesson is that the channel is part of the control. If the same inbox can request, approve, and confirm a high-risk action, an attacker only needs one successful impersonation. These controls tend to break down in fast-moving organisations where executive assistants, finance teams, and incident responders all rely on informal exception handling because the business has normalised bypassing the standard approval path.
Common Variations and Edge Cases
Tighter approval controls often increase friction, requiring organisations to balance fraud resistance against executive convenience and business speed. That tradeoff is real, especially during travel, mergers, market close, or crisis response. Best practice is evolving, but current guidance suggests treating these periods as higher-risk rather than relaxing controls permanently.
Remote and distributed leadership teams are especially exposed because attackers can exploit time zones, personal email habits, and over-reliance on mobile approvals. In those environments, organisations should pre-register backup verifiers, maintain out-of-band contact methods, and define what can never be approved by email alone. This is also where OWASP NHI Top 10 thinking is useful: trust boundaries matter, and identity assertions must be validated at the moment of action, not assumed from a message header.
There is no universal standard for this yet, but organisations that reduce spear phishing risk most effectively usually combine policy, identity assurance, and transaction controls. For broader governance context, the Ultimate Guide to NHIs — Why NHI Security Matters Now and CoPhish OAuth Token Theft via Copilot Studio both reinforce the same practical point: attackers increasingly abuse trusted identity and workflow channels, so organisations must verify the request, not just the sender.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10, CSA MAESTRO and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-03 | Exec phishing often becomes credential abuse and token theft. |
| NIST CSF 2.0 | PR.AC-1 | Access should be based on verified identity and context, not email trust. |
| NIST AI RMF | GOVERN | Executive phishing risk needs clear ownership and policy enforcement. |
| CSA MAESTRO | IAM-03 | Agentic-style impersonation maps to identity and workflow abuse patterns. |
| OWASP Agentic AI Top 10 | LLM-02 | Trusting a message without validation mirrors prompt and instruction injection risk. |
Verify intent and source before executing sensitive actions triggered by messages.
Related resources from NHI Mgmt Group
- When should organisations treat an NHI as a high-priority risk?
- How should security teams reduce phishing risk in high-value access paths?
- How should organisations reduce the risk of borrowed identities in high-value environments?
- How should organisations reduce phishing risk when users are under time pressure?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org