Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› How should security teams prioritise people who are…
Governance, Ownership & Risk

How should security teams prioritise people who are repeatedly targeted by phishing and BEC?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 28, 2026 Domain: Governance, Ownership & Risk

Security teams should rank individuals and shared lists by a blended exposure model, not by raw message volume alone. A person hit by fewer but more severe threats can represent greater risk than someone receiving many low severity emails. Prioritisation should combine targeting, actor type, threat type, and frequency so controls focus on the people most likely to be compromised.

How to prioritise repeated phishing and BEC targeting

Repeated targeting is a useful signal, but it should not be treated as the sole ranking factor. Teams get better results when they score people by exposure plus consequence, so a small number of high-impact attempts can outrank a large volume of low-grade mail. That means weighting who is targeted, what kind of actor is behind it, and whether the pattern suggests escalation toward account compromise or payment fraud.

What a blended exposure model should measure

The right model distinguishes noise from meaningful pressure. Message volume matters because it shows persistence, but it is only one variable. The more important question is whether the targeted person sits in a role where a successful phish or BEC attempt would create real business impact, such as finance, executive support, procurement, or mailbox-admin access. A person who receives fewer messages may still rank higher if the sender is better resourced, more credible, or more likely to convert.

For that reason, prioritisation should combine targeting frequency, threat actor type, threat severity, and the target’s business role. Shared mailboxes, delegated inboxes, and assistant accounts can also be high value because they often sit close to approvals, payments, and external communications. When you evaluate repeated targeting, look for patterns that indicate an adversary is testing trust, harvesting context, or working toward a second-stage fraud rather than just blasting generic spam.

How to turn priority into action

Once the highest-risk people are identified, use that ranking to drive control strength and monitoring intensity. High-priority targets should get tighter mailbox review, stronger phishing-resistant authentication where feasible, faster incident triage, and more frequent confirmation for payment or account-change requests. Teams should also watch for correlated targeting of a person and their assistants, shared inboxes, or closely related business functions, because BEC often succeeds through relationships rather than one mailbox alone.

Repeated targeting should also influence where security teams invest their limited human review time. A well-designed queue will elevate people who are both heavily targeted and operationally sensitive, instead of spreading effort evenly across everyone who ever receives phishing email. That approach makes awareness, containment, and escalation more efficient because the highest-risk users are the ones most likely to be worth active defensive attention.

Risk and Threat Considerations

Repeated phishing and BEC targeting is dangerous because it can signal active adversary interest in a person, not just generic campaign noise. The main risk is that attackers use repeated attempts to refine their pretext, time their send, or reach the right internal relationship until one message lands and produces credential theft, invoice fraud, or mailbox abuse.

Failure mechanism: Low-quality volume-based triage can hide high-value targeting, especially when a determined actor sends only a few convincing messages to a small set of people who can approve payments, reset access, or expose sensitive correspondence.

Impact: The result can be account takeover, fraudulent transfer, internal impersonation, and broader trust erosion across the business process that the targeted person supports.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-9 — Email and Web Browser ProtectionsRepeated phishing priority depends on email attack exposure and filtering control strength.
Recommendation — Tune email protections and user reporting to reduce successful phishing against high-risk targets.
NIST SP 800-53 Rev 5AU-6 — Audit Record Review, Analysis, and ReportingPrioritisation needs review of repeated targeting patterns and anomalous mailbox activity.
IA-2 — Identification and Authentication (Organizational Users)BEC risk increases when user accounts can be compromised through weak authentication.
IA-5 — Authenticator ManagementPhishing and BEC often exploit weak credential lifecycle and reuse.
Recommendation — Review alerts and audit data for repeated targeting and possible mailbox abuse. Strengthen user authentication for the people most likely to be targeted. Rotate and manage credentials for high-risk accounts with tighter lifecycle controls.

Practitioner Guidance

What to prioritise: Rank people by a combined score that weights targeted severity and business consequence, not just count of received messages. In practice, that means putting executive assistants, finance approvers, procurement, and mailbox-adjacent accounts ahead of low-impact recipients even when their raw phishing volume is lower.

What to verify: Confirm whether repeated targeting is coming from the same actor set, the same lure pattern, or a campaign that is escalating toward credential capture or payment fraud. If the pattern changes from generic phishing to impersonation of a trusted contact, the priority should move up immediately.

Practitioner takeaway: The best triage question is not “who got the most phishing?” but “whose compromise would do the most damage, and is an attacker already working that path?”

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 28, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org