Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› How should security teams respond when certain users…
Governance, Ownership & Risk

How should security teams respond when certain users are attacked more often than others?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 28, 2026 Domain: Governance, Ownership & Risk

Security teams should treat heavily targeted users as a separate risk group and apply controls that match the exposure they are actually facing. A practical response is to combine awareness training with observed attack patterns, then reinforce behavior around the lures those users encounter most. That approach improves resilience by reducing repeat clicks, improving judgment, and aligning training to real attack pressure.

Why heavier targeting changes the security response

When a subset of users is attacked more often, the problem is not just individual caution, it is an exposure pattern. Security teams should treat that group as its own operational population because their lure mix, attacker attention, and error rate are likely different from the rest of the workforce. That means the response should be driven by observed attack pressure, not by generic baseline training alone.

In practice, the right lens is “who is being targeted, how, and how often?” If a user group repeatedly sees the same social engineering themes, the control objective shifts from broad awareness to targeted resilience. The team should use those patterns to decide what training content, simulation themes, and escalation paths deserve priority.

How to tailor controls to the attack pattern

The most effective response is to align the control with the lure. If attackers repeatedly use credential prompts, invoice fraud, document shares, or urgent executive requests, the reinforcement should focus on those exact behaviors. That is more useful than issuing a wide reminder about phishing in general, because it addresses the failure mode the users are actually facing.

Targeted reinforcement also works better when it is paired with operational support. Users who are disproportionately targeted often need faster confirmation paths, clearer reporting steps, and visible escalation options when a message feels unusual. The goal is to shorten the time between suspicion and reporting, while reducing the chance that a successful lure becomes a repeat event.

Where the pattern is persistent, security teams should also review whether those users have a role-related exposure that increases risk, such as public-facing responsibilities, financial approval rights, or frequent external communication. In those cases, the right answer is not only more training, but a tighter blend of process, verification, and communication controls.

What changes when the same group keeps getting hit

Repeated targeting usually indicates one of three things: the group is valuable, the group is visible, or the lure works. Each of those conditions calls for a different operational response. Valuable targets may need stronger verification steps; visible targets may need reduced exposure in public channels; and effective lures require immediate content adjustments in awareness and simulation programs.

A practical way to operationalise this is to tie awareness to live attack telemetry. The point is not to punish users for being targeted, but to make the security programme adaptive. A control that ignores current attack patterns will usually over-train on low-probability scenarios and under-train on the messages that are actually reaching inboxes and chat tools.

For broader context on repeat compromise and common attack paths, The 52 NHI Breaches Report shows how attackers often reuse effective access and abuse patterns once they find a working path.

Risk and Threat Considerations

Heavily targeted users create concentrated exposure: one successful lure can produce outsized business impact because the same role often has the same permissions, inbox reach, or approval authority every day. Repeated attacks also raise the odds of alert fatigue, which makes the next malicious message easier to miss.

Failure mechanism: Attackers repeatedly probe the same user segment with tailored lures until one succeeds, then exploit the user's normal workflow, trust relationships, or approval habits to gain access or trigger fraudulent action.

Impact: The organisation faces a higher probability of account compromise, payment fraud, data leakage, or downstream misuse of trust, especially when the targeted users sit close to sensitive processes.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-14 — Security Awareness and Skills TrainingTargeted users need training matched to the lures they actually face.
Recommendation — Tailor awareness content to observed attack patterns and reinforce the most common lure types.
NIST CSF 2.0PR.AT-01 — Users are trained and aware of their roles and responsibilitiesRepeated targeting changes how awareness must be delivered and measured.
DE.CM-01 — Networks and network services are monitored to find potentially adverse eventsObserved attack patterns should drive which lures and users are monitored most closely.
Recommendation — Train the heavily targeted group on the specific messages and workflows attackers abuse. Monitor live attack telemetry to identify which user groups are receiving the most pressure.
NIST SP 800-53 Rev 5AT-2 — Awareness TrainingRepeatedly targeted users need awareness content that reflects their actual exposure.
RA-5 — Vulnerability Monitoring and ScanningRisk should be reassessed when a user group shows persistent attack pressure.
Recommendation — Use awareness training that matches the dominant lure types hitting the targeted users. Continuously reassess exposure when repeated targeting suggests a stable attack path.

Practitioner Guidance

What to prioritise: Start with the users who face the most repeated pressure and map the dominant lure types they receive. That gives you the fastest path to reducing actual risk rather than general awareness volume.

What to verify: Confirm that training, simulations, and reporting guidance match the real attack themes seen in mail, collaboration tools, and helpdesk events. If the observed lures and the training content do not line up, the programme is probably lagging the threat.

What good looks like: The targeted group reports suspicious messages faster, makes fewer repeat clicks on the same lure style, and knows exactly when to escalate rather than self-decide. The measure is not zero attacks, it is lower success rate under sustained pressure.

Practitioner takeaway: When one population is attacked more than the rest, treat that as a signal to specialise the control set, not just intensify the generic one.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 28, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org