Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security What breaks when employees are not trained to…
Cyber Security

What breaks when employees are not trained to spot phishing and pretexting?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 24, 2026 Domain: Cyber Security

When users cannot recognize social engineering cues, attackers gain a direct path to credentials, malware delivery, and fraudulent requests. The result is not just account compromise but business disruption, data loss, and delayed response. Gaps in recognition also make it harder for security teams to distinguish normal activity from a real attack.

Why This Matters for Security Teams

Phishing and pretexting are not just user-awareness problems. They are access-path problems that turn human trust into an attack surface. When employees cannot recognise spoofed messages, urgent payment requests, or fake support calls, attackers can bypass perimeter controls and move straight into identity compromise, malware execution, or fraudulent approvals. That is why the NIST Cybersecurity Framework 2.0 treats awareness and training as part of a broader risk management program, not a standalone checkbox.

The practical risk is that one weak interaction can create multiple downstream failures at once. A stolen password may enable mailbox access, a malicious link may launch credential harvesting, and a fake executive request may trigger wire fraud or data exposure. Security teams also lose signal quality because legitimate user actions and attacker activity start to look the same, especially when the attacker uses a real account or follows normal business language. In practice, many security teams encounter phishing only after credentials have already been used, rather than through intentional detection of the initial lure.

How It Works in Practice

Effective training reduces the chance that a user will hand over access or take an unsafe action under pressure. The strongest programs are behavioural, repeated, and role-aware. They teach employees to verify requests through a separate channel, inspect sender domains and reply paths, treat unexpected file-sharing prompts as suspicious, and escalate anything involving payments, password resets, or account changes. NIST guidance aligns with this by framing awareness as a control that supports prevention, detection, and response rather than just policy compliance.

In practice, training should be paired with technical safeguards so that one mistake does not become a full incident. That typically includes:

  • Phishing-resistant MFA for privileged and high-risk users.
  • Mailbox protections that flag spoofing, lookalike domains, and anomalous forwarding rules.
  • Approval workflows for payments, vendor changes, and access requests that require out-of-band verification.
  • Reporting paths that let staff escalate suspicious messages without fear of blame.
  • Targeted simulations that reflect the real tactics used against finance, HR, IT, and executive assistants.

Pretexting deserves special attention because it exploits procedure, not just technology. Attackers often call help desks, impersonate executives, or pose as suppliers to obtain password resets, MFA prompts, or confidential data. Good training therefore needs to cover voice and messaging channels, not only email. It should also teach staff to slow down when the request carries urgency, secrecy, or authority pressure. These controls tend to break down in decentralised organisations with weak approval paths and high staff turnover because repeated exceptions normalise unsafe responses.

Common Variations and Edge Cases

Tighter awareness controls often increase friction for employees, requiring organisations to balance faster work execution against lower social-engineering risk. That tradeoff becomes more visible in high-velocity environments such as customer support, finance operations, healthcare, and managed service desks, where staff are expected to respond quickly and often under time pressure.

Best practice is evolving for hybrid and AI-assisted attack patterns. Current guidance suggests that training now needs to cover synthetic voices, deepfake video, and chatbot-generated lures that sound polished but are still malicious. There is no universal standard for this yet, but teams should assume that attacker quality will improve faster than human intuition. The key is to teach verification habits that do not depend on tone, spelling, or obvious grammatical mistakes.

This also intersects with identity and privileged access governance. A phished user account can become a stepping stone to non-human identities, service accounts, or admin consoles if credential reuse and over-permissioning are present. For that reason, phishing awareness should be coordinated with access review, PAM, and incident response procedures rather than run as a separate campaign. More mature programs also correlate user reports with SIEM and SOAR workflows so suspicious messages become triage input, not just training metrics. For broader control mapping, the NIST Cybersecurity Framework 2.0 remains a practical anchor for linking training to governance and response.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AT-01Training and awareness directly reduce phishing and pretexting success.
NIST Zero Trust (SP 800-207)Zero trust reduces reliance on user recognition by verifying every request.

Deliver recurring awareness training and test whether staff can recognise and report social engineering.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org