Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security What breaks when organisations only focus anti-phishing controls…
Cyber Security

What breaks when organisations only focus anti-phishing controls on email attachments?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 26, 2026 Domain: Cyber Security

When defences focus mainly on attachments, they miss the growing share of attacks delivered through links. That leaves gaps in SMS phishing, QR code phishing, and remote access software campaigns that begin with a click rather than a file. Security teams need controls that inspect destinations, not just payloads, and they need monitoring across every user communication channel.

Why This Matters for Security Teams

Attachment-only filtering creates a false sense of coverage. It addresses one delivery method while leaving users exposed to credential theft, malware staging, and remote access abuse that arrives through links, QR codes, cloud-sharing invitations, or messaging apps. A mature anti-phishing programme needs to reduce the chance that a user ever reaches a malicious destination, not just block a file at the gateway.

This matters because attackers adapt to the control that is easiest to bypass. If an organisation only inspects attached files, threat actors can pivot to URL-based lures, compromised legitimate sites, and login pages that harvest credentials without ever delivering a suspicious document. That shift also complicates investigation, because security teams may see a successful sign-in, token capture, or remote-control session long before any malware alert appears. Guidance in NIST SP 800-53 Rev 5 Security and Privacy Controls supports layered control selection rather than dependence on one inspection point. In practice, many security teams encounter the real weakness only after a phishing page has already captured credentials, not during the original email review.

How It Works in Practice

Effective phishing defence treats the message, the destination, and the user action as separate control points. Attachment scanning remains useful, but it must sit alongside URL rewriting or detonation, browser isolation where appropriate, reputation checks, and identity-layer safeguards such as MFA resistant to token replay. Security teams should also account for channel diversity, because phishing now arrives through SMS, collaboration platforms, social media, QR codes, and direct messages as often as through email.

Operationally, a stronger design usually includes:

  • Inspecting links at click time, not only at delivery time.
  • Blocking or warning on newly registered domains and lookalike domains.
  • Validating web forms that request credentials, payment details, or session tokens.
  • Logging user clicks, redirects, and authentication outcomes for SIEM correlation.
  • Training users to treat QR codes and shortened URLs as untrusted entry points.

This approach aligns with broad control frameworks such as CISA phishing guidance and the detection-focused mapping used in MITRE ATT&CK. It also becomes more effective when paired with identity controls that reduce the blast radius of stolen credentials, especially phishing-resistant authentication and step-up verification for sensitive actions. These controls tend to break down in high-volume collaboration environments where users can move from message to browser to cloud app in seconds because the security stack cannot preserve context across tools.

Common Variations and Edge Cases

Tighter link inspection often increases user friction and operational overhead, requiring organisations to balance protection against false positives and workflow disruption. That tradeoff is especially visible in marketing teams, sales teams, and executive assistants who exchange many legitimate links every day.

There is no universal standard for every communication channel yet, so best practice is evolving. Some organisations can enforce heavy inspection in email but have far weaker visibility in SMS, chat, or mobile endpoints. Others rely on secure web gateways, but those controls lose value when users open links on personal devices or outside the corporate network. QR code phishing is another edge case: the malicious destination is hidden from the gateway, so the only reliable control may be device-side browser protection plus user awareness.

For identity teams, the key question is not whether a message looked like phishing, but whether the click led to credential capture, session hijack, or an unauthorised tool session. That makes alert triage and authentication telemetry just as important as message filtering. The practical lesson is simple: if the control only understands attachments, it will miss the attack paths that modern phishers prefer.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-7Phishing defense depends on verified access and authentication outcomes.
NIST AI RMFAI-assisted filtering and threat decisions need governance and risk oversight.
OWASP Agentic AI Top 10User-clicked links can trigger agentic workflows with tool access and execution authority.
MITRE ATT&CKT1566Phishing attack patterns include email, links, and other user interaction vectors.
NIST SP 800-635.2.2Phishing-resistant authentication reduces account takeover after link-based lures.

Use access controls and authentication telemetry to limit damage after a successful phish.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org