Email-only programs leave major blind spots. Attackers regularly use SMS, voice, and QR codes, so employees may learn to spot one format while staying vulnerable to others. The result is weaker resilience, lower reporting confidence, and a false sense of readiness that does not reflect how modern attacks actually unfold.
Why This Matters for Security Teams
Email-only phishing awareness programs create a narrow view of attacker tradecraft. Modern adversaries mix email with SMS, voice calls, QR codes, collaboration tools, and impersonation of internal workflows, so training that focuses on one channel can improve recognition in the lab while missing the channel combinations used in real incidents. The practical risk is not just user error, but distorted assurance: leaders may believe reporting rates and user resistance are stronger than they really are.
Security teams should treat phishing resilience as a cross-channel control problem, not a single-format training exercise. That means aligning awareness content with adversary behaviour, testing users across multiple lures, and correlating reports with detection and response activity. NIST SP 800-53 Rev. 5 frames this well through awareness, training, and incident response controls, especially when organisations need to prove that education maps to actual threat patterns rather than generic cautionary messaging. NIST SP 800-53 Rev 5 Security and Privacy Controls
In practice, many security teams encounter the gap only after a successful voice or SMS lure has already bypassed an email-focused programme.
How It Works in Practice
Effective phishing defence starts with mapping the attack surface the way adversaries use it. Email remains common, but the real objective is credential theft, social engineering, malware delivery, or payment diversion, and those outcomes can be reached through many channels. The best programs build scenarios around the MITRE ATT&CK Enterprise Matrix so teams can connect training to techniques such as phishing, valid accounts, and user execution, then extend that logic into SMS, voice, and collaboration app abuse.
Operationally, a multi-channel program usually includes:
- Phishing simulations across email, text, voice, and QR code scenarios.
- Reporting paths that are equally visible from mobile devices and desktop workflows.
- Role-specific lures for finance, executive support, HR, help desk, and IT admin staff.
- Metrics that track report quality, not just click rates, so defenders can see whether users escalated suspicious activity correctly.
- Feedback loops into SOC triage and incident response so reports become detection signals, not training-only events.
This matters even more as attackers adopt AI-assisted personalisation. Threat reports such as the Anthropic — first AI-orchestrated cyber espionage campaign report show how automation can improve targeting, volume, and message refinement across multiple channels. CISA advisories also regularly reflect blended social engineering campaigns rather than email alone, which is why awareness content should be refreshed from current threat intelligence, not annual slide decks. CISA cyber threat advisories
These controls tend to break down when reporting is trapped inside email plugins or inbox rules because mobile-first channels and voice-based lures never enter the same workflow.
Common Variations and Edge Cases
Tighter cross-channel simulation often increases programme complexity, requiring organisations to balance realism against legal, HR, and communications constraints. That tradeoff is real, especially when testing executives, regulated functions, or regions with strict privacy and labour rules. There is no universal standard for how many channels must be covered, but current guidance suggests coverage should reflect the organisation’s actual exposure profile rather than a fixed annual checklist.
Some environments need extra nuance. In highly regulated sectors, SMS or voice testing may trigger consent, recording, or call-routing issues. In distributed workforces, collaboration platforms may be more relevant than phone calls. In customer-facing organisations, impersonation of service desks, vendors, or payment portals can be more damaging than classic credential-harvest email. For AI-assisted campaigns, the MITRE ATLAS adversarial AI threat matrix is useful when defenders want to understand how model-generated content can amplify social engineering at scale, even if the core control is still user awareness and reporting discipline.
Best practice is evolving toward scenario-based resilience testing: measure whether people recognise suspicious intent, verify through a second channel, and report through approved paths regardless of the lure format. Organisations that keep the test surface narrow often get clean metrics without real resilience, which is useful for compliance theatre but weak against blended attack chains.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AT-1 | Awareness training must cover more than one phishing channel to build usable user readiness. |
| MITRE ATT&CK | T1566 | Phishing techniques span multiple delivery methods, not just email. |
| NIST SP 800-53 Rev 5 | AT-2 | Security awareness training should reflect realistic social engineering scenarios. |
| OWASP Agentic AI Top 10 | AI-generated social engineering can scale and personalise multi-channel phishing. |
Include AI-assisted lure scenarios in testing and controls where automation changes attacker speed.
Related resources from NHI Mgmt Group
- What breaks when defenders focus only on phishing pages instead of token replay?
- What breaks when phishing targets Signal or WhatsApp accounts instead of email?
- What breaks when Microsoft Teams is used for phishing instead of email?
- What breaks when AppSec programs focus on findings instead of fixes?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org