Join our Newsletter — 33% off our NHI Course
Home› FAQ› Threats, Abuse & Incident Response› What do security teams get wrong about testing…
Threats, Abuse & Incident Response

What do security teams get wrong about testing for spear-phishing and initial access campaigns?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 30, 2026 Domain: Threats, Abuse & Incident Response

Teams often test only the phishing click itself and miss what happens next. A useful assessment must also examine credential harvesting, post compromise access, and whether the environment allows attackers to pivot into internal resources. If the exercise stops at the inbox, it will underestimate real world risk and leave lateral movement paths untested.

Why a phishing test has to go past the inbox

A spear-phishing assessment is only useful when it measures the attacker’s full path, not just whether someone clicked. Real campaigns are designed to turn a single message into usable access, so the test should examine whether credentials can be captured, whether those credentials work, and whether a foothold can be converted into broader internal access. That is the difference between a mail exercise and a realistic initial access simulation.

Teams often overvalue click rates because they are easy to measure, but click-only results can hide the controls that matter most. A stronger assessment checks whether the landing page captures credentials, whether MFA or session controls stop reuse, and whether the exposed account can reach sensitive systems or management planes. That broader view is what reveals the real blast radius.

Another common mistake is treating initial access as the end state. In practice, compromise pressure shifts quickly from the first credential or session to internal discovery, persistence, and privilege expansion. A useful exercise asks what an attacker could do after the first successful login, not just whether the lure was convincing.

What a realistic initial access exercise should test

The assessment should cover the full chain from delivery to post-compromise action. That means testing whether a user can be induced to disclose credentials, whether those credentials can be replayed, whether access controls block lateral movement, and whether the environment exposes internal resources that make further compromise easy. JumpCloud breach 2023 is a useful reminder that initial access can become much more serious once trusted management paths or downstream access are available.

It should also test whether phishing can be escalated into a session, token, or consent problem rather than a password problem alone. Modern campaigns often abuse identity flows, not just passwords, so a test that ignores OAuth consent, token theft, or account recovery paths misses a large part of current attacker tradecraft. CoPhish OAuth phishing via Copilot Studio shows how social engineering can be used to capture tokens through a trusted-looking identity flow.

For remote access environments, the question is whether an initial credential or MFA event opens a path to VPN, VDI, or admin tooling that the attacker can then use for internal discovery. Remote Access Identity Guide is relevant here because the access boundary itself often becomes the real target, especially where dormant accounts, weak device posture checks, or overbroad remote access policies still exist.

How to judge whether the test is actually realistic

A realistic exercise should be judged by post-access evidence, not by whether the phishing email looked convincing. If the test does not verify credential reuse, token validity, internal reachability, privilege boundaries, and detection of suspicious follow-on activity, it is under-scoped. A click without usable access is a warning signal; a successful login with no lateral movement test is still incomplete.

The best exercises also reflect the attacker’s sequencing. A typical path is delivery, credential capture, access validation, internal discovery, and movement toward a higher-value system. If the scenario ends before the environment’s internal controls are tested, the result overstates defensive maturity and underestimates the harm a real intruder could cause.

Risk and Threat Considerations

Phishing tests that stop at user interaction create a false sense of resilience because they do not measure the controls that actually limit compromise. The risk is not just that a message works, but that one successful interaction becomes valid access that can be reused, expanded, or moved laterally.

Failure mechanism: Attackers use the lure to collect a password, token, session, or consent grant, then pivot into internal systems that the exercise never attempted to reach. If the environment accepts that access and the follow-on paths remain untested, the assessment misses the most important failure modes.

Impact: Security teams may understate real-world exposure, leave privilege boundaries unchallenged, and fail to find the exact internal paths an adversary would use after initial access. That gap can turn a low-severity phishing result into an unmeasured compromise pathway.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKT1566 — PhishingPhishing delivery is the initial access vector under test.
T1078 — Valid AccountsCredential capture and replay are central to post-phish access.
T1021 — Remote ServicesThe exercise must check whether stolen access can reach internal remote entry points.
Recommendation — Map lure delivery and user interaction to T1566 and validate detection of phishing attempts. Hunt for Valid Accounts abuse after phishing and validate alerts on unusual login use. Test whether phished access can reach remote services and trigger segmentation controls.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementPhishing tests should verify whether stolen credentials or tokens can be reused.
AC-4 — Information Flow EnforcementLateral movement and internal reachability depend on how flows are restricted after initial access.
Recommendation — Review authenticator lifecycle controls and rotate or revoke exposed credentials promptly. Enforce flow restrictions that block pivoting from a compromised user into internal resources.
CIS Controls v8CIS-6 — Access Control ManagementTesting should assess whether a phished account can obtain broader access than intended.
Recommendation — Limit access paths so a phished account cannot reach unnecessary systems or privileges.
NIST SP 800-63Digital Identity GuidelinesPhishing-resistant authentication and authenticator assurance are directly relevant to token and credential theft.
Recommendation — Adopt phishing-resistant authenticators for high-risk entry points and verify assurance strength.

Practitioner Guidance

What to prioritise: Test the post-click path first. A phishing exercise should prove whether stolen credentials, tokens, or approved sessions can actually reach valuable systems, because that is where the real defensive value is.

What to verify: Confirm whether the test checks replay resistance, MFA resilience, internal segmentation, and alerting on unusual follow-on activity. If the scenario cannot answer those questions, it is not yet a complete initial access assessment.

Common mistake: Treating click rate as the primary success metric. A lower click rate does not mean the organisation is well defended if a single successful phish can still open internal access paths.

Practitioner takeaway: Measure the attack path, not the lure. The point of spear-phishing testing is to learn whether one compromised interaction can become workable access, then broader compromise.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 30, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org