Phishing and business email compromise still work because awareness alone does not stop urgency, convenience, and habit from driving decisions. The report shows that many users knowingly take risky actions even when they understand the danger. Attackers exploit that gap by creating pressure, impersonation, and time-sensitive prompts that override careful verification.
Why awareness does not stop the click
Phishing and business email compromise succeed because “knowing the risk” is not the same as interrupting the decision in the moment. Users often act under time pressure, social pressure, or routine habit, which means the attacker only needs one short lapse in verification. The real failure is not ignorance alone, it is a predictable gap between understanding and action.
That gap matters because many phishing flows are designed to feel operationally normal. A message that appears to be from a manager, vendor, or finance contact can fit existing work patterns, so the user does not experience the request as unusual enough to slow down and validate it.
How attackers make risky actions feel reasonable
Attackers typically do not rely on a single trick. They combine impersonation, urgency, and a believable business context so the request seems like something that should be handled quickly. The more the message resembles an ordinary workflow, the more likely the user is to bypass careful checking and follow the path of least resistance.
Business email compromise is especially effective because it exploits trust relationships that already exist inside the organisation. If the sender looks like a known executive, finance partner, or supplier, the request inherits credibility from the relationship itself. That is why verification failures often happen even when users are generally aware that phishing exists.
Attackers also count on habit. People are trained to keep work moving, answer quickly, and avoid creating friction for colleagues. In practice, those social norms can be stronger than abstract security knowledge, especially when the request is framed as urgent, confidential, or routine.
What changes when verification is built into the workflow
Awareness works best when it is paired with controls that slow down risky decisions and make verification easy to perform. The most effective defences reduce ambiguity at the point of action: confirm payment changes through a separate channel, challenge unexpected login prompts, and require users to check sender identity before acting on instructions that change money, credentials, or access.
One useful test is whether the control changes behaviour when the user is busy, distracted, or pressured. If the answer depends on perfect attention or memory, it is fragile. Controls that embed verification into normal work, such as secure request channels, out-of-band confirmation, or stronger email authentication and filtering, are harder for attackers to bypass because they reduce the need for users to make the right judgement under stress. For email-authentication guidance, NIST SP 800-63 Digital Identity Guidelines is useful for understanding phishing-resistant authentication choices, and NIST SP 800-53 Rev 5 Security and Privacy Controls gives the broader control context around authentication, audit, and access governance.
Risk and Threat Considerations
The risk is not simply that a user may misread a message, it is that one hurried decision can authorise payment, expose credentials, or open the door to broader compromise. BEC is especially dangerous because the attacker is not always looking for malware execution, they are often looking for a legitimate-looking business action that the user is willing to complete.
Failure mechanism: The attacker creates a high-pressure, low-verification situation that makes the safe option feel slower or socially awkward than the risky one.
Impact: A single approved action can lead to financial loss, mailbox takeover, credential reuse, or downstream access to sensitive systems and correspondence.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | Phishing and BEC exploit weak user authentication and verification decisions. |
| AU-6 — Audit Review, Analysis, and Reporting | Detection of BEC depends on reviewing suspicious account and message activity. | |
| SC-23 — Session Authenticity | Phishing often abuses trusted sessions and lookalike prompts to mislead users. | |
| Recommendation — Require stronger user authentication for high-risk actions and sensitive access requests. Review audit signals for anomalous email access and risky approval activity. Validate session authenticity before trusting requests that change access or payments. | ||
| NIST CSF 2.0 | PR.AA-05 — Identity and Access Management | Phishing resistance and access verification are central to preventing user-driven compromise. |
| Recommendation — Strengthen identity controls for high-impact actions and sensitive workflows. | ||
| CIS Controls v8 | CIS-5 — Account Management | BEC often succeeds through abused accounts and weak account lifecycle controls. |
| Recommendation — Harden account lifecycle and restrict high-risk account actions. | ||
Practitioner Guidance
What to verify: Do not measure success by quiz scores or awareness training completion alone. Verify whether users have a separate, reliable habit for high-risk actions such as payment changes, password resets, and requests that involve credentials or urgency. If that habit does not exist, the organisation is still exposed even when awareness is high.
What good looks like: Users pause on unexpected requests, confirm through a second channel, and escalate anything that asks for secrecy, urgency, or process exceptions. The goal is not perfect suspicion, it is a repeatable verification behaviour that survives time pressure and routine.
Practitioner takeaway: Awareness reduces susceptibility, but only workflow friction, authentication strength, and verification habits reliably stop the attacker from turning human judgement into an approved action.
Related resources from NHI Mgmt Group
- Why do phishing, vishing, smishing, and email compromise attacks still succeed against trained users?
- Why do AI-driven phishing attacks still succeed when organisations use modern authentication?
- Why do phishing attacks still succeed even when people know the warning signs?
- Why do phishing attacks still succeed in well-defended environments?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org