Because click rate alone ignores access context. A user who clicks once may be low risk if they have limited permissions, while a user who clicks and holds privileged or sensitive access can represent a far greater threat. Risk programmes need to evaluate behaviour and entitlement together.
Why This Matters for Security Teams
Phishing simulation programmes are often treated as a simple behavioural scorecard, but that approach can hide the people who matter most. A click from a standard user is not the same as a click from someone with privileged admin access, finance permissions, or access to sensitive customer data. The real risk is not the click alone, but what the attacker can reach if that user is compromised.
That is why security teams should read simulation results alongside identity and entitlement data, not in isolation. A useful programme should help answer who clicked, what access they had, whether their account could be used to escalate, and whether the event exposed a meaningful path to data theft or system disruption. The NIST Cybersecurity Framework 2.0 reinforces this broader view by tying awareness, access control, and risk management into a single operational model.
In practice, many security teams discover the highest-risk employees only after a simulation click is followed by a real account takeover, rather than through intentional risk-based scoring.
How It Works in Practice
Effective phishing measurement starts by joining simulation telemetry with identity context. That means linking click, credential submission, and reporting behaviour to role, privilege level, authentication strength, data access, and downstream system reach. Once those signals are combined, the programme can identify employees whose behaviour creates materially different exposure even if their click frequency is similar to everyone else’s.
Practically, this often means building tiers such as:
- high-impact users with administrative, financial, legal, or operational control
- users with access to sensitive data, production environments, or approval workflows
- users whose compromise could enable lateral movement or social engineering of others
- users who frequently interact with external mail, files, or vendor workflows
Security leaders should also separate raw susceptibility from control effectiveness. A person who clicks but immediately reports the message may be less concerning than someone who repeatedly clicks, reuses credentials, or works in an environment where MFA fatigue, weak conditional access, or poor segmentation increases blast radius. This is where NIST SP 800-53 Rev 5 Security and Privacy Controls is useful, because awareness, access enforcement, auditing, and incident response should be designed as linked controls rather than separate programmes.
A practical model scores employees by combining behaviour with exposure: simulation outcome, privilege level, sensitivity of systems accessed, and the presence of compensating controls such as phishing-resistant MFA or just-in-time privilege. That gives defenders a better way to prioritise coaching, restrictions, and monitoring than click rate alone. These controls tend to break down in highly decentralised organisations where access reviews are stale, identity data is fragmented across platforms, and simulation tools cannot reliably map users to real permissions.
Common Variations and Edge Cases
Tighter risk scoring often increases operational overhead, requiring organisations to balance better targeting against data quality and administrative effort. Best practice is evolving here, and there is no universal standard for how to weight behaviour versus entitlement, especially across different business units.
Some environments should give heavier weight to access context. For example, a small number of contractors may have elevated production access, while a larger employee group may have little authority but frequent exposure to phishing because of customer-facing work. In regulated or high-availability environments, a single compromised admin or approver can be more important than dozens of low-privilege users who click.
Edge cases also matter. Simulation metrics can understate risk when users share accounts, when service desks reset passwords too easily, or when the real danger is token theft rather than credential entry. They can overstate risk when staff are in training-heavy departments that receive more simulations but have limited access to sensitive systems. In those cases, programmes should compare simulation results with account privileges, endpoint posture, and incident history rather than treating performance scores as a standalone measure.
That approach aligns with identity-aware security practices and helps surface the employees whose compromise would create the largest operational impact, not just the highest training failure rate. For teams building a more mature control set, the main question is no longer who clicked, but who clicked and could actually be used to do damage.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST AI RMF and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA-01 | Identity and access context should inform phishing risk prioritisation. |
| NIST AI RMF | Risk scoring should combine multiple signals, not a single behavioral metric. | |
| NIST SP 800-53 Rev 5 | AT-2 | Awareness training is relevant because simulation results should drive targeted training. |
Tie simulation outcomes to access exposure so higher privilege users get more scrutiny.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 21, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org