Some users face more risk because they are targeted more often, receive more sophisticated attacks, or are more likely to click malicious content. When those patterns are visible, teams can connect exposure to specific controls instead of treating all users the same. That approach improves precision, reduces wasted effort, and helps security teams respond faster to the threats that matter most.
Why some users create more security risk in a people-centric attack model
People-centric risk is rarely uniform. Some users are exposed to more targeted phishing, business email compromise, or social engineering because of their role, authority, communication patterns, or access to sensitive workflows. Others are more likely to click because they are repeatedly targeted with better crafted lures. The useful question is not who is “careless”, but which users have a materially larger attack surface.
What makes exposure uneven across users
Attackers do not distribute effort evenly. They prioritize users who can approve payments, reset credentials, access customer data, or move laterally through core business systems. Those users often receive more convincing messages, more follow-up attempts, and more impersonation pressure, so their exposure is higher even when general security awareness is similar.
Behavior matters too, but not in a simplistic way. A user who clicks more often may be easier to trick, yet that same user may also sit in a low-impact role. By contrast, a cautious executive assistant or finance operator can be a high-value target because a single compromised message can open access to multiple people, workflows, or payments. The risk comes from the combination of exposure and potential consequence.
That is why people-centric models are strongest when they distinguish between likelihood and impact. A user who is frequently targeted is not always the most dangerous, and a user with the highest privilege is not always the most targeted. Security teams get better results when they score users by observed exposure, not by job title alone.
How to turn user differences into actionable controls
Once you can see which users face disproportionate pressure, you can tune controls more precisely. High-exposure groups may need stronger phishing-resistant authentication, tighter approval workflows, more restrictive email controls, or targeted verification for payment and account-change requests. Lower-exposure users may only need baseline controls and periodic reinforcement.
This is also where identity governance becomes practical. If certain users routinely receive higher-risk requests, their access paths, approval rights, and recovery processes should be easier to verify and harder to exploit. Zero Trust Identity Guide is useful here because it frames identity-centric policy as a way to reduce trust in the request itself, not just in the user receiving it.
Good teams also separate users by observed threat exposure and likely harm, then adjust controls accordingly. That makes awareness training more relevant, incident triage faster, and escalation decisions less subjective. It also avoids wasting strong controls on low-risk populations while leaving high-risk populations under-protected.
Risk and Threat Considerations
People-centric attack models are risky because the same weakness can have very different consequences depending on who is targeted. A successful social engineering attempt against a routine user may be contained, while the same technique against finance, HR, legal, or executive support can enable fraud, data exposure, or broader compromise. Attackers exploit that asymmetry by concentrating on users whose mistakes are most profitable.
Failure mechanism: Repeated targeting, realistic impersonation, and workflow abuse concentrate pressure on users with privileged influence, creating uneven exposure and a higher chance of credential theft, fraudulent approval, or account takeover.
Impact: Organisations can mis-rank risk, under-protect the users most likely to be targeted, and miss the point where a human mistake becomes a business-impacting security event.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and OWASP ASVS set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | Uneven user risk is reduced by limiting what targeted users can do. |
| IA-2 — Identification and Authentication (Organizational Users) | People-centric attacks often succeed by taking over user authentication paths. | |
| AU-6 — Audit Record Review, Analysis, and Reporting | User-level exposure is best detected through logs of targeted requests and suspicious actions. | |
| Recommendation — Apply AC-6 to shrink the damage a compromised user can cause. Strengthen IA-2 for users who face repeated phishing and impersonation attempts. Use AU-6 to identify which users are attracting the most hostile activity. | ||
| OWASP ASVS | V10 — OAuth and OIDC | Phishing-resistant and federated login choices matter when targeting is uneven across users. |
| V16 — Security Logging and Error Handling | User-targeted abuse is easier to prioritize when suspicious activity is logged consistently. | |
| Recommendation — Use V10 to harden authentication paths for high-exposure users. Apply V16 to preserve the evidence needed to spot user-specific attack pressure. | ||
Practitioner Guidance
What to verify: Confirm which user groups are actually receiving the most malicious mail, identity prompts, payment-change requests, and impersonation attempts. That exposure profile is more useful than a generic “high risk user” label.
Decision rule: If a user can approve funds, reset access, or trigger sensitive actions, treat that account as a higher-value attack target even when the person is otherwise security-aware.
What good looks like: High-risk users have tighter verification steps, fewer blind trust points, and faster escalation paths for suspicious requests, while the control set remains proportionate to the real attack pattern.
Practitioner takeaway: The goal is not to blame the user with the weakest click rate, but to match controls to the users whose exposure and blast radius are actually greatest.
Related resources from NHI Mgmt Group
- Why does a pipeline-centric security model create risk in regulated application environments?
- Why do some foundation models create more security risk than others in enterprise deployments?
- Why do non-human identities create more risk than many human accounts?
- Why do non-human identities create more remediation risk than many human accounts?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org