Join our Newsletter — 33% off our NHI Course
Home FAQ Threats, Abuse & Incident Response Why do spearphishing attacks work so well against…
Threats, Abuse & Incident Response

Why do spearphishing attacks work so well against organisations that already have email filters and security training?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 17, 2026 Domain: Threats, Abuse & Incident Response

They work because attackers do not need to defeat every technical control. They only need to hijack trust in a familiar sender or context, then persuade a person to take the next unsafe step. Training helps, but if it stops at recognition and does not build verification habits and escalation paths, the attack can still succeed.

Why spearphishing still succeeds after filters and awareness training

Email filtering is a useful barrier, but it only blocks part of the attack path. Spearphishing works when the message is convincing enough to bypass suspicion, lands in the right context, and pushes the target toward a human decision, such as opening a file, approving a login, or continuing a conversation outside email controls.

That is why the attack is less about “beating email security” and more about exploiting trust. The attacker only needs one person, one moment, and one unsafe follow-through.

Training also has limits when it is focused on recognition alone. People may spot obvious spam yet still trust a familiar brand, a senior executive, a supplier, or a routine workflow. Without verification habits, a known escalation path, and explicit permission to pause or validate, awareness does not reliably interrupt the attack.

Where the control gap really sits

The common failure is not that organisations have no controls, it is that the controls are fragmented across different decision points. Filters inspect message content, but the real risk often appears after the email is read, when the user is asked to reset credentials, approve a transfer, share a document, or sign in through a lookalike portal.

That is why The 52 NHI breaches Report is useful as a broader reminder that attackers often exploit trust relationships and credentials rather than defeating perimeter controls outright. The same principle applies to human-targeted phishing: if the message reaches a believable context, the attacker can move the victim into an unsafe action even after the inbox is filtered.

Security training is strongest when it reinforces behaviour under pressure, not just recognition of bad tells. The hard part is verifying requests that look legitimate, especially when the message exploits urgency, authority, or routine business processes. In practice, the “last mile” of defense is usually a person deciding whether to trust the request, not the mail gateway deciding whether the message is clean.

What practitioners should strengthen beyond email filtering

SANS Security Resources is a practical reference point for the operational side of this problem: detection, response, and user-facing decision support matter as much as prevention. Organisations should make it easy for users to validate unusual requests through a separate channel, and they should make escalation normal rather than exceptional.

Two habits matter most:

  • Require out-of-band verification for money movement, credential resets, and access changes, especially when urgency is part of the request.
  • Design reporting paths so users can forward suspicious messages or ask for help without fear of blame or delay.

Practitioner takeaway: Spearphishing remains effective because it targets trust and follow-through, not just inbox hygiene. The strongest programs pair filtering with process controls, easy verification, and a culture that rewards pausing before acting.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AT-1 — Awareness and TrainingUser training directly affects phishing resistance and verification behaviour.
PR.AC-1 — Identity Management, Authentication, and Access ControlPhishing often succeeds by stealing or abusing access pathways.
DE.CM-8 — Monitoring for Unauthorized Personnel, Connections, Devices, and SoftwarePhishing campaigns often surface through anomalous logins and suspicious activity.
Recommendation — Train users to verify requests through separate channels before taking action. Tighten access paths so suspicious requests cannot directly trigger privileged actions. Monitor for unusual sign-ins and message-linked access anomalies.
CIS Controls v88 — Audit Log ManagementSuspicious authentication and mailbox activity must be visible after a phishing attempt.
14 — Security Awareness and Skills TrainingThe question explicitly concerns why training alone does not stop spearphishing.
Recommendation — Centralise logs so phishing-related access and forwarding activity can be investigated quickly. Teach users to validate requests and report suspected phishing immediately.
MITRE ATT&CKT1566 — PhishingSpearphishing is a phishing technique that leverages social engineering and trust.
Recommendation — Map phishing attempts to T1566 and tune detections for delivery and follow-on abuse.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 17, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org