They measure isolated activity, not actual exposure. A person who passes training can still hold excessive access, use unsanctioned tools, or be under active threat. Workforce risk profiling works better because it combines behaviour, identity context, and threat signals. That multidimensional view shows who is both vulnerable and high impact, which is what security teams need to prioritise action effectively.
Why This Matters for Security Teams
Standalone phishing scores and training completion rates are attractive because they are easy to report, but they rarely describe real exposure. A high score may reflect test familiarity, not resilience under pressure, while a completed course says nothing about privilege, device trust, or whether an account is already being targeted. Security teams can end up optimising for measurement rather than risk reduction.
That gap matters because phishing is often only one step in a wider intrusion path. Attackers combine social engineering with credential theft, session hijacking, and privilege abuse, so an apparently “well trained” workforce can still be a weak entry point if identities are over-permissioned or monitoring is thin. NIST’s broader identity guidance in NIST SP 800-63 Digital Identity Guidelines reinforces that assurance is not a single metric, but a set of controls and context signals. In practice, many security teams discover this only after a believable phishing lure has already been converted into account takeover, rather than through intentional risk prioritisation.
How It Works in Practice
Useful workforce risk profiling combines training, telemetry, and identity context into one operational picture. The point is not to discard awareness training, but to stop treating it as a proxy for security maturity. A practical model typically blends:
- phishing simulation outcomes and repeat susceptibility,
- identity data such as role, privilege level, access to sensitive systems, and recent access changes,
- endpoint and email telemetry, including suspicious logins, risky forwarding rules, and payload execution attempts,
- threat intelligence that shows whether the person or their business unit is being actively targeted,
- behavioural signals such as anomalous sign-in geography, impossible travel, or unusual app consent activity.
That approach is closer to how modern control frameworks think about risk. The CISA guidance on phishing-resistant authentication is useful here because it shifts attention from user memory to stronger authentication design, while the CIS Critical Security Controls emphasise practical safeguards such as access management, logging, and user awareness. Security teams should use completion rates as a hygiene metric, then weight them alongside exposure indicators to decide who needs targeted coaching, step-up authentication, or tighter access review. This is especially important where identity is the control plane, because an employee with low simulation scores but no privilege may be less urgent than a highly trained user with admin rights and active targeting. These controls tend to break down in large, decentralised environments because data is scattered across email, IAM, EDR, and HR systems, making correlation slow and inconsistent.
Common Variations and Edge Cases
Tighter measurement often increases operational overhead, requiring organisations to balance better prioritisation against data quality, privacy, and analyst workload. That tradeoff is real, and current guidance suggests there is no universal standard for weighting phishing metrics against identity and threat signals yet. Different environments need different thresholds.
For example, a small organisation may rely more heavily on training outcomes because it lacks mature telemetry, while a regulated enterprise should place more emphasis on access criticality, authentication strength, and active threat targeting. Mature programmes also avoid punishing users for factors outside their control, such as poor email filtering or inherited access sprawl. In identity-heavy environments, the more relevant question is often not “who clicked?” but “who clicked while holding privileged access, exposed data, or a compromised session?” That distinction is where workforce risk profiling becomes useful. It aligns more closely with NIST AI Risk Management Framework-style thinking about context, measurement, and continuous monitoring, even when the underlying problem is human rather than machine. The best programmes treat phishing scores as one signal among many, not as evidence that exposure has been reduced.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-63, NIST Zero Trust (SP 800-207) and NIST AI RMF set the technical controls, while NIS2 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RM | Risk measurement should inform prioritisation, not just compliance reporting. |
| NIST SP 800-63 | IAL/AAL/FAL | Identity assurance depends on authentication strength, not training alone. |
| NIST Zero Trust (SP 800-207) | PA/PE | Zero trust relies on continuous context, not static user trust signals. |
| NIST AI RMF | MEASURE | Risk scoring needs measurable inputs and clear limits on what each metric means. |
| NIS2 | Art. 21 | Operational security measures must be based on real risk, not superficial training evidence. |
Use governance and risk management to weight phishing results against actual exposure and business impact.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org