Join our Newsletter — 33% off our NHI Course
Home› FAQ› Threats, Abuse & Incident Response› Why does volume alone fail to measure real…
Threats, Abuse & Incident Response

Why does volume alone fail to measure real email risk to users?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 28, 2026 Domain: Threats, Abuse & Incident Response

Volume is a weak proxy because it ignores severity, intent, and attacker sophistication. Large numbers of low risk messages can hide a smaller number of highly targeted attempts that are far more dangerous. A better model evaluates who is targeted, what kind of threat is used, and how likely the attack is to produce compromise or financial loss.

Why volume is the wrong unit for email risk

Email risk is not just a question of how many messages arrive, it is a question of what those messages are trying to do. A mailbox can receive thousands of harmless or low-effort messages and still be far less exposed than a smaller inbox that is being probed by highly targeted phishing, impersonation, or business email compromise attempts.

Volume becomes misleading because it mixes together routine noise, opportunistic spam, and genuinely dangerous activity. From a user-safety perspective, a single convincing message from a well-resourced attacker can matter far more than a flood of generic junk.

What volume misses about targeting and attacker intent

To understand real email risk, you have to ask who is being targeted and why. Attackers often choose recipients based on role, access, authority, payment responsibility, or likelihood of responding under pressure. That means the same inbox volume can hide very different levels of exposure depending on whether the messages are random or precision-targeted.

Intent also changes the meaning of the traffic. A campaign designed to harvest credentials, redirect payments, or establish persistence is materially different from one that simply annoys users. The risk is not the count of messages, but the probability that one of them will cause a harmful action.

How to judge email risk more accurately

A better assessment looks at severity, delivery method, and likely outcome. Messages that imitate trusted brands, spoof internal executives, or use social engineering tailored to the recipient create a much higher chance of compromise than bulk spam that is easy to ignore.

Practitioners should evaluate email exposure across multiple dimensions, including recipient sensitivity, lure quality, brand abuse, and the potential impact if a user clicks, replies, or shares secrets. That produces a more realistic picture of whether a campaign is simply noisy or genuinely dangerous.

Risk and Threat Considerations

High message volume can hide low-frequency, high-impact threats, which is why mailbox metrics based only on counts often understate the true user risk. The most dangerous campaigns are usually the ones that are selective, believable, and aligned to a clear attacker objective such as credential theft, payment diversion, or account takeover.

Failure mechanism: Defenders treat aggregate volume as the primary signal, so targeted messages are lost inside the background of routine mail, and the attacker only needs one successful interaction to win.

Impact: Users may be tricked into revealing secrets, approving fraudulent actions, or enabling compromise of accounts and downstream business processes.

Practitioner Guidance

What to prioritise: Measure risk by recipient exposure and message credibility before you measure by raw inbox volume. Separate bulk spam from targeted phishing, impersonation, and business email compromise so the reporting reflects actual user danger.

What to verify: Check whether the mailbox population includes high-value roles, whether messages are tailored to those roles, and whether the campaign is trying to trigger a security decision, a payment action, or a credential submission.

What good looks like: Your email risk view can distinguish nuisance traffic from a small set of messages with outsized compromise potential, and your controls prioritise those high-severity cases first.

Practitioner takeaway: If the metric cannot tell you which messages are believable, targeted, and likely to cause harm, it is measuring workload, not risk.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 28, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org