Join our Newsletter — 33% off our NHI Course
Governance, Ownership & Risk

VAPs

← Back to Glossary
By NHI Mgmt Group Updated September 27, 2026 Domain: Governance, Ownership & Risk

VAPs, or very attacked people, are users who face disproportionate targeting from phishing and account abuse. They often include executives, finance staff, and other high value roles with strong trust relationships or broad communication reach. Identifying them helps security teams focus controls, monitoring, and training where attacker attention is most concentrated.

What VAPs Mean in Security Operations

Very attacked people are not defined by job title alone. The useful signal is that they attract unusually frequent phishing, impersonation, and account abuse attempts because attackers expect higher access, faster response fatigue, or greater downstream reach.

That makes VAPs a targeting concept as much as a people concept. Security teams use it to focus attention on the accounts most likely to be probed, not to assume every senior person is automatically high risk in every environment.

How VAPs Differ from General High-Risk Users

VAPs sit inside a broader class of sensitive users, but the label specifically describes who is attracting active adversary attention. In practice, that may include executives, finance staff, assistants, M&A teams, HR leaders, admins, and anyone whose communications or approvals are worth impersonating.

The distinction matters because attack pressure is dynamic. A user can become a VAP temporarily during a transaction, public announcement, payroll cycle, board process, or vendor change, even if they are not normally treated as a special population.

Why VAPs Matter for Phishing and Account Abuse

Attackers prefer accounts that can unlock money movement, sensitive approvals, trusted relationships, or broader internal access. That is why VAPs often become the first targets for credential theft, mailbox compromise, business email compromise, and impersonation chains.

Security work around VAPs is therefore less about prestige and more about concentration of attacker effort. The objective is to recognize where the likely lure, pretext, and follow-on abuse will land so defenses can be tuned accordingly.

What Good VAP Identification Usually Changes

Once a user group is recognized as heavily targeted, the organization can raise scrutiny around authentication prompts, unusual inbox activity, approval anomalies, and lookalike sender behavior. It can also tailor awareness content to the lures that actually reach those users, rather than using generic training alone.

VAP handling should stay evidence-based and operational. A label is only useful if it improves detection, prioritization, and response for the accounts most likely to be abused.

Risk and Threat Considerations

VAPs concentrate adversary attention on a small set of users whose compromise can produce outsized business impact. The main risk is not status itself, but the combination of trust, access, and message reach that makes impersonation and account takeover more effective.

Failure mechanism: Attackers use reconnaissance, spoofing, credential theft, MFA fatigue, or mailbox compromise to exploit the trust placed in these users and then pivot into payments, approvals, internal fraud, or secondary account abuse.

Impact: Successful compromise can cause unauthorized transactions, sensitive disclosure, reputational harm, and broader compromise through trusted communication channels.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-05 — Multi-Factor AuthenticationVAPs are often targeted through account takeover attempts that MFA helps resist.
DE.CM-01 — Network and Host MonitoringVAP programs depend on watching for anomalous access and impersonation activity.
Recommendation — Require MFA for highly targeted users to reduce the success rate of phishing-driven account abuse. Monitor high-value user activity for unusual logins, inbox behavior, and approval anomalies.
CIS Controls v8CIS-5 — Account ManagementVAP handling centers on managing and reviewing the accounts most exposed to abuse.
Recommendation — Review and harden accounts that attract repeated phishing and impersonation attempts.
NIST SP 800-53 Rev 5IA-2 — Identification and Authentication (Organizational Users)VAPs are organizational users whose authentication is a primary control point under attack.
AU-6 — Audit Record Review, Analysis, and ReportingHigh-value user compromise is often detected through review of suspicious authentication and mailbox activity.
Recommendation — Strengthen authentication for users who are disproportionately targeted by phishing and account abuse. Triage audit data for signs of impersonation, token abuse, and suspicious approvals around VAPs.

Practitioner Guidance

What to watch for: Treat VAP status as a living operational signal, not a fixed title list. The most useful programs refresh the set when business context changes, then align monitoring and user protection to the current attack surface around those people.

Common misunderstanding: A VAP program is not a substitute for phishing-resistant controls or mailbox security. It is a prioritization layer that helps teams decide where stronger scrutiny, faster escalation, and closer monitoring will matter most.

Practitioner takeaway: If you can explain why a user is heavily targeted, you can usually explain which abuse paths deserve the earliest detection and the tightest response.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 27, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org