Join our Newsletter — 33% off our NHI Course
Home Glossary Governance, Ownership & Risk Very Attacked People
Governance, Ownership & Risk

Very Attacked People

← Back to Glossary
By NHI Mgmt Group Updated August 27, 2026 Domain: Governance, Ownership & Risk

Very Attacked People are users who face a higher-than-average volume of targeted threats because of their role, access, or visibility. The term helps security teams prioritise protection where the business risk is concentrated. It is used to focus monitoring, training, and response on people most likely to be targeted.

Expanded Definition

Very Attacked People is a risk-prioritisation term for humans whose role, access, or visibility attracts disproportionately frequent targeting. In NHI security and IAM practice, it is less about personal notoriety and more about attack concentration around executives, administrators, support staff with privileged workflows, and people who can approve, reset, or delegate access. The concept complements broader identity security because attackers often target the person to reach the account, secrets, or approval path behind it. Its usage is still evolving, so some teams treat it as a people-centric analogue to high-value identity protection rather than a formal security control category. For that reason, it should be used with explicit criteria such as privilege, exposure, and business impact, not informal popularity or guesswork. It aligns naturally with guidance in NIST SP 800-53 Rev 5 Security and Privacy Controls and the identity-centric risk themes in Ultimate Guide to NHIs — Why NHI Security Matters Now. The most common misapplication is treating every employee in a visible role as equally exposed, which occurs when security teams fail to distinguish privilege-bearing workflows from ordinary communications.

Examples and Use Cases

Implementing Very Attacked People rigorously often introduces monitoring and response overhead, requiring organisations to weigh focused protection against broader operational friction.

  • Executive assistants and finance approvers receive enhanced phishing monitoring because a successful impersonation can unlock payment approvals or vendor changes.
  • Cloud administrators are included in a high-risk people tier when their accounts can indirectly expose service credentials, tokens, or privileged automation paths, a pattern echoed in the 52 NHI Breaches Analysis.
  • Security operations staff are watched more closely because attackers may target them to suppress alerts, reset access, or harvest internal tooling details, consistent with adversary tradecraft tracked in the MITRE ATT&CK Enterprise Matrix.
  • Help desk personnel get extra verification steps for password resets and MFA changes because they are common social-engineering targets and can become an access gateway.
  • Researchers, public spokespeople, and vendor managers may be placed in this category when their contact details and approval authority are easy to find and abuse.

These use cases are strongest when tied to business process mapping, not assumptions about seniority alone.

Why It Matters in NHI Security

Very Attacked People matter because attackers rarely stop at the person; they use the person to reach accounts, secrets, delegated access, and non-human identities that power business operations. When teams under-protect these users, they create an efficient route into privileged workflows, including service account resets, API key exposure, and approval abuse. That is especially dangerous in environments where NHIs outnumber human identities by 25x to 50x and only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs — Key Challenges and Risks. The practical lesson is that people risk and NHI risk are often linked, not separate.

Security programs also need to account for adversaries who deliberately combine social engineering with identity abuse, as reflected in CISA cyber threat advisories and AI-enabled attack patterns discussed by Anthropic — first AI-orchestrated cyber espionage campaign report. Organisations typically encounter the full cost of this concept only after a phishing-led account takeover, at which point the Very Attacked People classification becomes operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-1Identity proofing and access management underpin protection for highly targeted users.
NIST SP 800-63Digital identity assurance informs stronger authentication for users with elevated exposure.
OWASP Non-Human Identity Top 10NHI-01Targeted users often expose the humans who can reach privileged NHIs and secrets.
NIST Zero Trust (SP 800-207)AC-1Zero Trust assumes breach and limits trust in users who are frequently targeted.
OWASP Agentic AI Top 10A1Targeted humans can be manipulated to grant tool access or approvals to agents.

Apply stronger authenticator and recovery assurance to users most likely to be impersonated.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org