Join our Newsletter — 33% off our NHI Course
Home Glossary Governance, Ownership & Risk Very Attacked People
Governance, Ownership & Risk

Very Attacked People

← Back to Glossary
By NHI Mgmt Group Updated September 7, 2026 Domain: Governance, Ownership & Risk

Very Attacked People are users who face a higher-than-average volume of targeted threats because of their role, access, or visibility. The term helps security teams prioritise protection where the business risk is concentrated. It is used to focus monitoring, training, and response on people most likely to be targeted.

Expanded Definition

Very Attacked People refers to individuals whose roles, visibility, or access make them disproportionately attractive to phishing, social engineering, account takeover, and impersonation attempts. In practice, the term is about exposure concentration, not prestige: executives, finance staff, help desk teams, recruiters, privileged administrators, and employees with external-facing authority often sit at the centre of targeted abuse.

The concept is narrower than a general user-risk category because it focuses on users likely to be singled out rather than everyone who may be attacked. It is also different from pure privilege management, because the threat can arise from reputation, influence, or delegated trust even when the person is not highly privileged. NHI Management Group treats this as an operational prioritisation term: it helps security teams decide where stronger monitoring, tighter identity checks, and faster response matter most.

A common boundary mistake is to assume the label only applies to senior leadership. In reality, any role that can approve payments, reset credentials, publish authoritative messages, or approve access can become a high-value target.

Examples and Use Cases

Very Attacked People shows up wherever attackers can profit from targeting a person rather than a system. Security teams use the concept to concentrate controls on users whose compromise would likely be immediately useful to an adversary.

  • An executive receives highly tailored phishing that references current projects, travel, or public statements.
  • A finance approver is targeted with invoice fraud or payment redirection because their decisions can move money quickly.
  • A help desk analyst is impersonated so an attacker can request a password reset or MFA change.
  • A recruiter or HR user is used as an entry point because they handle large volumes of external communication and identity data.
  • A privileged administrator is targeted with credential theft because one successful login can expose many downstream systems.

There is a practical tradeoff here: the more visible a role is, the harder it becomes to remove all exposure through training alone. That is why the term is usually paired with stronger identity verification, step-up approval, and tighter monitoring for high-impact actions. For broader adversary context, MITRE ATT&CK Enterprise Matrix helps readers connect these targeting patterns to real attack techniques.

Security Implications

Misclassifying Very Attacked People as ordinary users creates an uneven defense posture. The most likely outcome is not a dramatic breach on day one, but repeated exposure to credential harvesting, impersonation, business email compromise, consent abuse, or fraudulent approval flows. Once a targeted user is tricked, the attacker often inherits legitimate trust rather than forcing a noisy exploit.

That makes the failure mode especially dangerous in environments where identity actions are powerful. A compromised approver can authorise payments, a compromised assistant can expose schedules and contacts, and a compromised support user can become the shortest path to account recovery abuse. The observable symptom is often a pattern of persistent, well-crafted messages that look routine until the final action request arrives.

Practitioners should pay attention when targeting is recurrent and role-specific, because that usually signals a concentration of trust and decision-making power. Where the adversary can exploit current events, public profiles, or delegated authority, the user becomes a durable attack surface rather than a one-time victim.

Domain and Governance Relevance

In identity and access governance, Very Attacked People is a prioritisation lens for where extra friction is justified. It supports decisions about stronger authentication, tighter approval paths, targeted awareness, and more aggressive monitoring of sensitive actions. The point is not to treat every person as equally risky, but to recognise that some users are repeatedly used as entry points because they sit at trust boundaries.

The term also matters for NHI-adjacent governance when human users control service accounts, secrets, delegated access, or recovery workflows. In those cases, the person is effectively part of the trust chain for non-human identities and automated systems. A weak human recovery path can therefore undermine machine identity assurance, even if the original target was a person rather than an NHI.

For operational intelligence on active targeting trends, readers can also consult CISA cyber threat advisories when they want current attacker patterns that often affect high-value users.

Risk and Threat Considerations

Very Attacked People create a concentrated exposure problem: attackers do not need to compromise the whole workforce if they can reliably identify and target the few users whose decisions, trust, or access unlock more valuable paths. The risk increases when these users can approve payments, reset credentials, authorise access, or speak with organisational authority.

Failure mechanism: Adversaries abuse social trust, impersonation, and credential theft against the most targeted users, then convert that access into account recovery abuse, business email compromise, fraud, or lateral movement through trusted workflows.

Impact: The result can be financial loss, unauthorised access, misuse of delegated authority, exposure of sensitive communications, and a broader collapse in confidence around identity-based approvals.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK and OWASP Non-Human Identity Top 10 address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKT1566 — PhishingTargeted social engineering is the core threat pattern behind VAP.
T1078 — Valid AccountsCompromise of high-value users often yields legitimate access paths.
Recommendation — Map targeted-user lures to T1566 and tune detections for role-specific phishing indicators. Hunt for abnormal use of valid accounts when targeted users receive suspicious access attempts.
CIS Controls v86 — Access Control ManagementVAP programs need tighter access and approval paths for high-risk users.
14 — Security Awareness and Skills TrainingRole-tailored training is a direct control for targeted-user exposure.
Recommendation — Apply CIS Control 6 to harden access and approval workflows for heavily targeted roles. Use CIS Control 14 to deliver role-specific phishing and impersonation training to targeted users.
NIST CSF 2.0PR.AA — Identity Management, Authentication and Access ControlThe term centers on identity assurance for users likely to be abused.
DE.CM — Security Continuous MonitoringHigh-value users need closer monitoring for suspicious authentication and email activity.
Recommendation — Strengthen PR.AA controls for users whose identities are repeatedly targeted for abuse. Increase DE.CM monitoring on accounts with elevated targeting risk and sensitive action rights.
OWASP Non-Human Identity Top 10NHI-01 — Inventory and OwnershipWhen targeted users control secrets or recovery, their role becomes part of NHI governance.
Recommendation — Inventory human owners of sensitive non-human identities and assign explicit accountability.

Practitioner Guidance

Why practitioners should care: This term is useful because it tells security teams where standard controls are least likely to be enough on their own. The same training programme, authentication policy, or alert threshold rarely fits both a routine employee and a role that is repeatedly singled out for attack.

Common misunderstanding: “Very attacked” does not always mean “most senior.” A travel coordinator, support agent, recruiter, assistant, or finance approver may face more targeting than an executive if the role offers a more practical path into trust or transactions.

Practitioner takeaway: Treat the label as a dynamic risk signal, not a fixed job title, and revisit it whenever a role gains visibility, approval power, or recovery authority.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 7, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org