Spear Phishing Risk Assessment: A 3-Phase Framework to Measure and Reduce Human Risk Across People, Technology, and Processes

Key takeaways
- A spear phishing risk assessment measures exposure, likelihood, control strength, and business impact across people, technology, and processes rather than scoring one simulated click.
- Targeted deception defeats organizations that pass generic phishing tests, because a credible pretext arrives through a trusted identity and a familiar workflow.
- A three-phase spear phishing risk assessment maps exposure, validates controls under pressure, and converts findings into scored, owned, deadline-bound remediation.
- Separating inherent risk from residual risk shows which safeguards interrupt a targeted cyberattack and which merely produce a policy document.
- Processes that move money, grant access, or release regulated data deserve the strictest verification controls a spear phishing risk assessment can specify.
- Multi-channel cybersecurity awareness training turns assessment findings into rehearsed verification behavior across email, voice, SMS, and video.
- Reassessment after acquisitions, executive turnover, identity migrations, and payment changes keeps the spear phishing risk assessment aligned with actual exposure.
Targeted deception rarely fails because an organization lacks a security policy. It fails because a finance approver, an executive assistant, or a help desk agent receives a request that fits the day's work, arrives from a name they recognize, and carries just enough urgency to skip an independent check. Filters, authentication, and annual courses all pass their audits while that single decision moves money out of the building.

According to the FBI Internet Crime Complaint Center's 2025 Internet Crime Report, internet crime drove $20.877 billion in reported losses, a 26% jump over the prior year. Losses at that scale accumulate one approved request at a time, which is why measuring targeted deception requires more than a click-rate dashboard.
A spear phishing risk assessment answers a harder question: which attack paths remain open across people, technology, and processes, and what would each one cost if a trusted request reached the person who could act on it.
This guide covers:
- How a spear phishing risk assessment differs from a phishing test, a vulnerability scan, and an annual course;
- How a targeted cyberattack progresses from reconnaissance to business impact, and where each phase becomes testable;
- A three-phase method for mapping exposure, validating controls, and assigning scored remediation;
- A scoring model that separates inherent risk from residual risk across people, technology, and process ratings;
- How to validate email, identity, and access controls with evidence rather than configuration screenshots;
- How to test susceptibility safely, measure resilience, and convert findings into cybersecurity awareness training that changes behavior.
Targeted deception reaches trusted finance and executive staff long before an email filter flags anything unusual. Adaptive Security measures that exposure across email, voice, SMS, and identity workflows.
What Is a Spear Phishing Risk Assessment and Why Does It Matter?
A spear phishing risk assessment is a structured evaluation of an organization's exposure to targeted deception, the likelihood of a successful cyberattack, the strength of its technical and human controls, the business impact of compromise, and its remaining residual risk. It identifies realistic attack paths and shows which people and processes cyberattackers are most likely to exploit. It then turns those findings into a prioritized remediation plan covering the full chain from reconnaissance through employee action, unauthorized access, fraud, data loss, and recovery.
What Does a Spear Phishing Risk Assessment Cover?
A spear phishing risk assessment measures whether a targeted social engineering cyberattack can move through an organization and produce a material business outcome. The assessment starts with exposure, including publicly available employee information, executive communications, supplier relationships, payment workflows, cloud applications, remote access methods, and approval processes. This open-source intelligence (OSINT) review shows what a cyberattacker can learn before sending a message and which details make a pretext credible.
Likelihood comes next. The assessment examines who would be targeted, which communication channel would be most persuasive, what request would trigger action, and how much access the targeted person controls. A finance employee who can change vendor bank details presents a different spear phishing risk than an employee with no payment authority, so the assessment evaluates roles and processes rather than inboxes alone.
Control strength forms the third layer. Technical controls include multifactor authentication, email authentication, access restrictions, payment verification, conditional access, reporting mechanisms, and monitoring. Human controls cover whether employees recognize suspicious requests, pause when urgency is manufactured, verify instructions through a trusted channel, and report messages quickly.
A control earns credit only when it works under realistic pressure. According to Verizon's 2026 Data Breach Investigations Report, 62% of confirmed breaches involve a human element, a figure that has risen year over year. A documented policy that employees cannot recall during a rushed wire request is not an effective operational control.
Business impact completes the analysis. The assessor estimates what happens if a cyberattacker captures credentials, changes a supplier account, exposes confidential information, convinces an employee to approve a payment, or uses one compromised account to reach another system. Impact should include direct financial loss, operational interruption, regulatory exposure, legal costs, and executive decision-making time.
The resulting risk rating combines likelihood and impact while accounting for the controls already in place. The 2025 CISA advisory on targeted phishing activity describes cyberattackers using tailored techniques and recommends mitigations involving identity, access, monitoring, and user behavior. A spear phishing assessment must therefore test the relationships between people, processes, and technology instead of treating phishing as an isolated email problem.
How Is Spear Phishing Risk Different From Ordinary Phishing Risk?
Ordinary phishing sends broad messages to many recipients, relying on volume, recognizable lures, and predictable behavior. Spear phishing is narrower and more deliberate, because the cyberattacker selects a person or small group, researches their responsibilities, and builds a message around information that appears relevant to their work. Personalization increases credibility because the request fits the recipient's role, timing, relationships, or current business activity.
That distinction matters because an organization can perform well against generic phishing and remain exposed to targeted fraud. An employee might reject an email with a suspicious subject line yet trust a message that references a real vendor, an active project, or a legitimate executive meeting. Targeted cyberattacks also reduce observable warning signals, since a message can use correct grammar, a familiar signature, and a plausible request while directing the recipient toward credential theft or an unauthorized payment.
The volume behind that risk is substantial. According to the FBI Internet Crime Complaint Center's 2025 Internet Crime Report, phishing and spoofing generated 191,561 complaints, the highest number of reports in any category. Several related terms describe the more targeted end of that activity:
- Spear phishing: A targeted message aimed at a specific individual or team to steal credentials, deliver malware, obtain sensitive information, or induce a high-value action;
- Whaling: Spear phishing directed at senior leaders, where the cyberattacker targets authority, access, and decision-making power rather than a broad employee population;
- CEO fraud: A deception in which a cyberattacker impersonates a senior leader and pressures an employee to transfer money, disclose information, or bypass an approval process through email, text, voice, or video;
- Vendor email compromise: A targeted cyberattack impersonating a supplier, contractor, or other trusted business partner, usually requesting a payment-instruction change, an invoice review, or account information;
- Business email compromise (BEC): A broader fraud category using compromised or impersonated business accounts to manipulate payments, payroll, procurement, or data access, often entered through spear phishing.
These categories overlap, although they should not be collapsed into one measurement. A general phishing test usually records whether employees click or submit credentials, while a spear phishing risk assessment measures whether the organization can distinguish a legitimate-looking request from a dangerous one. It also measures whether business processes stop an incorrect action after the message reaches a trusted employee.
That difference changes testing priorities. A broad test might send a simulated login page to a representative sample of employees, whereas a targeted assessment examines finance approval chains, executive support workflows, procurement contacts, help desk identity checks, and supplier-change procedures. The central question is whether a cyberattacker can combine several small facts into one convincing pretext and whether the organization has a reliable way to interrupt it.
What Is a Spear Phishing Risk Assessment Not?
A spear phishing risk assessment is not a single phishing test. A test provides a point-in-time signal such as click rate, credential submission rate, or report rate. Those measures are useful, yet they do not reveal whether a high-risk payment process can be manipulated or whether an employee can detect a multistep cyberattack spanning email, phone, and messaging platforms.
It is not a vulnerability scan. Vulnerability scanning identifies technical weaknesses such as missing patches or insecure configurations, while spear phishing assessments examine how cyberattackers use information, trust, authority, and business workflows. A fully patched device does not stop an employee from approving a fraudulent bank-account change.
It is not a penetration test either. Penetration testing evaluates whether an authorized tester can exploit technical or physical weaknesses within a defined scope, whereas a spear phishing risk assessment focuses on human decision points and business controls. Its findings can still identify technical control gaps that require a separate penetration test or engineering review.
It is not an annual course. A course confirms that content was assigned or completed, while an assessment tests whether employees apply the skill when a realistic request creates time pressure or appears to come from a trusted person. Completion is an activity measure, and reduced susceptibility, faster reporting, stronger verification, and fewer process exceptions are the risk measures that matter.
It is also not an exercise in blaming employees. Employees provide the organization's most important detection and reporting signal when they receive practical cybersecurity awareness training, realistic practice, and clear escalation paths. The assessment should evaluate whether the organization has made the safe action easy, visible, and operationally supported.
What Outcomes Should a Spear Phishing Risk Assessment Produce?
A useful assessment ends with decisions instead of a score alone. Its primary output is a prioritized map of attack paths showing how an adversary could move from public information to a targeted request and then to financial loss, credential compromise, or sensitive-data exposure. Each path should identify the target role, pretext, channel, required employee action, existing control, control failure, and likely business consequence.
Social engineering earns that attention on its own merits. According to Verizon's 2026 Data Breach Investigations Report, social engineering ranked as the third most common breach pattern, representing 16% of all breaches. A spear phishing risk assessment should convert that pattern into five concrete outcomes:
- A ranked exposure profile. Identify executives, finance personnel, administrators, privileged users, and supplier contacts whose access or public exposure creates elevated risk.
- A control validation record. Confirm whether email controls, multifactor authentication, reporting workflows, payment verification, and manager escalation work under realistic conditions.
- A human-risk baseline. Measure engagement with targeted phishing simulations, reporting speed, and verification behavior without shaming employees for an unsuccessful attempt.
- A remediation backlog. Assign each finding an owner, priority, deadline, and expected risk reduction, giving payment and identity workflows precedence over low-consequence awareness gaps.
- A retest plan. Repeat the relevant scenario after remediation to determine whether the control changed behavior or merely produced a new policy document.
The strongest assessment also separates residual risk from eliminated risk. No assessment proves that an organization cannot be deceived; it shows which attack paths remain plausible, which safeguards interrupt them, and where additional investment will produce the greatest reduction in exposure. Phishing simulations covering targeted email, BEC, and vendor impersonation supply behavioral evidence when they are tied to role-specific attack paths and followed by focused remediation.
That evidence turns a broad concern about targeted deception into specific decisions about people, processes, controls, and the points where intervention prevents a trusted request from becoming a costly business event.
Click-rate dashboards say nothing about whether a payment approval workflow can be manipulated by a single trusted-looking request. Adaptive Security connects observed behavior to real business consequences.
How Does a Spear Phishing Cyberattack Progress From Reconnaissance to Exploitation?
A spear phishing risk assessment should trace a cyberattack from public-data collection through delivery, interaction, compromise, persistence, and business impact. Each phase maps to a control, an owner, and a measurable test, rehearsed across email, SMS, voice, social platforms, and trusted accounts. AI-generated content, deepfakes, stolen session tokens, and hybrid cyberattacks change the shape of that path rather than forming separate cyber threats that existing controls automatically cover.
1. Identify Reconnaissance and Personalization Controls
Reconnaissance opens a spear phishing cyberattack because the adversary must identify whom to target, what that person can authorize, and which details make a request credible. Public websites, professional profiles, conference videos, job postings, and breached credentials create open-source intelligence (OSINT) revealing reporting lines, travel schedules, suppliers, and approval workflows.
Record what a cyberattacker can learn without touching internal systems. Review executive biographies, finance responsibilities, vendor relationships, and exposed email addresses, then ask whether an outsider could infer a high-value process such as changing payroll details, approving an invoice, or releasing a confidential document.
The control is broader than removing information from the internet. Organizations should reduce unnecessary exposure, monitor high-risk identities, and train employees to treat personalized context as a reason to verify.
Target selection follows data collection. Cyberattackers choose people who control money, credentials, or access to a more valuable colleague, so a finance employee who processes wires, an executive assistant with calendar access, and an IT administrator who handles resets each require different scenarios.
Map each role to its authority, dependencies, communication channels, and highest-consequence actions. Personalization turns those facts into a pretext referencing a current acquisition, a supplier renewal, or a conference trip.
Generative AI accelerates this stage by producing fluent, correctly formatted messages without the grammar errors that once signaled phishing. It can also imitate a person's writing style and response patterns, shifting the control from proofreading for mistakes to validating the request, sender identity, and context.
An effective test measures whether a person pauses when a familiar request arrives through an unfamiliar path. Multi-channel phishing simulations rehearse the same pretext across email, SMS, voice, and video with safe, role-specific scenarios, so employees practice recognition under pressure.
2. Test Delivery and Identity-Based Deception
Delivery is the point at which the pretext reaches the target, and it extends well beyond an email inbox. A cyberattacker can send a phishing email, a smishing message, a vishing call, a social-platform direct message, or an invitation from a compromised trusted account.
A stolen vendor mailbox, hijacked executive account, or breached partner account bypasses normal suspicion because the visible identity belongs to someone the recipient knows. The assessment should therefore test the channel and the identity signal together.
- Email: Examine display-name spoofing, lookalike domains, reply-chain abuse, and compromised accounts;
- SMS: Test shortened links, delivery notices, and urgent authentication prompts;
- Voice: Assess whether employees verify callback numbers and high-risk instructions when a caller sounds familiar;
- Social platforms: Examine whether staff accept file transfers, meeting invitations, or connection requests based on a known name alone.
Deepfake video and AI voice cloning remove another traditional assumption, because seeing and hearing a trusted person no longer proves that the person initiated the request. In 2024, a finance employee at Arup approved roughly $25 million after a video call in which the other participants were reportedly deepfakes, according to The Guardian's 2024 report. Payment changes, sensitive disclosures, and privileged-account actions therefore require independent verification through a known contact method instead of details supplied inside the message.
The attempted impersonation of Ukraine's former foreign minister in a video call with U.S. Sen. Ben Cardin shows how a hybrid cyberattack can move from email to live video. NBC News' 2024 account reported that an email introduced the contact, a video call appeared consistent with prior encounters, and unusual questions eventually exposed the deception.
Assessments should test whether employees verify meeting requests before joining, challenge out-of-character behavior, and end a conversation when an ordinary request shifts toward sensitive action. Familiarity is a signal to investigate, never permission to comply.
Delivery controls also depend on identity infrastructure. OAuth consent phishing persuades a user to authorize a malicious application without surrendering a password, while MFA fatigue sends repeated prompts until a user accepts one to stop the interruption.
An adversary-in-the-middle cyberattack places a phishing site between the employee and the legitimate service, relaying credentials and session data in real time. CISA's 2025 guidance on phishing-resistant MFA identifies FIDO2 and WebAuthn-based authentication as controls built to resist phishing and credential relay.
The assessment must test the decision alongside the technology. Measure whether employees deny unexpected prompts, reject unreviewed OAuth applications, and use a verified channel for urgent requests. Security teams should also review application-consent policies, session protections, and privileged-access paths so one interaction does not immediately become an account takeover.
3. Trace Exploitation Through Business Impact and Cleanup

Exploitation begins when the target interacts with the lure. That interaction can be a link click, an attachment opening, an OAuth approval, an MFA acceptance, or a conversation revealing internal details. The visible action is often small, and its significance comes from what the cyberattacker obtains afterward.
Credential theft is only one outcome. A phishing page captures a username and password, while an adversary-in-the-middle cyberattack steals the authenticated session token proving the user already completed login. Stolen session tokens invalidate the assumption that a password reset alone ends the incident.
Assessments should include token revocation, session invalidation, device review, and reauthentication for sensitive applications. After access, the adversary seeks persistence through mailbox rules, malicious OAuth grants, additional accounts, or trusted third-party connections.
Lateral movement uses the compromised employee's relationships to target colleagues, vendors, and customers. A captured executive account can launch business email compromise (BEC), while an infected workstation or cloud identity exposes files, payment instructions, and recovery channels.
Business impact follows the process the adversary selected, so the same spear phishing path can produce fraudulent wires, payroll diversion, intellectual-property theft, regulatory exposure, or ransomware. According to the FBI's 2025 Internet Crime Report, cyber-enabled fraud accounted for almost 85% of all losses reported to IC3, totaling $17.7 billion, up from $13.7 billion in 2024.
Each interaction should connect to a consequence and an owner:
- Finance click: Payment verification, treasury review, and bank recall procedures;
- IT credential submission: Identity containment and privileged-access review;
- Data disclosure: Legal, privacy, and customer-notification decisions;
- Compromised mailbox: Message search, forwarding-rule removal, and related-account review.
Cleanup and evasion belong inside the original attack path. Cyberattackers can delete messages, alter mailbox rules, remove OAuth permissions, rotate forwarding addresses, or keep using a stolen session after an employee reports the original phish.
Security teams should preserve evidence, revoke sessions and tokens, remove persistence, notify affected process owners, and feed the findings into targeted cybersecurity awareness training. A complete spear phishing risk assessment asks at every phase which signal should stop the cyberattack and who owns the response when it is missed.
That discipline turns reconnaissance, deception, and exploitation into testable controls instead of an annual awareness exercise, giving security leaders a clearer view of where human judgment protects the business.
Reconnaissance, delivery, and exploitation each fail quietly when no owner is assigned to the warning signal. Adaptive Security rehearses those decision points across every channel cyberattackers currently use.
How Should Organizations Conduct a Three-Phase Spear Phishing Risk Assessment?
A spear phishing risk assessment moves from exposure evaluation to control validation, risk scoring, and remediation planning. Define the scope, collect evidence, and test how controls and employees perform under realistic conditions, then convert findings into owners, deadlines, and measurable actions. Repeat the cycle after major organizational, technical, or process changes, because exposure and susceptibility both shift over time.
1. Map Exposure Before Testing Controls
The assessment begins by identifying what cyberattackers can discover, whom they can target, and which business actions would create the greatest impact. Create an approved inventory of public email addresses, employee names and roles, executive profiles, exposed phone numbers, public documents, conference appearances, social media accounts, and other open-source intelligence (OSINT). Record each source, collection date, confidence level, and whether the organization already knows about the exposure.
Extend the inventory beyond the corporate directory to executives, finance staff, administrators, help desk personnel, developers with production access, remote workers, contractors, mobile users, recruiters, assistants, and vendors involved in payment or data processing. An executive assistant's public address can open access to calendars, approvals, and travel details, making it as valuable to a cyberattacker as the executive's own address.
Connect people to high-value business processes. Document who can approve wire transfers, change vendor banking details, reset credentials, release sensitive data, authorize payroll, or communicate with customers during an incident. Map the systems and workflows supporting each process so the assessment reflects business impact rather than treating every inbox as equal.
Build scenarios from that exposure, setting generic phishing templates aside. Include executive impersonation, vendor invoice changes, password-reset lures, fake human resources documents, contractor onboarding messages, cloud-storage shares, and follow-up phone calls. For high-value roles, add vishing, smishing, and collaboration-tool impersonation, with each scenario naming the pretext, target, requested action, expected control, and potential consequence.
Set governance requirements before collecting data. Name a security leader as the assessment owner and include identity, email, endpoint, finance, human resources, legal, procurement, and incident response stakeholders. Define business units, subsidiaries, geographies, user groups, domains, and excluded systems in writing, then prohibit credential harvesting, malware delivery, personal-account testing, or customer contact unless explicitly approved.
Severity is rising fast enough to justify that rigor. According to the U.K. National Cyber Security Centre's Annual Review 2025, the agency's incident management team supported 429 incidents in the year to August 2025, of which 204 were nationally significant, compared with 89 the previous year.
Phase 1 should produce an exposure register in place of a list of assumptions. Each entry should identify the exposed asset, business owner, attack path, data source, verification date, and initial consequence. Organizations that need continuous visibility into executive exposure, privileged users, and behavior-based signals can connect the register to a human risk management program.
2. Validate Controls and Susceptibility Under Pressure
The second phase tests whether preventive, detective, and human controls perform as designed. Inventory email authentication coverage for every sending domain, multifactor authentication (MFA) coverage across workforce, administrative, service, contractor, and vendor accounts, and endpoint and web protections for mobile and remote users. Record enforcement mode, exceptions, monitoring, and ownership rather than noting only that a setting exists.
CISA's 2025 Cross-Sector Cybersecurity Performance Goals call for training users to recognize manipulation attempts and reducing spear phishing risk through stronger authentication. Assign every gap to an owner and an attack path instead of logging it as an abstract compliance deficiency. Document exceptions for unmanaged devices, contractors, personal phones, and legacy applications, because cyberattackers regularly target the least protected route.
Test the human workflow by tracing how an employee reports a suspicious message, how the security team classifies it, and how quickly related messages can be removed. Verify reporting through Outlook, Gmail, mobile applications, and collaboration platforms, then review payment verification, vendor-change procedures, dual approval, call-back requirements, and incident response playbooks. A policy that fails during an urgent request is not an operating control.
Use authorized phishing simulations to test susceptibility without creating real harm. Obtain written approval from the assessment sponsor, legal counsel, human resources, and affected process owners, then define sender domains, content, target groups, timing, collected data, stop conditions, notification rules, and post-test support. Never capture real credentials or create avoidable anxiety, and measure reporting, verification, response time, and escalation alongside clicks.
The evidence package should include configuration exports, DNS records, identity reports, policy documents, interview notes, phishing simulation results, incident tickets, and exception registers. Give every artifact an owner, collection date, system of record, and retention rule so remediation teams can defend findings and act on them.
3. Score Decisions and Assign Remediation
The third phase converts exposure and test results into prioritized decisions. Score each finding across likelihood, asset value, control strength, exploitability, and business impact, keeping the dimensions separate before calculating priority. Separation shows whether risk comes from an exposed executive, a weak payment control, an easily spoofed domain, or a severe recovery consequence.
Likelihood should reflect cyberattacker access to information, pretext credibility, reachable channels, and the target's demonstrated response. Asset value should account for money, privileged access, regulated data, intellectual property, and operational dependency. Control strength should reflect tested performance over policy language, while exploitability considers whether existing defenses interrupt the path.
Business impact should include financial loss, service disruption, legal exposure, and recovery time. A transparent five-point scale can support scoring, provided the formula does not conceal judgment. A medium-likelihood cyberattack against a payroll administrator can outrank a high-likelihood lure aimed at a low-impact mailbox, so record the rationale, evidence, confidence level, and risk acceptance authority for every priority.
Assign each high-priority finding one accountable owner and a due date. Technical actions can include DMARC enforcement, stronger MFA, removal of stale privileged accounts, and improved email-reporting workflows. Process actions can include out-of-band verification for payment changes, dual approval for high-value transfers, and updated incident response escalation.
Human-layer actions can include role-specific phishing simulations, targeted microlearning, executive impersonation drills, and practice using the reporting path. Define remediation scope as carefully as testing scope, stating whether the action covers employees, contractors, vendors, subsidiaries, managed devices, mobile users, and personal accounts. A finding closes only when the control is implemented, tested, and supported by evidence.
Assessment duration depends on organizational size, system access, legal review, and the number of business units involved. Establish checkpoints for charter approval, exposure-register completion, preliminary control-gap review, phishing simulation authorization, and leadership sign-off on the final risk register instead of a universal timeline.
Repeat the three phases after major acquisitions, executive turnover, domain changes, identity migrations, payment-process changes, or significant shifts to remote and mobile work. The spear phishing risk assessment creates lasting value when it operates as a decision cycle showing which attack paths remain exposed, which controls interrupt them, and where investment reduces the most consequential risk.
Exposure registers age quickly when executives change roles and when payment workflows move onto new systems. Adaptive Security keeps that picture current with continuous human risk signals.
How Should Organizations Build a Spear Phishing Risk Scoring Model?
A spear phishing risk assessment should score a cyberattack before controls, then recalculate the remaining exposure after people, technology, and process controls are applied. Define the cyber threat scenario, rate likelihood, exposure, business value, and impact, then record the result in a risk register with an owner and due date. The model exists to direct action toward the highest combined risk, never to rank employees by click rate.
1. Define the Scoring Dimensions and Formula
A usable spear phishing risk assessment scores the full attack path, going well past one employee behavior. A finance employee who ignores simulated email lures can still face substantial risk when cyberattackers arrive by vishing, impersonate a supplier, or exploit an approval process without independent verification. A low phishing simulation failure rate is useful evidence, yet it does not prove that high-value targets or untested channels are safe.
Use a 0-to-10 score for each dimension:
- Threat likelihood (L): How plausible and active the scenario is, given current targeting, adversary capability, exposed identities, and known campaigns;
- Target exposure (E): How easily a cyberattacker can reach and personalize the target, including public profiles, email addresses, conference videos, phone numbers, supplier relationships, and external messaging platforms;
- Asset or process value (V): What the targeted person can access or authorize, scoring payment systems, privileged accounts, customer data, intellectual property, and executive communications above routine information;
- Attack impact (I): What follows a success, including financial loss, credential theft, business email compromise (BEC), operational disruption, regulatory exposure, and reputational damage;
- Control strength (C): How consistently technical, people, and process controls prevent, detect, or contain the scenario, scored so higher represents stronger protection.
The NIST Cybersecurity Framework 2.0, published in 2024, organizes cybersecurity risk management around organizational context, risk assessment, and prioritized action. That structure supports a transparent register in which every score carries a business explanation in place of an unexplained color or aggregate number.
Calculate inherent risk before controls with:
Inherent Risk = (L × 0.25) + (E × 0.20) + (V × 0.25) + (I × 0.30)
This weighted average produces a score from 0 to 10. The weights give greater influence to impact and business value than to adversary activity or public exposure. An organization can adjust the weights, provided it documents the reason and applies the same method across departments.
Calculate residual risk after controls with:
Residual Risk = Inherent Risk × (1 - C / 10)
A payment approval process with likelihood 8, exposure 7, value 10, and impact 9 produces an inherent risk score of 8.6. If combined controls score 4, residual risk falls to 5.2. That result does not mean the organization is safe; it means controls have reduced the modeled exposure while leaving material risk that requires treatment.
Treat scores from 0 to 2.9 as low, 3 to 5.9 as moderate, 6 to 7.9 as high, and 8 to 10 as critical. Set escalation rules in advance, because a critical inherent risk deserves treatment even when residual risk falls. A moderate residual risk tied to payroll, privileged access, or customer data should stay visible to the risk owner.
Impact scoring benefits from an external benchmark. According to IBM's Cost of a Data Breach Report 2026, the global average cost of a data breach reached a record $4.99 million, a 12% increase over the previous year, with detection, escalation, and lost business accounting for roughly two-thirds of the total.
2. Rate People, Technology, and Process Controls Using Observable Evidence
The control score should combine three separate ratings. Score people, technology, and process from 0 to 10, then calculate:
C = (People + Technology + Process) / 3
Points belong to evidence that the control works under realistic conditions. Owning a policy or purchasing a tool earns nothing on its own.
People Rating
A 0-to-3 people score indicates weak behavioral readiness. The organization runs little role-based cybersecurity awareness training, employees rarely report suspicious messages, and phishing simulations cover only obvious email lures. Evidence includes repeated failures without targeted coaching and no way to identify exposed executives or finance staff.
A 4-to-7 score indicates developing readiness. Most employees complete their cybersecurity awareness training, reporting channels exist, and phishing simulations produce usable trend data, although coverage remains inconsistent. Finance, executives, contractors, or help desk staff may never rehearse scenarios matched to their authority.
An 8-to-10 score indicates demonstrated readiness. Employees report suspicious activity through a defined channel, high-risk roles complete recurring scenario-based practice, and failed phishing simulations trigger focused coaching over blame. The organization tracks reporting speed, verification behavior, repeat exposure, and performance by channel across multiple periods.
Technology Rating
A 0-to-3 technology score means controls provide little resistance. External email authentication is incomplete, multifactor authentication is absent from important accounts, privileged access is broad, and reported phishes are handled manually. Voice, SMS, collaboration, and deepfake risks sit outside the monitoring model entirely.
A 4-to-7 score reflects partial coverage, with multifactor authentication, email filtering, identity controls, and reporting tools in place alongside standing exceptions. Detection performs better against known malicious links than against trusted-account impersonation, payment fraud, or benign-looking requests. The security team can investigate a reported message without consistently remediating similar messages across mailboxes.
An 8-to-10 score requires layered, tested coverage. Strong identity controls protect high-value accounts, risky forwarding and access patterns generate alerts, and reported phishing moves quickly into classification and containment. Testing spans realistic spear phishing, BEC, vishing, smishing, and executive impersonation, and phishing simulations across multiple channels prove technology and human behavior were tested together.
Process Rating
A 0-to-3 process score means the organization relies on informal judgment. Payment changes lack independent confirmation, employees do not know how to escalate suspicious requests, and incident ownership is unclear, so urgency and authority override normal approval controls.
A 4-to-7 score means documented procedures exist and are unevenly followed. Verification is required for some transactions, reporting instructions are available, and incident response exercises occur occasionally. Exceptions for executives, urgent payments, remote work, or suppliers are not consistently tested.
An 8-to-10 score means critical actions carry enforced, repeatable safeguards. Payment and account changes require out-of-band confirmation, sensitive requests have dual approval, employees report without penalty, and response teams rehearse escalation paths. Audit records show who verified and approved each request, and how quickly a suspected compromise was contained.
3. Build the Risk Register and Prioritize Treatment
Create one row for each meaningful scenario, avoiding one row per employee. A useful register includes the target role, attack path, business process, adversary or trigger, L, E, V, I, people score, technology score, process score, inherent risk, residual risk, treatment, owner, evidence source, and review date.
Write scenarios in operational language. "Cyberattacker impersonates a supplier by email and phone to change bank details for an approved invoice" is actionable, while "finance phishing risk" is not. The detailed description identifies the channel combination, target process, likely consequence, and controls that require testing.
Review the register quarterly and after a major organizational change such as an acquisition, executive appointment, new payment system, or public incident. CISA's Fiscal Year 2023 Risk and Vulnerability Assessment analysis, published in 2024, treats spear phishing as targeted social engineering, reinforcing the need to assess specific people and workflows over generic organizational susceptibility.
Prioritization requires judgment when scores conflict. If human risk is high while technical controls are strong, focus on high-consequence pathways that technology does not fully govern. Assign targeted practice to executives, finance staff, and privileged users, require independent verification for payment and credential requests, and test vishing, smishing, and deepfake scenarios, because strong filtering does not stop a person from approving a fraudulent transfer.
If technical controls are weak despite low simulated susceptibility, prioritize technology and process remediation. A low click rate can reflect an easy phishing simulation, a small sample, or employees recognizing the test pattern, and it proves nothing about whether authentication, mailbox monitoring, or response procedures withstand a tailored cyberattack. Require stronger identity protections, tighter privileged access, rapid containment, and phishing simulations that use realistic personalization.
Keep click rate as one signal among several. Track reporting rate, time to report, repeat failures, verification completion, exposure of high-value roles, control exceptions, and residual risk by business process. A mature spear phishing risk assessment shows where a cyberattacker can still produce the greatest business outcome and assigns a named owner to close that gap.
Scoring models collapse when the control rating rewards purchased tools over tested employee behavior. Adaptive Security supplies the behavioral evidence that makes a control score genuinely defensible.
How Should an Organization Assess People and Digital Exposure in a Spear Phishing Risk Assessment?

A spear phishing risk assessment should identify which people cyberattackers can convincingly impersonate, pressure, or reach through exposed digital channels. It is not a ranking of careless employees. It maps human access, public information, and workflow authority to show where targeted deception is most likely to trigger a payment, a credential disclosure, or a sensitive-data loss.
The strongest assessment combines role risk with digital exposure. Review human risk management practices alongside identity and access records, reporting structures, travel calendars, vendor relationships, public profiles, and known credential exposure. According to Verizon's 2026 Data Breach Investigations Report, pretexting reached 6% of all breaches as a tracked initial access vector, driven by synchronous impersonation of help desk, HR, and leadership contacts.
Which Identities Deserve Priority in a Spear Phishing Risk Assessment?
Prioritize identities where authority, urgency, and access overlap. Include executives and their assistants, finance and accounts-payable teams, privileged administrators, help desk staff, recruiters, remote workers, contractors, and mobile-device users. Anyone who can approve payments, reset credentials, access customer records, or communicate with vendors belongs in the review.
The likely pretext should shape the assessment. A finance employee might receive a vendor-payment request referencing a real invoice, while a help desk agent faces a convincing password-reset call. A recruiter might receive a weaponized résumé, and a sales representative traveling to an event might be targeted through a fake venue, partner, or customer request.
Evaluate those scenarios by role, since one generic test for every employee proves little. A practical review should examine:
- Authority: Can the person approve funds, change access, or direct another employee;
- Access: Can the person reach sensitive data, administrative consoles, or payment workflows;
- Visibility: Are the person's title, reporting line, travel plans, clients, or vendors publicly available;
- Reachability: Are personal email addresses, mobile numbers, or messaging accounts exposed;
- Behavioral context: Does the role routinely operate under deadlines, across time zones, or from unmanaged devices.
This prioritization gives security teams a defensible testing order and keeps high-impact identities from disappearing inside an organization-wide average. The U.K. National Cyber Security Centre's 2025 Annual Review also highlighted continuing spear phishing against personal accounts, which reinforces the need to assess personal and corporate exposure together.
How Do OSINT and Privacy Exposure Increase Targeting Risk?
Public information turns a vague phishing email into a plausible business conversation. Cyberattackers use open-source intelligence (OSINT) from company pages, social profiles, job posts, conference agendas, press releases, public documents, and breached-credential records to assemble names, titles, reporting lines, writing patterns, and current projects. They can then imitate a vendor, reference a recent event, or time a request around travel and absence.
Assess exposure at the person level and the relationship level. Search for corporate and personal email-address exposure, reused usernames, phone numbers, executive video and audio, document metadata, and posts that reveal internal terminology. Review whether employees disclose manager names, approval processes, or upcoming trips.
The objective is narrower than removing every public detail. It is to identify which details make a message believable, reduce unnecessary exposure, and add verification controls where removal is impossible.
Technical safeguards determine how much damage a successful deception can cause. Record whether high-risk workflows require out-of-band approval, phishing-resistant MFA, dual authorization, privileged-access management, mobile-device controls, and rapid credential revocation. Public exposure without independent workflow verification is a high-priority finding, while exposure protected by strong verification is a managed risk.
How Can Organizations Measure Susceptibility Without Blame?
One failed phishing simulation captures a moment in place of a permanent weakness. Distinguish an isolated result from a control gap by examining repeat behavior, scenario relevance, reporting quality, response time, and role risk. An employee who clicks an implausible test yet quickly reports a genuine suspicious message differs sharply from a finance approver who repeatedly complies with realistic payment requests.
Use repeated, role-specific scenarios across email, voice, SMS, and collaboration channels. Track whether the employee reports the message, how quickly the report reaches the security team, and whether targeted coaching changes behavior. Interpret results in context, since a privileged administrator or contractor with sensitive access requires faster intervention than a low-access employee facing an irrelevant scenario.
Cybersecurity awareness training should build verification habits rather than punish failed tests. Employees need a clear action path: pause high-pressure requests, verify through a known channel, report suspicious contact, and avoid using information supplied in the message to perform that verification. A mature spear phishing risk assessment converts those behaviors into signals for targeted practice and establishes the baseline for tracing how reconnaissance becomes exploitation.
Public exposure and workflow authority combine into concentrated risk that no organization-wide average will ever reveal. Adaptive Security surfaces that concentration by role, identity, and observed behavior.
How Can a Spear Phishing Risk Assessment Validate Email, Identity, and Access Controls?
A spear phishing risk assessment tests whether controls stop, expose, or contain a cyberattack, going well beyond confirming that settings exist. Preventive controls block malicious messages and unauthorized access before damage occurs, while detective controls surface suspicious activity for investigation. The strongest assessment measures prevention, detection, and containment together through controlled test results, authentication logs, alert-to-action times, token revocation tests, network segmentation evidence, and least-privilege reviews.
Email filtering should be tested against blocked-message samples, URL and attachment analysis, malware detections, browser and web filtering, endpoint alerts, SPF, DKIM, and enforced DMARC policies. Identity controls such as MFA, passkeys, biometrics, smartcards, conditional access, and session protection become decisive when a cyberattacker bypasses filtering through a trusted account or an identity-based request.
How Should Email and Message-Layer Controls Be Compared?
Email controls must be judged by outcomes under controlled conditions. Send benign test messages reproducing spear phishing characteristics, including lookalike domains, newly registered links, safe attachment types, and reply-chain impersonation. Record whether secure email filtering blocks, quarantines, rewrites, or delivers each message, and preserve the headers and verdict for review.
Anti-spoofing validation should confirm that SPF and DKIM checks produce the expected results and that DMARC enforcement rejects or quarantines unauthorized senders in place of reporting them passively. URL analysis should test redirects, shortened links, and newly observed domains, while malware protection shows how quickly a payload is detected after delivery.
Browser and web filtering should be tested against the same destination from managed and unmanaged devices, while endpoint protection records prevention, alerting, isolation, and remediation actions. A complete program connects these controls to phishing response and remediation workflows so analysts can measure whether a reported message is contained across user inboxes instead of merely classified.
How Do Identity and Session Defenses Compare?
Identity defenses address cyberattacks that traditional filtering cannot see, including consent phishing, stolen-session abuse, fake help desk calls, and requests sent from a legitimate mailbox. Test each control with approved scenarios measuring failed-login alerts, impossible-travel detection, conditional-access decisions, session expiry, and administrator response time.
Credential abuse remains a leading route into the environment. According to Verizon's 2026 Data Breach Investigations Report, credential abuse accounted for 13% of breaches as an initial access vector, and the report notes that credential misuse appears far more widely once the full attack chain is considered.
Password managers reduce password reuse without providing the phishing resistance of passkeys or hardware-backed smartcards. SMS and push MFA add friction for cyberattackers yet remain exposed to SIM swapping, social engineering, and push fatigue. NIST's 2025 Digital Identity Guidelines distinguish phishing-resistant authentication from methods that merely add another factor, making that distinction central to the assessment.
Evidence should include authentication logs, device-posture decisions, conditional-access policy results, token revocation tests, and proof that active sessions terminate after account disablement or suspected compromise. A control that requires phishing-resistant MFA while leaving refresh tokens active has not contained the cyberattack.
Which Controls Reduce the Blast Radius?
Containment controls determine how far a successful spear phishing event can travel. Review least-privilege assignments for finance, administration, code repositories, and sensitive data, then test whether a compromised standard account reaches those systems. Network segmentation should keep ordinary user devices off critical administrative paths, while application permissions restrict data access by role.
Use controlled accounts to test privilege escalation, lateral movement, mailbox delegation, and external forwarding. Measure the time required to disable the account, revoke tokens, isolate an endpoint, and remove malicious inbox rules. The evidence should show that segmentation and least privilege stop the next action in the attack chain.
What Evidence Proves a Control Works?
A defensible spear phishing risk assessment produces a control-to-outcome record. For each test, document the attack condition, expected result, observed result, log source, alert-to-action time, owner, and corrective action. Compare preventive controls by blocked or rejected events, detective controls by signal quality and response speed, and containment controls by the systems and access that remained unreachable.
CISA's 2025 Cybersecurity Performance Goals treat phishing-resistant MFA and email authentication as measurable risk-reduction practices in place of checkbox exercises. Re-test after policy changes, identity migrations, and major application deployments. That cadence turns the assessment into evidence that the organization can withstand identity-based cyberattacks even when a malicious message reaches an employee.
Configuration screenshots prove a setting exists and say nothing about whether a stolen session was ever actually revoked. Adaptive Security ties control evidence to observed employee decisions.
Which Business Processes Create the Greatest Spear Phishing Risk?
A spear phishing risk assessment starts with business processes over inboxes, because cyberattackers target decisions that move money, grant access, or release data. In its 2025 IC3 Annual Report, the FBI defines business email compromise (BEC) as a scam targeting organizations that conduct legitimate financial transactions. The same trust mechanisms affect payroll, procurement, and identity workflows, because familiar senders lower suspicion while urgency suppresses independent checks.
According to the FBI's 2025 Internet Crime Report, BEC accounted for $3.046 billion in losses across 24,768 incidents, averaging roughly $123,000 per case. Those figures describe ordinary business processes operating exactly as designed for a request that only appeared legitimate.
Which Workflows Carry the Highest Spear Phishing Risk?
High-value workflows create the greatest exposure when one message can trigger an irreversible action. Review each process for financial value, access privilege, data sensitivity, time pressure, and dependence on email identity. Prioritize:
- Payment requests, invoice approvals, and bank-account changes;
- Payroll updates, direct-deposit changes, and tax-document requests;
- Procurement, vendor onboarding, and supplier-contact changes;
- Credential resets, multifactor authentication changes, and urgent access requests;
- Executive approvals, data exports, and requests involving regulated information.
Bank-account changes require the strictest controls, because a fraudulent request can look routine, pass through ordinary procurement steps, and redirect a legitimate payment. Require dual approval from people outside the requesting function, callback verification using a known number stored in the vendor record, and independent channel confirmation before changing payment instructions. The phone number or link supplied in the suspicious message must never be used for that check.
Credential resets and emergency access requests deserve the same discipline. A message that appears to come from an executive, help desk, or cloud administrator should not authorize privileged access by itself. Require separation of duties, identity verification through an established process, and a time-limited approval that records who requested, reviewed, and completed the change.
How Should Verification and Escalation Controls Work?
Verification controls reduce spear phishing exposure by breaking a cyberattacker's control over the communication channel. Write each control into the workflow instead of leaving it to individual judgment. For high-risk requests, the recipient should pause the transaction, contact the requester through a known number, and ask a challenge question absent from the original message.
Exception handling matters because cyberattackers often manufacture urgency by claiming that normal controls cannot apply. Document which circumstances permit an exception, who can authorize it, and when the action receives retrospective review. An emergency procedure should accelerate verification rather than remove it, so an urgent payroll correction can use two-person approval and a same-day audit review.
Test these controls with phishing simulations that measure more than click rates. Send realistic invoice changes, fake credential-reset requests, and urgent executive approvals, then record whether employees verify independently, report the message, and escalate through the correct route. Teaching employees to recognize pressure tactics makes them an active detection layer without asking them to identify every technical signal.
The escalation path must work even when the affected mailbox cannot be trusted. If a cyberattacker controls a vendor, executive, or employee account, replies inside the same thread provide no independent confirmation. Define an out-of-band route through the security team, finance controller, HR operations, or an executive assistant, and test that route during exercises.
Why Do Third-Party Dependencies Increase Spear Phishing Exposure?
Vendor and partner relationships expand the trust boundary, because a compromised external account can produce a message that looks legitimate to employees and internal systems. According to Verizon's 2026 Data Breach Investigations Report, third-party involvement appeared in 48% of breaches, a 60% year-over-year increase driven by vendor, SaaS, and OAuth integration compromise.
A supplier's real domain, familiar invoice format, and accurate contract details do not prove that the sender is authorized. Assess vendors that can change payment details, access internal portals, submit files, or request sensitive data, then assign stronger verification requirements to those with greater business impact.
Change-of-bank controls should require confirmation against previously validated contact records and review by a separate owner, while vendor onboarding verifies legal identity, approved contacts, payment instructions, and the responsible business sponsor. Procurement teams should treat a new contact, unusual urgency, or deviation from established billing patterns as a reason to escalate.
Trusted-account takeover also affects internal workflows, because a compromised mailbox can send convincing follow-ups, answer questions, and imitate a colleague's tone. When a message involves money, privileged access, or sensitive exports, the process must outrank the apparent identity of the sender.
Mapping these dependencies completes the business-process portion of a spear phishing risk assessment and creates the foundation for testing how reconnaissance becomes a trusted request, a pressured decision, and an operational loss.
Vendor bank-detail changes pass through procurement looking entirely routine until the redirected payment lands elsewhere. Adaptive Security rehearses those exact requests with the finance teams who approve them.
How Can Organizations Test Spear Phishing Susceptibility Safely?

A safe spear phishing risk assessment requires written authorization, legal and HR review, strict privacy limits, and a design that measures decisions without creating a real security incident. Define the audience, scenarios, data collected, exclusions, support plan, and success criteria before sending anything. Treat the exercise as skill-building for employees and validation for technical defenses, never a trap or a public ranking.
1. Establish Rules of Engagement Before Testing
Document the purpose, scope, dates, approved senders, domains, channels, escalation contacts, and stop conditions. Obtain signoff from the security owner, legal counsel, HR, privacy, and the executive responsible for each affected business unit. The authorization must prohibit credential collection, production-data access, malware, real account lockouts, and attempts to bypass controls beyond the agreed boundaries.
A spear phishing risk assessment evaluates the human and technical path that a conventional vulnerability assessment does not. It measures whether employees verify unusual requests, whether email controls quarantine or deliver messages, whether reporting workflows reach security staff, and whether incident responders can contain the event. CISA anti-phishing program guidance identifies simulated cyberattacks and results analysis as components of an anti-phishing program.
Set privacy boundaries before collecting results. Store only the minimum fields required, such as department, role, message delivery, link interaction, and time to report, then restrict individual results to authorized reviewers and define a retention period. Exclude employees in crisis, on protected leave, or managing live financial workflows, and never test a payment approval, payroll change, or emergency-response process without separate approval.
2. Design Realistic Scenarios Without Creating Real Harm
Build scenarios from proportionate open-source intelligence (OSINT) such as public job titles, department names, vendor relationships, or published business events. Avoid scraping private accounts, impersonating family members, exploiting personal hardship, or using sensitive information employees reasonably expect the organization to protect. The objective is to reproduce adversary signals, avoiding anything that maximizes embarrassment.
Use a safe landing page that records only the interaction and immediately explains the exercise. It must contain no login form and never request a password, multifactor authentication code, payment detail, or confidential file. Attachments should be inert documents such as a controlled policy sample, carrying no macros, scripts, tracking payloads, or executable content.
Keep each scenario proportionate to the role, so finance staff rehearse invoice verification while executives confirm urgent requests through an independent channel. Channel coverage matters as much as realism. According to Verizon's 2026 Data Breach Investigations Report, the median successful click rate in mobile-centric phishing simulations using voice and text messaging runs 40% higher than the equivalent email rate.
Extend testing to vishing and smishing only with carrier, telephony, and privacy approval. Use controlled numbers, avoid caller ID spoofing where prohibited, never record real conversations without consent, and provide an immediate opt-out. For smishing, use short links resolving to the same safe landing page and schedule messages during working hours.
Coordinate the exercise with the incident-response team so an employee report triggers the same triage and communication workflow used for a real event. That coordination tests the response chain and the message design together.
3. Turn Results Into Learning Rather Than Blame
Run monthly pulse checks that test one behavior or channel, alongside a broader quarterly assessment covering email, reporting, technical controls, and response coordination. Rotate scenarios so employees build judgment over memorized templates, and measure delivery, interaction, reporting rate, time to report, and containment time.
A click is not proof of negligence. Interpret it alongside role, workload, message design, prior exposure, and whether the reporting path worked. Provide just-in-time coaching after the interaction, explain the warning signals, and show employees how to verify the request safely.
Share aggregate findings with leadership and give employees practical feedback without naming or shaming them. Compare results over time and prioritize recurring gaps such as vendor-payment requests that bypass approval or voice calls lacking callback verification. A modern phishing simulation program can connect these signals across email, voice, and SMS while keeping the exercise controlled.
A completed assessment should produce three actions: one behavior to reinforce, one technical control to tune, and one incident-response step to rehearse. Those safeguards turn susceptibility testing into a practical view of how a spear phishing cyberattack moves from reconnaissance toward exploitation.
Poorly governed testing damages employee trust faster than any lure ever reaches an inbox. Adaptive Security runs authorized, privacy-bounded phishing simulations that build judgment instead of resentment.
Which Metrics Show Spear Phishing Exposure and Resilience?
A useful spear phishing risk assessment compares exposure with resilience in preference to treating one click rate as the verdict on program effectiveness. Exposure measures how easily employees and technical controls allow a simulated cyberattack to progress, while resilience measures whether people recognize, report, and contain it before business harm occurs. Click rate, credential-submission rate, and attachment-open rate capture different points of susceptibility, so none of them should stand alone.
Reporting rate, report quality, false-positive rate, and time to report show whether employees function as a defensive layer. The strongest measurement system connects those signals to control performance and business outcomes.
What Are the Leading Indicators of Spear Phishing Risk?
Leading indicators identify conditions that predict future exposure. Track delivered-versus-blocked test messages, because a low click rate means little when the phishing simulation never reaches its intended population. For delivered messages, measure click, credential-submission, and attachment-open rates by department, role, and channel.
Elevated results should trigger investigation into message realism, workload, recent organizational change, and role-specific targeting, never automatic blame. Pair susceptibility data with positive behavior, so reporting rate distinguishes reports from inaction while report quality records whether employees correctly identify malicious links, impersonation, or business email compromise (BEC).
Track false-positive rate as well, because high reporting volume with poor classification overloads analysts and weakens trust in the reporting process. Time to report, participation in cybersecurity awareness training, and repeat susceptibility complete the early-warning picture. An employee who clicks once and reports within seconds presents a different risk from one who neither clicks nor reports.
Technical and procedural indicators show whether surrounding controls reinforce employee decisions. Include MFA adoption, DMARC policy status, payment-verification compliance, and the percentage of simulated messages blocked before delivery. The 2025 NIST enterprise risk management draft emphasizes quantifiable performance measures and risk tolerances, supporting thresholds that connect indicators to a defined action.
Which Lagging Indicators Prove Spear Phishing Resilience?
Lagging indicators measure what happened after exposure or control failure. Track time to triage, time to contain, confirmed credential use, affected accounts, payment exceptions, and the percentage of reported messages remediated across inboxes. For real incidents, compare those results with phishing simulation performance to test whether rehearsed behavior transfers beyond controlled exercises.
A control should not be declared effective because click rate fell once. Minimum evidence requires a documented baseline, repeated tests across comparable scenarios, adequate delivery volume, segmented results, stable or improving reporting quality, and response records showing that triage and containment met defined targets.
Completion records make a poor substitute for that evidence. As NIST computer scientist Julie Haney and University of Maryland Associate Professor Wayne Lutters concluded in their peer-reviewed analysis published in Computer (October 2020), compliance metrics do not tell the whole story and fail to measure whether a program produces sustained change in employee attitudes and behaviors.
Add repeat-susceptibility data across several testing cycles. Verify that high-risk departments and executives improve, because a strong companywide average can conceal concentrated exposure. Resilience becomes credible when safer behavior persists across scenarios, channels, and pressure levels.
How Should Leaders Interpret Elevated Spear Phishing Metrics?
Elevated click, credential-submission, or attachment-open rates identify a risk signal in place of an employee character judgment. Investigate whether the campaign used a realistic spear phishing pretext, whether technical controls altered delivery, whether the population understood the reporting process, and whether the same people repeatedly encountered similar scenarios.
Compare executive and department risk with job function and cyberattack likelihood, then assign targeted practice over broad remedial coursework. Employees who report suspicious messages quickly provide a measurable defensive signal even when a phishing simulation exposes a decision that needs reinforcement.
Estimate each remediation investment by comparing expected loss before and after intervention. Calculate the change in successful high-risk actions, multiply it by the organization's estimated financial impact per event, and subtract program cost and implementation effort. Treat the result as a decision estimate rather than a guarantee, then validate it with later phishing simulations and real-world reporting.
What Should a Board Report Show?
Board reporting should compress operational metrics into exposure, control performance, response, and resilience. Present the percentage of delivered tests that produced a risky action, the percentage correctly reported, repeat susceptibility among high-risk groups, executive and department risk concentration, and MFA and DMARC status.
Boards are already positioned to receive that detail. According to the World Economic Forum's 2026 Global Cybersecurity Outlook, 52% of organizations indicate that board members receive regular cybersecurity updates, and 30% of board members in high-resilience organizations hold personal liability for breaches compared with 9% in low-resilience organizations.
Show time to report, time to triage, and time to contain beside the number of incidents requiring investigation. Use trend lines and risk thresholds instead of a single green score. A concise dashboard should explain which investment changed behavior, how much exposure declined, where controls still fail, and what action follows.
NIST's 2025 incident response guidance treats response measurement as part of capability improvement in place of post-incident documentation. For ongoing visibility, human risk reporting can organize these signals by employee, department, and executive exposure, giving leaders a clearer basis for prioritizing behavioral change and control improvements.
Boards receive reassuring green scorecards while concentrated exposure sits quietly inside finance, procurement, and executive support teams. Adaptive Security reports human risk at the level where it actually accumulates.
How Should Organizations Prioritize Remediation After a Spear Phishing Risk Assessment?
A spear phishing risk assessment becomes useful only when findings turn into time-bound action. Contain suspected compromise immediately, then assign 30-day and 90-day remediation based on exploitability, asset value, business impact, recurrence, and control gaps. Treat every click or disclosure as an investigation signal, never a reason to blame the employee.
1. Contain the Incident After a Click or Disclosure
The immediate objective is to stop adversary access before investigating the full campaign. Confirm what happened through a trusted channel, preserve the original message and headers, identify what was exposed, and open an incident record with a named owner and deadline.
Speed decides the outcome. According to the CrowdStrike 2026 Global Threat Report, average adversary breakout time, the window between initial access and lateral movement, dropped to 29 minutes, with the fastest observed at 27 seconds.
For a suspected account compromise, reset the password, revoke active sessions and refresh tokens, invalidate application passwords, review mailbox rules and forwarding settings, and suspend the account when evidence shows active misuse. Investigate sign-ins, OAuth grants, sent and deleted items, mailbox access, and related accounts. Isolate any device that opened a malicious attachment, and preserve forensic evidence before reimaging it.
Financial exposure requires a parallel response. Place payment holds, contact the bank through a verified number, and request a recall immediately if funds are moved. The FBI's 2024 business email compromise guidance directs organizations to contact their financial institution and request a recall as soon as they discover a fraudulent transfer.
Notify legal, privacy, compliance, cyber insurance, affected vendors, and law enforcement according to the incident plan, and assess notification duties before communicating externally. Email cannot be trusted during a mailbox compromise, so brief leadership through a known phone number or a preapproved out-of-band account. CISA's 2025 incident response advisory recommends out-of-band communications, practiced response plans, centralized logging, and prompt responder access to security tools.
2. Assign Remediation by Risk Band and Deadline
Risk bands prevent a long queue of findings from obscuring the issues that can cause immediate business damage. Rank each finding against five questions:
- Can a cyberattacker exploit it now;
- Does the target control privileged access, payments, sensitive data, or executive communications;
- What is the likely business impact;
- Has the behavior or control failure recurred;
- Which safeguard failed or does not exist.
Immediate, within hours. Treat a clicked link followed by credential entry, token disclosure, malware execution, executive impersonation, payment instruction, or privileged-account exposure as critical. Complete containment, account and session resets, mailbox investigation, payment holds, device isolation, evidence preservation, notifications, and regulatory assessment before closing the incident.
Within 30 days. Close the control gaps that enabled the event. Require phishing-resistant MFA for privileged and email accounts, establish independent verification for payment and sensitive-data requests, publish a reporting path employees can use immediately, and train the affected role on the exact scenario. Remove exposed identities from public sources where feasible, tune filtering rules for the observed sender, and review related mailboxes for the same lure, then use targeted phishing simulations to test whether revised verification behavior holds.
Within 90 days. Redesign the process instead of relying on employee vigilance alone. Separate payment approval from payment release, segment high-value systems, remove standing administrative access, enforce least privilege, strengthen vendor change-of-bank controls, and require independent confirmation for unusual requests. Define an owner for every control, measure reporting time and repeat-failure rates, and retest the same attack path with a new phishing simulation.
3. Capture Lessons Learned and Brief Leadership
A lessons-learned review should explain how the cyberattack moved from trust to access, which signal appeared first, and which decision would have prevented escalation. Include the employee's report, email telemetry, identity logs, payment records, and control evidence. Preserve the distinction between a training finding, a suspected compromise, and a confirmed incident.
Leadership needs a concise business narrative in place of an inbox transcript. Report the affected asset, exposure window, operational consequence, current containment status, financial or regulatory implications, root control gap, accountable owner, and deadline for each remediation. State what remains unknown and when the next update will arrive.
NIST's 2025 incident response recommendations frame response as a risk-management activity that reduces incident impact and improves detection, response, and recovery efficiency. Close the finding only after evidence shows the control changed and retesting confirms that the behavior or process withstands the same pressure. That discipline turns a spear phishing risk assessment from a scorecard into a measurable reduction in human-layer exposure.
Findings without named owners and firm deadlines decay into a backlog that no executive ever reads again. Adaptive Security links each remediation step to retested employee behavior.
Which Standards and Frameworks Guide a Spear Phishing Risk Assessment?

A spear phishing risk assessment compares governance frameworks with technical testing methods to determine whether an organization can prevent, detect, and contain targeted social engineering. The NIST Cybersecurity Framework provides a broad risk-management structure, while NIST Digital Identity Guidelines focus on authentication, identity proofing, and account recovery. CISA phishing guidance emphasizes prevention, reporting, and organizational readiness, and MITRE ATT&CK describes adversary techniques that help teams model reconnaissance, spear phishing, and credential theft.
PTES and OSSTMM add testing discipline when the assessment includes authorized penetration testing or broader operational-security validation. No framework replaces risk judgment, so a useful assessment combines business context, employee behavior, identity controls, incident readiness, and documented remediation.
Governance and Risk Alignment for a Spear Phishing Risk Assessment
Governance establishes what the assessment must protect, who owns each decision, and how risk acceptance works. Start with the NIST Cybersecurity Framework functions of Govern, Identify, Protect, Detect, Respond, and Recover, then define spear phishing scenarios by business consequence. A finance employee receiving a vendor-payment request presents a different risk from an engineer receiving a fake source-code invitation, even when both cyberattacks begin with a targeted email.
Map each scenario to business owners, sensitive processes, privileged roles, third parties, and escalation thresholds, and record the trust signal, requested action, expected control, and residual risk after remediation. CISA guidance supports practical controls such as employee reporting, incident escalation, and repeated testing.
For identity-related exposure, NIST Digital Identity Guidelines provide a reference for authentication strength, federation, authenticator management, and recovery procedures. Test whether a convincing spear phishing message can lead to credential disclosure, MFA fatigue, unsafe recovery, session theft, or unauthorized privilege use. Pair those findings with access reviews and least-privilege decisions, since course completion proves nothing about safety.
Technical and Identity Control Mapping
Technical mapping connects adversary behavior to defensive controls and test evidence. MITRE ATT&CK techniques can organize the attack path from open-source intelligence (OSINT) reconnaissance and spear phishing attachment or link delivery through valid-account use, credential access, and internal discovery. That shared language helps security, identity, and compliance teams describe the same weakness consistently.
Where the scenario touches web authentication, password resets, customer portals, or application workflows, OWASP guidance can frame tests for input handling, session management, authentication, and authorization. PTES fits an authorized penetration test with defined rules of engagement, while OSSTMM fits a broader operational-security review. Neither methodology measures employee judgment unless the scope explicitly includes controlled social-engineering exercises.
A practical control map should connect each test to one or more actions:
- Prevent: Phishing-resistant MFA, conditional access, secure email configuration, and least privilege;
- Detect: Reporting channels, identity alerts, suspicious-login monitoring, and analyst triage;
- Respond: Account suspension, token revocation, payment verification, and incident communications;
- Recover: Credential reset, access restoration, lessons learned, and targeted cybersecurity awareness training.
Organizations can use phishing simulations and multi-channel testing to generate behavioral evidence across email, voice, and SMS without presenting a phishing simulation as a penetration test. That distinction keeps technical findings and employee decision-making measurable without confusing their control objectives.
Evidence for Audits
Audit evidence must show a repeatable management process in place of a single test result. Retain the assessment methodology, scope approval, risk register, scenario library, phishing simulation records, access-control reviews, and remediation tickets. Each finding should include an owner, due date, severity rationale, compensating control, and retest outcome.
This evidence maps to SOC 2, HIPAA, GDPR, PCI DSS, ISO 27001, NIST CSF, and CMMC requirements when it demonstrates risk assessment, workforce training, access control, incident response, and continuous improvement. It supports compliance with those frameworks without establishing certification by itself. Completion records prove participation, while phishing simulation outcomes and reporting data show whether employees recognized and escalated a targeted cyberattack.
How Should Frameworks Work Together?
Use NIST CSF to govern the assessment, NIST identity guidance to evaluate account and authentication exposure, CISA guidance to shape prevention and reporting, MITRE ATT&CK to describe adversary behavior, and OWASP, PTES, or OSSTMM only where their technical scope fits. The final judgment should come from the organization's assets, cyber threat model, regulatory duties, and observed behavior.
NIST SP 800-61 Revision 3, published in 2025, integrates incident-response recommendations into cybersecurity risk management and the CSF 2.0 community profile. That structure creates a defensible spear phishing risk assessment and gives security leaders the evidence needed to prioritize remediation where human behavior and control gaps intersect.
Audit files full of completion certificates prove attendance and nothing about resistance to a targeted fraudulent request. Adaptive Security produces behavioral evidence that assessors can actually examine.
How Should Spear Phishing Risk Assessments Adapt to AI, Mobile, and Third-Party Cyber Threats?
A spear phishing risk assessment that tests one email at one moment misses identity-based cyberattacks moving across voice, SMS, video, browsers, personal devices, and trusted vendors. The result is a risk score that understates exposure when adversaries combine cloned authority, urgency, stolen sessions, or a compromised supplier to bypass familiar controls. According to Verizon's 2026 Data Breach Investigations Report, 41% of social engineering breaches now involve vectors beyond email, with roughly a quarter arriving through social media or phone-based channels.
How Should Spear Phishing Scenarios Evolve?
Scenario design should follow how adversaries build trust, in preference to how email gateways classify messages. A modern spear phishing risk assessment starts with open-source intelligence (OSINT) and tests whether employees can resist believable requests delivered through several channels:
- AI-generated messages: Personalized spear phishing that matches an executive's writing style, vocabulary, signature, and current business context;
- Voice and video impersonation: Cloned voice calls, deepfake video meetings, and requests appearing to come from a CFO, customer, regulator, or security administrator, as the Arup and Cardin cases both demonstrated;
- Mobile and browser cyberattacks: Smishing, vishing, QR code phishing, OAuth consent phishing, MFA fatigue, and adversary-in-the-middle techniques that relay credentials or capture authentication sessions;
- Identity and access abuse: Stolen session tokens, fake password-reset workflows, personal devices, remote work locations, contractors, and compromised vendors that provide a trusted route into business processes.
Synthetic media has moved from novelty to volume. According to Sumsub's 2025–2026 Identity Fraud Report, deepfake cyberattacks increased 2,100% globally, with sophisticated fraud including deepfakes, synthetics, and telemetry tampering surging 180% year over year.
Each scenario should measure the decision in place of the click. Record whether an employee verifies a payment change through a known channel, rejects unexpected OAuth permissions, refuses repeated MFA prompts, reports a suspicious QR code, or pauses when a vendor's bank details change. Multi-channel phishing simulations let security teams rehearse these decisions without blaming employees for encountering a convincing deception.
How Can Continuous Telemetry Improve Reassessment?
A continuous spear phishing risk assessment treats the risk score as a changing signal in place of a permanent label. Recalculate exposure when new cyber threat intelligence identifies an active impersonation campaign, when incident telemetry shows repeated reports from one department, or when a control change alters the attack path through a new identity provider, mobile workflow, vendor integration, or remote-access policy.
Employee movement also changes exposure. A finance employee who becomes an executive assistant, a contractor who receives payment authority, or a manager who gains customer-record access requires reassessment before new cybersecurity awareness training is assigned. Unapproved AI tool use should update the score when employees copy sensitive material into them, and digital-footprint changes should trigger review when public profiles reveal a new title, conference appearance, or contact detail.
Adversary tooling is scaling in the same direction. According to IBM's Cost of a Data Breach Report 2026, one in four malicious breaches were AI-enabled, a 56% year-over-year increase, and those breaches carried an average cost of $6 million.
CISA's 2024 guidance identifies passkeys and other phishing-resistant methods as defenses against adversary-in-the-middle cyberattacks. Assessments must still test the human actions surrounding enrollment, account recovery, consent, and support requests. A failed phishing simulation, a reported real phish, a near miss, and a changed privilege level should each produce a different response, never automatic punishment.
How Should Human-Risk Data Be Used Without Creating Privacy Harm?
Human-risk data should improve protection in place of becoming a performance dossier. Store susceptibility results, learning performance, reported-phish history, and OSINT exposure under strict purpose limitation. Security teams should use the data to target coaching, strengthen verification procedures, and prioritize control changes, never to shame employees.
Access should be role-based. Security administrators need detailed event data, department leaders need aggregated trends, and executives need exposure summaries over individual behavioral histories. Set retention limits for raw phishing simulation events, document who can access risk scores, and separate identity records from analytical results where operationally possible.
Employees should understand what is measured, why it is collected, how long it remains available, and how to challenge inaccurate context. A privacy-aware program also distinguishes susceptibility from misconduct, because an employee who reports a sophisticated deepfake after engaging with it has supplied a valuable defensive signal. The correct response is rapid coaching, clearer verification guidance, and reassessment after practice.
Risk scores calculated on last quarter's org chart miss the contractor who just gained payment authority. Adaptive Security continuously recalculates exposure as roles, permissions, and channels change.
How Can Spear Phishing Risk Assessment Results Produce Measurable Behavioral Change?
A spear phishing risk assessment produces measurable behavioral change when its findings determine what employees practice, well beyond a filed compliance report. Employees who click, submit credentials, delay reporting, or approve unusual requests need targeted intervention tied to the observed behavior and its role-specific consequences. The 2025 Department of Homeland Security and CISA awareness guidance makes the operational priority clear: recognize and report phishing before it spreads.
How Should Assessment Findings Drive Targeted Remediation?
Targeted remediation starts by treating every assessment result as a signal in place of a verdict. A finance employee who approves a simulated vendor-payment request needs invoice fraud and business email compromise (BEC) practice, while an executive assistant who shares calendar details needs identity verification and executive impersonation scenarios. An employee who spots the message and reports it slowly needs rehearsal focused on reporting speed and escalation paths.
Just-in-time cybersecurity awareness training should follow the decision that created exposure. A short module immediately after a failed phishing simulation can explain the cue the employee missed and require a safer response. Tone matters, because employees should understand that reporting a suspicious message is a security contribution even when it proves harmless.
That framing turns the workforce into an active detection layer, and practice stops feeling like punishment. A modern security awareness training program should connect role, behavior, and timing. Security teams can assign different exercises to finance, executives, help desk staff, developers, and contractors, then adjust difficulty as performance improves.
The objective is narrower than making every employee memorize identical warning signs. It is to build reliable decisions in the situations each person actually faces.
How Can Security Teams Measure Spear Phishing Risk Reduction?
Risk reduction requires more than completion rates. A useful measurement loop compares the initial spear phishing risk assessment with later behavior across four outcomes: susceptibility, reporting quality, reporting speed, and response accuracy. A lower click rate matters, and so does whether employees report genuine cyber threats, avoid flagging harmless messages, and provide enough context for analysts to act.
Phish triage adds operational evidence to the assessment. Reported emails can be classified by disposition and confidence, while security teams track whether employees identify malicious messages before submitting credentials or approving payments. Open-source intelligence (OSINT) signals add another dimension by showing which public details could support personalized spear phishing.
Combined with risk scores, those signals reveal whether exposure is falling because behavior improved or because the phishing simulation became easier. The loop should also extend beyond email, since AI-era social engineering coordinates email, voice, SMS, deepfake video, identity, and behavioral pressure.
A person who performs well against email phishing simulations can still trust a cloned executive voice or comply with an urgent smishing request. Multi-channel assessments expose those gaps, while repeated practice measures whether safer verification transfers from one channel to another. That gap is widening as employees adopt AI tools faster than governance reaches them.
According to the National Cybersecurity Alliance's 2025–2026 Oh Behave! The Annual Cybersecurity Attitudes and Behaviors Report, 58% of employed participants reported receiving no training on the security or privacy risks of AI tools, despite 65% now using AI and 43% admitting to sharing sensitive work information with AI tools.
A continuous improvement cycle follows a clear sequence. Assess behavior, deliver targeted practice, repeat the relevant phishing simulation, review reporting and triage quality, update the risk score, and assign the next intervention. Each cycle should preserve the prior result so leaders can see whether a person, team, or role is improving over time, well beyond isolated pass-or-fail events.
How Should Leaders Communicate Spear Phishing Assessment Results?
Leadership communication should translate human-risk signals into business decisions. Executives need to know which roles face the highest exposure, which attack paths remain open, how quickly employees report suspicious activity, and what corrective action is underway. A department with a high phishing simulation failure rate is a priority group requiring better scenarios, clearer verification procedures, or more frequent practice.
The report should separate activity from outcome, because completion shows participation while reduced susceptibility and faster, higher-quality reporting show behavioral change. Leaders should review trends by department and cyberattack channel, then assign accountable owners across security, finance, human resources, and business operations.
Ownership must be explicit. The human-risk manager should own the assessment methodology and the learning response, security operations should own phish triage and escalation, and business leaders should reinforce verification for payments, credential resets, and sensitive-data transfers. Reassessment should occur monthly for high-risk roles, quarterly for the broader workforce, and immediately after a material incident or major organizational change.
Behavior changes when practice follows the exact decision that created exposure rather than the annual calendar. Adaptive Security assigns that practice automatically from documented spear phishing assessment findings.
How Adaptive Security Operationalizes a Spear Phishing Risk Assessment

Adaptive Security closes the distance between a spear phishing risk assessment and the behavior it is supposed to change. Assessment findings flow directly into role-specific cybersecurity awareness training, OSINT-driven spear phishing scenarios, and voice, SMS, and deepfake exercises aimed at the finance approvers, executive assistants, and privileged administrators who carry the most authority. Every result updates an employee risk score, so exposure is measured where it concentrates, avoiding an organization-wide average that flatters the program.
Detection and human behavior operate as one system on the Cloud Email Security side. Dual machine learning and large language model detection catches AI-generated phishing and BEC that native Google and Microsoft filters miss, activates through API without MX record changes, and removes confirmed cyber threats automatically across every inbox they reach. Each detected cyberattack then feeds the targeted employee's risk profile and triggers the practice that matches the lure they actually received.
Evidence follows the same loop. Phish Triage records classification, disposition, and containment speed, Risk Monitoring tracks exposure by employee, department, and executive, and Compliance Training supplies the workforce-education records that SOC 2, HIPAA, and ISO 27001 assessors expect alongside behavioral proof. The result is a spear phishing risk assessment that produces remediation, retesting, and audit-ready documentation from the same evidence stream.
Assessment findings lose their value in the gap between a spreadsheet and a rehearsed employee decision. Adaptive Security closes that gap with detection, practice, and measurement combined.
Frequently Asked Questions About Spear Phishing Risk Assessment
What Is the Purpose of a Spear Phishing Risk Assessment?
A spear phishing risk assessment identifies where targeted deception could compromise people, technology, or business processes and turns those findings into prioritized remediation. It evaluates exposure, cyberattack likelihood, control strength, and business impact well beyond one simulated click, covering email, SMS, voice, identity, payment workflows, vendors, and reporting procedures. It also distinguishes inherent risk before controls from residual risk after controls. CISA recommends combining employee awareness, simulated cyberattacks, results analysis, and documented response actions in an anti-phishing program (CISA phishing guidance). The practical outcome is an evidence-based risk register with owners, deadlines, and retest criteria.
How Often Should an Organization Conduct a Spear Phishing Risk Assessment?
An organization should conduct a formal spear phishing risk assessment at least annually, with quarterly reassessments for high-risk environments and monthly pulse checks for changing exposure. A new assessment is also warranted after an incident, a major identity or email-control change, a merger, a workforce shift, or a material change to payment processes. Cadence should follow risk over habit, so recurring measurements of reporting quality, repeat susceptibility, response time, and control performance keep risk scores moving when the evidence changes.
What Is a Good Phishing Simulation Click Rate for Employees?
A good phishing simulation click rate is not a universal percentage. A lower rate is favorable, although it becomes meaningful only when paired with message difficulty, reporting rate, credential-submission rate, role risk, and repeat behavior. NIST created the Phish Scale because click rates alone do not show how difficult a simulated message was to detect (NIST Phish Scale). Treat any elevated result as an investigation trigger, avoiding any employee judgment, compare equivalent scenarios over time, and target coaching where behavior and business exposure overlap. The strongest measure is improving resilience across realistic channels rather than reaching an arbitrary zero.
How Long Does a Spear Phishing Risk Assessment Take?
A spear phishing risk assessment typically takes several weeks, while a narrow review can take a few days and a multi-channel enterprise assessment can take several months. Duration depends on scope, workforce size, data availability, technical-control testing, business-process reviews, legal approval, and the number of scenarios authorized. A credible assessment includes planning, exposure inventory, control validation, safe testing, analysis, leadership review, and remediation ownership, so compressing those activities into one click test produces incomplete evidence. The assessment is complete when material findings have accountable owners, deadlines, residual-risk ratings, and criteria for retesting.
How Is Spear Phishing Risk Calculated?
Spear phishing risk is calculated by combining cyber threat likelihood, target exposure, business impact, exploitability, and control strength, then comparing inherent risk with residual risk after controls. A practical model is: inherent risk = likelihood × exposure × impact. Rate each dimension on a consistent 1-to-10 scale, apply a control-strength factor from 0.0 to 1.0, and calculate residual risk = inherent risk × (1 − control strength). Keep people, technology, and process scores visible, and use the resulting register to fund targeted controls rather than to rank individual employees.
Spear phishing findings decay into a filed report unless something converts them into rehearsed, measurable employee behavior. Adaptive Security makes that conversion a routine, auditable part of operations.
As experts in cybersecurity insights and AI threat analysis, the Adaptive Security Team is sharing its expertise with organizations.
Get started with Adaptive Security
Related articles

Interactive Phishing Simulation Tools: The Complete Guide for Testing Email, Voice, and Deepfake Threats

AI Phishing Simulation: How It Works, Key Metrics, and How to Build a Multi-Channel Program That Cuts Human Risk

How to Check Phishing Links Safely: A Practical Guide to Inspecting, Verifying, and Reporting Suspicious URLs
Get started