phishing
July 27, 2026 · Last updated on July 20, 2026

Segmentation Like a Marketer: Why Finance and Engineering Need Different Campaigns, Not the Same One Twice

Segmentation Like a Marketer: Why Finance and Engineering Need Different Campaigns, Not the Same One Twice
# Phishing

Borrowed, Part 3: What marketing segmentation can teach phishing simulation targeting

Ant Davis
Ant Davis
Segmentation Like a Marketer: Why Finance and Engineering Need Different Campaigns, Not the Same One Twice
Borrowed, Part 3: Ideas taken from outside security and applied to awareness practice.
 Part one  of this series covered product design,  part two  covered memory research. This one goes to marketing, and a decades-old fix for a problem security awareness still hasn't solved: sending the same message to audiences who need completely different things from it.

No marketing team would send the same campaign to two audiences with completely different motivations, risk exposure and daily behaviour, and call it a strategy. Security awareness does this constantly. One phishing simulation, one training module, one set of messaging, sent to finance and engineering and everyone in between, as if a single narrative fits every job function equally well. It doesn't, and treating it as if it does is why so much content lands flat with at least half the audience it's aimed at.

Marketing solved this problem decades ago

Segmentation has a specific origin. Marketing consultant Wendell Smith proposed it in a 1956 paper as an alternative to treating the whole market as one audience, arguing that a mixed, varied market is really a number of smaller, more similar groups once you split it by what actually differentiates people, need, behaviour, risk tolerance, rather than averaging everyone into a single message. The idea won an industry award as the most significant marketing article of that year. Seventy years on, it's still how every marketing team builds a campaign. Security awareness never got the memo.
Security awareness rarely does this. Most programmes segment, if at all, by department name on a spreadsheet rather than by anything that actually changes what content should look like. The result is one invoice fraud simulation sent to a team that's never near an invoice, and one credential harvesting exercise sent to a team that would never fall for it because their day job already trains them to be suspicious of exactly that pattern.
I've built this properly before, and it works. HR gets targeted training on recruitment scams and payroll diversion fraud, the specific patterns that show up in their inbox and nowhere else. Finance gets contract fraud and business email compromise aimed at invoice changes, a completely different attack shape. Same organisation, same overall threat landscape, but a recruiter and an accounts payable clerk are never going to fall for the same email, so there's no reason to train them against it.

Why finance and engineering are not the same audience

Finance teams are targeted with invoice fraud, payment redirection, CEO impersonation asking for an urgent transfer. The attack exploits process and urgency, not technical naivety. The right simulation for finance tests whether someone will pause and verify a payment change through a second channel, not whether they can spot a dodgy link.
Engineering teams are targeted differently. Credential harvesting aimed at source code repositories, fake dependency packages, social engineering through developer tools and platforms like GitHub or package registries. The right simulation here looks nothing like an invoice email. It looks like a fake pull request notification or a spoofed CI/CD alert.
Send the invoice simulation to engineering and it barely registers, because it's not a pattern they encounter. Send the credential harvesting simulation to finance and the same problem applies in reverse. Both teams end up with simulation stats that look fine, and neither team has actually been tested against the thing most likely to catch them out.

Building segments that are actually usable

Full personalisation for every team isn't realistic for most programmes, and it isn't necessary. Marketers rarely go further than a handful of well-built segments, and the same applies here. Three or four groups, built around genuine differences, cover most of what matters:
By risk exposure - Groups handling money, sensitive data, source code or privileged access face different threats than groups that don't. Segment by what an attacker would actually want from that team, not by department name.
By technical fluency - A team that spends all day in ticketing systems and terminal windows will read a phishing attempt differently to a team whose main tool is email and a shared drive. Content pitched at the wrong fluency level either patronises or loses people.
By prior behaviour - Anyone who has clicked, reported well, or shown a pattern over time is a different audience to someone starting from scratch. Reusing the same content regardless of history wastes the people who've already progressed past it.
By day-to-day workflow - What tools does this team actually live in. What would a convincing attack look like inside that workflow specifically, rather than in a generic inbox.

The one campaign, two audiences problem

Anywhere else in a business, sending identical messaging to audiences with opposite needs and calling it strategy would be seen as a failure of basic targeting. In security awareness it's still the default. Building even three or four real segments, based on exposure and workflow rather than org chart labels, does more for engagement than another year of the same simulation sent to everyone at once.
Coming up in Borrowed, Part 4: What SaaS products get right about onboarding that HR gets wrong on a new starter's first day.



Comments (0)
Popular
avatar

Dive in

Related

Content
Phish of the Week 27th of July
By Mette Luntama • Jul 27th, 2026 Views 3
Content
Phish of the Week 20th of July
By Mette Luntama • Jul 20th, 2026 Views 18
Content
Built In A Day: What Happened When We Stopped Planning and Started Building
By Ant Davis • Jul 23rd, 2026 Views 69
Content
What Spaced Repetition Research Says About Why Annual Training Doesn't Stick
By Ant Davis • Jul 20th, 2026 Views 23
Content
Phish of the Week 27th of July
By Mette Luntama • Jul 27th, 2026 Views 3
Content
Built In A Day: What Happened When We Stopped Planning and Started Building
By Ant Davis • Jul 23rd, 2026 Views 69
Content
What Spaced Repetition Research Says About Why Annual Training Doesn't Stick
By Ant Davis • Jul 20th, 2026 Views 23
Content
Phish of the Week 20th of July
By Mette Luntama • Jul 20th, 2026 Views 18
Privacy Policy
Your Privacy Choices