The Adversarial Mindset: The Phishing Economy
Phishing isn't a technical failure.
It's an economic one.
Despite better filters, stronger authentication, and endless awareness training, phishing continues to succeed at scale. Not because defenders are careless, but because attackers understand how people make decisions under pressure, and how to turn influence into profit.
The Phishing Economy reframes phishing as an adversarial system driven by persuasion, efficiency, and return on investment. Instead of cataloguing red flags or tools, this book examines how phishing really works, from psychological manipulation and identity abuse to monetisation and persistence, and where defenders actually have leverage.
Written for security practitioners and decision-makers, this book focuses on what happens after prevention fails.
In this book, you'll learn: Why phishing persists even in mature security environments
How attackers think, prioritise targets, and adapt their tactics
How identity, access, and trust are exploited after user interaction
Where high-signal detection opportunities actually appear
How response and containment reduce real-world impact
What resilient organisations do differently, by design
This is not a guide to spotting fake emails.
It is a guide to breaking the chain between influence and impact.
The Phishing Economy is built for professionals who manage phishing risk as a reality, not a compliance exercise. If you're responsible for detection, response, or security leadership, this book provides a mindset designed for how attacks actually unfold.
Part of The Adversarial Mindset series, this book explores phishing not as a collection of tricks, but as a system, one that can be disrupted when defenders stop chasing perfection and start designing for resilience.