Compliance Node Overview
MITRE ATT&CK T1566 (Phishing) describes adversary delivery of malicious content via electronic messages (email, instant messenger, SMS) to gain initial access. The technique has four sub-techniques: T1566.001 (Spearphishing Attachment), T1566.002 (Spearphishing Link), T1566.003 (Spearphishing via Service), and T1566.004 (Spearphishing Voice). Phishing accounts for the largest share of initial access vectors in modern breaches per IBM Cost of a Data Breach 2024. Compliance obligations include user awareness training (NIST 800-53 AT-2, ISO A.6.3), email security gateway configuration (NIS2 Article 21), and reporting under GDPR Article 33 and HIPAA Breach Notification Rule when phishing leads to data compromise.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1566/
SHA-256 integrity: d14f5963cea650c4f48aa02592d0a4919057f23b52f57427592da47a3e53f9aa
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1566: Phishing (https://attack.mitre.org/techniques/T1566/) - canonical technique description with 4 sub-techniques and 200+ documented adversary procedures
- NIST SP 800-53 Rev 5: AT-2 (Literacy Training and Awareness), IA-2 (Multi-Factor Authentication), SC-7 (Boundary Protection)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.