Skip to content
SECURITYSQUAD
Back to the blog

Phishing: why awareness training alone is not enough – and what actually helps

2026-08-07 · by SECURITYSQUAD

Phishing: why awareness training alone is not enough – and what actually helps

You can invest a great deal in security technology and still come undone through a single email. Phishing succeeds because it does not attack the technology but the person in front of it. The usual answer to that is training. Except that answer does not survive scrutiny.

The uncomfortable evidence

Researchers from the University of Chicago and UC San Diego ran a controlled experiment over eight months across more than 19,500 employees of a large healthcare provider: ten simulated phishing campaigns, with random assignment of who received training. The results were presented at the IEEE Symposium on Security and Privacy in 2025.

The finding is sobering. Between recently completed awareness training and the likelihood of failing a phishing simulation there was no significant relationship. Embedded training – the learning page that appears after a click – reduced the likelihood of clicking by only around two per cent.

That does not mean training is pointless. It means training in the form practised almost everywhere does not solve the problem it is sold for. Anyone basing their phishing defence on annual click rates is measuring something that barely moves.

We say this as a provider that has awareness training in its portfolio. It does not change the numbers.

Why the old warning signs no longer work

"Watch out for spelling mistakes" was good advice for a long time. Today phishing emails are linguistically flawless, personalised and refer to real transactions – language models removed the last remaining hurdle. Attackers research their targets, imitate internal senders and pick the moment when a request for quick action does not stand out.

There is also a technical shift: modern attacks increasingly aim at session hijacking rather than passwords. An attacker sits between the user and the genuine sign-in service, relays everything – including the second factor – and then takes over the session. The user notices nothing, because they really did sign in successfully. No amount of scrutinising the sender address helps against that.

What actually works

The order matters: first the measures that hold even when somebody clicks.

Processes that make the click irrelevant. If a payment instruction or a change of bank details is always confirmed through a second, independent channel – a call back on the known number, not the one in the email – even a perfect forgery comes to nothing. This is the single most effective measure against CEO fraud and invoice fraud, and it costs nothing but discipline.

Phishing-resistant sign-in. Methods based on the FIDO2 standard – passkeys or hardware tokens – are bound to the genuine domain. They simply do not work on a cloned page, even when the user does everything wrong. Where you cannot roll this out everywhere, it belongs at least on privileged accounts and remote access. The BSI's 2025 report records a rise in credential theft; this is precisely where the measure bites.

Technical filtering that reduces contact. SPF, DKIM and DMARC against sender spoofing in your own domain, a visible marker for external senders, attachment inspection. Any email that never arrives needs nobody to recognise it.

Shrink the blast radius. Least privilege and segmentation decide what a compromised account can actually do. A click on a clerk's account is a different matter from one on an administrator's.

What training is genuinely good for

There is one thing training can reliably improve, and it is usually the least practised: reporting.

Not "spot the forgery" but "report it within thirty seconds without thinking about it, even if you already clicked". That capability cuts response time from hours to minutes – and with an account takeover, time is the only currency that counts.

Three things are needed for it:

  1. A reporting route that is easier than ignoring it. A button in the mail client, not a form on the intranet.
  2. Feedback. Someone who reports and never hears anything will not report next time.
  3. No sanctions. Punishing employees for clicks mainly ensures that incidents go unmentioned. A quick report of a mistake is worth more than any penalty – even if instinct says otherwise.

What this means for your simulations

Phishing simulations are not worthless, but they measure and train the wrong thing when the click rate is the only metric. Two other numbers make more sense:

  • Reporting rate – how many reported the email, regardless of whether they clicked?
  • Time to first report – how quickly does IT hear about it?

Both can genuinely be improved by training, and both matter in a real incident. The click rate barely does.

When we set up awareness programmes, we build them around those two numbers – and say up front what training cannot deliver. That is less comfortable than a promise, but it lasts longer.

As at August 2026. Study: Grant Ho et al., "Understanding the Efficacy of Phishing Training in Practice", IEEE Symposium on Security and Privacy 2025; field experiment over eight months with more than 19,500 employees. Credential theft figures per the BSI 2025 report.

Read more: Security awareness training · Zero Trust · Ransomware protection · Cyber Risk Check