Most organizations have been running phishing awareness training for years. Many still get compromised through email. That is not usually because the training was bad — it is because the threat moved to attacks that training cannot stop.
The practical question for leadership is no longer how to make employees better at spotting fakes. It is which controls still work when an employee does everything right and is deceived anyway.
1. What changed
Three shifts matter more than the rest.
The obvious tells are gone. Poor grammar, awkward phrasing and generic greetings were never a reliable signal, and they are now absent. Messages can be drafted fluently, in context, referencing real projects and real colleagues drawn from public sources.
Attackers proxy the login rather than harvest it. Adversary-in-the-middle kits sit between the employee and the genuine sign-in page. The employee sees the real site, enters real credentials, approves a real multi-factor prompt — and the attacker captures the resulting session token. The second factor is satisfied legitimately, and stolen session cookies bypass it entirely on reuse.
The target moved past email. Voice calls to service desks, messages through collaboration platforms, and text to personal devices all avoid the controls concentrated on the inbox. Service desk password and MFA resets have become a reliable route into otherwise well-defended organizations.
2. Why awareness training stopped being the answer
Training still has a role. It is not a control. When a convincing message arrives, referencing a real deal, from a real supplier domain, at a plausible moment, a proportion of recipients will act on it — and the proportion never reaches zero.
Treating the workforce as the last line of defence puts the outcome of a security programme on the least controllable variable in it. The design goal should be that a click is survivable.
3. The controls that hold
- Phishing-resistant authentication. FIDO2 security keys and passkeys bind the credential to the legitimate domain, so a proxied login page cannot complete the exchange. This is the single control that defeats adversary-in-the-middle, and it defeats it structurally rather than probabilistically.
- Shorter, conditional sessions. If stolen tokens are the objective, session lifetime and re-evaluation on change of device, location or risk signal directly limit the value of the theft.
- A verification standard for the service desk. Identity checks that cannot be satisfied with information available on a professional networking profile. This is a process control, and it is frequently the weakest link.
- Out-of-band confirmation for payment changes. Any change to bank details or payment instruction confirmed through a known-good channel, on a number held on file rather than one supplied in the message.
- Detection on the consequences. Impossible-travel sign-ins, new mailbox forwarding rules, unusual mailbox permissions, and anomalous data access — the actions that follow a successful compromise.
4. Measure the response, not the click
Phishing simulation click rates are the most reported and least useful metric in this area. A low rate reflects the difficulty of the simulation more than the resilience of the organization, and a punitive programme mainly teaches people not to report.
More informative measures:
- What proportion of staff use phishing-resistant authentication — and does it cover administrators, finance and executives?
- How long between a report and containment?
- What proportion of recipients reported, rather than what proportion clicked?
- Can a compromised session be revoked across all applications, and how quickly?
Reporting rate is the number worth raising. It is the one that shortens response time on the real incident.
5. A reasonable order of work
Deploy phishing-resistant authentication to administrators, finance and executives first — the accounts where compromise is most consequential — then extend to the wider workforce. In parallel, fix service desk verification, because it is cheap and it is actively exploited. Then tighten session policy and build detection on post-compromise behaviour. Keep awareness training, but reposition it as a reporting mechanism rather than a barrier.
Design for the click that gets through
The organizations that handle phishing well are not the ones whose employees never fall for anything. They are the ones where a successful deception does not yield a usable credential, a long-lived session, or an unnoticed mailbox rule.
When email compromise is a board-level exposure
JLS Technology provides Fractional CISO leadership, cybersecurity strategy, and managed security operations for organizations strengthening identity and email defences without adding a full-time executive role immediately.
Explore Fractional CISO services · Review managed security services · Request a Strategic Technology Session
This article is general educational guidance, not legal advice, a certification, or a substitute for an organization-specific security assessment.


