Part 12 The Reckoning/Defense
Hardening the Organization: What Security Training Actually Achieves
Measure reporting, not click rate. Blame-based training suppresses the exact behaviour that limits damage, and controls beat education under load.
The organizational version of everything in Part 11 is training, and the evidence on training is more mixed than the industry that sells it suggests.
Longitudinal studies of simulated phishing programs find that click rates fall with training and continued simulation, and that the effect decays without reinforcement. That is the honest summary: training works, modestly, while it is maintained.
Two findings complicate the picture and they are the reason this chapter exists.
The first concerns the metric. Most programs measure click rate, and click rate is the wrong primary measure. What limits damage in a real incident is not whether someone clicked but whether they reported it, and how fast — because the response window for a fraudulent payment or a compromised credential is measured in hours. A program that reduces clicks by ten percent while suppressing reporting has made the organization less safe.
And suppression is exactly what blame-based delivery produces. Programs that name and shame people who fail simulations, or that attach performance consequences, teach employees that a mistake is dangerous to disclose, which is the opposite of the required behavior. Several studies have found that punitive framing reduces reporting.
The second complication is susceptibility variance. People are not equally vulnerable at all times. Chapter 329's material applies directly: susceptibility rises with workload, time pressure, fatigue and stress. Which means that a person who has passed a hundred simulations will fail on the day they are covering for a colleague, running late, and have forty unread messages — and that day is when the real attack arrives, because attackers time them to quarter-end, to holidays, and to known organizational events.
The conclusion the evidence supports is that education is a supplement to procedural controls rather than a substitute for them.
The controls that actually hold are the ones from chapter 319 and do not depend on anyone's state. Out-of-band callback verification for any change to payment details, with no exceptions for seniority — the exception for seniority is the attack. Dual control on payments above a threshold. Enforced separation between the person who changes bank details and the person who approves payment. Hardware-backed multi-factor authentication, which defeats credential phishing regardless of whether the credential was given up.
And the cultural requirement, which is the cheapest and the most often missed: reporting a mistake early has to be rewarded, visibly, including when the person clicked.
This counters Law 19.
The conclusion the evidence supports is that education is a supplement to procedural controls rather than a substitute for them.
1The case
2The mechanism
3What this chapter covers
- The Threat Pattern: Human Layer as Attack Surface
- Early Warning Signals & Organizational Tells
- Verified Case: Longitudinal Phishing Training Studies
- Detection Protocol: Measure Reporting, Not Just Clicks
- Counter-Response: Continuous Training Plus Hard Controls
Counters Law 19 — Let the Crowd Deliver Your Message