MALWARE AND PHISHING CyberArtical Editorial Team

What phishing awareness training can and cannot change

Employees seated around tables in a small meeting room during a training session, with a whiteboard at the front

Phishing training is easy to buy and easy to justify. It is much harder to say honestly what it achieves, and articles that attach a confident percentage to it are usually quoting a vendor’s own campaign data back at you. Neither CISA nor the FTC publishes a figure for how much awareness training reduces real-world compromise, so this piece does not offer one either. What follows is what the guidance actually supports.

Read this before buying a training package

  • No CISA or FTC consumer guidance states a percentage reduction from phishing awareness training. Treat any such figure as unsourced unless the source is named.
  • CISA does publish a teachable three-step response: resist clicking, report, delete — and do not reply.
  • CISA’s out-of-band rule is the one behaviour worth drilling: “Look up another way to contact the company or person directly.”
  • The #StopRansomware Guide’s first control is phishing-resistant MFA for email, VPNs and critical-system accounts — a control that works when training fails.
  • CISA notes AI-written lures now have perfect grammar and spelling, which retires the tell most training decks are still built on.

The claim you have heard

The familiar version runs: run a simulated phishing campaign, measure the click rate, run training, watch the click rate fall, and report the difference as risk reduced. It produces a chart that goes the right way, which is why it is popular.

What it measures is narrower than it sounds. A click rate is the response of a specific group to a specific simulated email on a specific day, sent by a system they may already have learned to recognise. It is a measure of the exercise, not of the threat.

What the guidance actually specifies

CISA’s phishing page does not talk about awareness scores. It gives a response sequence: if you suspect phishing, resist the temptation to click on links or attachments; report it using your mail client’s report option or the report spam button; then delete the message, without replying or clicking anything.

It also gives one verification rule, and it is the only instruction in the whole set that does not rely on the reader correctly judging a message: look up another way to contact the company or person directly. If a training session teaches one thing, that should be it.

For prevention, CISA’s #StopRansomware Guide reaches for technical controls first — phishing-resistant MFA for email, VPNs and accounts that access critical systems; offline, encrypted, regularly tested backups; and regular patching. Those are the measures whose effect does not vary with how well anyone slept.

What training can realistically do

This section is reasoning rather than a sourced claim, and is offered as such. Training plausibly helps in three narrow ways. It gives people a name for what they are looking at. It gives them a specific action to take instead of a vague sense of unease. And it establishes that reporting a mistake quickly is welcome rather than punished, which shortens the window between a click and a response.

That third effect is the one worth designing for. The gap between an incident starting and anyone knowing about it is the variable an organisation can actually influence, and it depends far more on culture than on curriculum.

Measuring it without inventing numbers

  1. Count reports, not clicks. A rising number of reported suspicious messages is a working reporting channel, not a worsening threat.
  2. Measure time-to-report on real incidents — from the moment someone acted to the moment someone was told.
  3. Check whether staff know the out-of-band rule by asking, rather than by testing them with a fake email.
  4. Audit the controls that do not depend on behaviour: is phishing-resistant MFA on the email accounts, are backups offline and restorable, is patching current?
  5. Record what you cannot measure, and say so, rather than borrowing a percentage from a marketing page.

Why “the human is the weakest link” keeps circulating

It is a comfortable framing for everyone except the human. It converts an architectural problem — that a single stolen password is enough to reach an email account — into a training problem, which is cheaper to address and easier to be seen addressing.

CISA’s own AI caveat undercuts it. If some phishing emails now arrive with perfect grammar and spelling, then a reader who fails to spot one has not been careless; they have been given a task that no amount of attention reliably completes. The honest response is to keep the training short and useful, and to spend the rest of the effort on the controls that hold when attention runs out.

There is a version of training worth running, and it is short. Teach the response sequence, teach the out-of-band rule, name the person to tell, and promise that reporting a mistake quickly carries no penalty. Everything beyond that is competing for attention with the technical controls that would have held anyway.

Sources: CISA — Recognize and report phishing · CISA — #StopRansomware Guide · FTC — How to recognize and avoid phishing scams · CISA — Multi-factor authentication

Reviewed 27 August 2026 by the CyberArtical editorial team against primary guidance from CISA and the FTC. Security guidance changes over time; where our earlier version of this page said something different, we say so in the article rather than editing it out quietly.

More Stories