The Phishing Training Elephant in the Room

Itwerx is a service-disabled veteran-owned managed IT and cybersecurity provider serving Seattle-area businesses, founded in 2005, and phishing training is one of the most commonly purchased, and most commonly misapplied, security controls its clients ask about.

A great deal of the time and money spent on phishing training is wasted effort, and it often creates friction between IT staff and the employees they are trying to protect. There are three reasons, and the second one is the one worth understanding in depth.

Reason one: most programs are punitive

Many training programs are built around making an end user feel foolish for not spotting something that sits well outside most people’s daily experience. That does not build a receptive audience for the message the training is trying to deliver.

Reason two: the survivor bias problem

Many programs build their training material out of real phishing emails, with the payloads and links “de-fanged” so they can be safely passed through to see who clicks. On the surface that looks like a sound idea. In practice it is a textbook case of survivor bias: if a phishing email could be detected and safely sanitized for training use, that is strong evidence it also could have been detected and blocked outright. The samples that make it into training are, almost by definition, the ones a technical control already had a shot at catching. That does not prepare anyone for the more dangerous case: the message that gets through precisely because nothing detected it.

Reason three: doing it properly is a lot of work

Building a training program that actually accounts for the first two problems, tailored to the real risks a given team faces rather than a generic template, takes more administrative effort than most IT teams have to spare. So it gets deployed largely as-is, mainly to satisfy a line item on a cybersecurity questionnaire, which compounds the first two issues rather than correcting for them. You will know before it is said here which vendor built its whole business model on exactly this administrative overhead.

So if your staff resents phishing training, now you know why.

Itwerx Corp is a service-disabled veteran-owned small business providing IT services across Seattle, Bellevue, Everett and Snohomish County. This is the kind of thing our cybersecurity work deals with – talk to us about yours.