Monday, December 15, 2025
No Result
View All Result
Shorouk Express
Advertisement
  • Home
  • World
  • Europe
  • Africa
  • Maghrab
  • Policies
  • Companies
  • Economy
  • Security & Defense
  • Sports
  • Technology
  • Culture
  • Home
  • World
  • Europe
  • Africa
  • Maghrab
  • Policies
  • Companies
  • Economy
  • Security & Defense
  • Sports
  • Technology
  • Culture
No Result
View All Result
Shorouk Express
No Result
View All Result
Home Technology

Employees learn nothing from phishing security training, and this is why

25 September 2025
in Technology
Reading Time: 4 mins read
0 0
A A
0
Employees learn nothing from phishing security training, and this is why
Share on FacebookShare on Twitter


MicroStockHub/iStock/Getty Images Plus

Follow ZDNET: Add us as a preferred source on Google.

ZDNET’s key takeaways

Phishing is a major and growing threat to businesses.But phishing awareness training has a minimal success rate.Researchers urge organizations to invest in countermeasures.

A new study has confirmed what many of us suspected — employee phishing training is simply not worth the effort. 

The study, conducted by UC San Diego Health and Censys researchers, found that phishing-related cybersecurity training programs had no effect on whether or not employees were duped by phishing emails. 

After analyzing the results of 10 different phishing email campaigns sent to over 19,500 employees at UC San Diego Health over eight months, the researchers found “no significant relationship between whether users had recently completed an annual, mandated cybersecurity training and the likelihood of falling for phishing emails.”

Also: Battered by cyberattacks, Salesforce faces a trust problem – and a potential class action lawsuit

The team also investigated whether embedded phishing training — when organizations send simulated phishing emails to see if their employees will fall for them — was effective. Simply put, it wasn’t, and there was almost no difference in failure rates for those who completed the training versus those who did not. The groups were separated by a reduced likelihood of falling for a phishing email of only 2%. 

This is especially concerning, given that phishing was found to be the leading cause of ransomware this year, fueled by infostealers and the abuse of AI tools, according to a new SpyCloud Identity threat report. Phishing was also the most reported attack vector by businesses participating in the research and was cited by 35% of affected organizations — up from 25% in 2024.

What is phishing? 

Phishing is a constant scourge and is a threat that impacts individuals, SMBs, and enterprises alike. Phishing campaigns often take the form of spray-and-pray fraudulent emails or targeted messages designed to elicit curiosity, panic, or fear in their recipients. 

By crafting messages that inspire fear or urgency, cybercriminals hope that their victims will not take a step back and think rationally, but will, rather, panic-click a button or hand over sensitive information that can be used in identity theft, to conduct fraudulent transactions, or for use in broader cybercrime. 

Also: Scammers are now faking the FBI’s own website – here’s how to stay safe

When the threat is so serious, and a phishing-related breach can lead to severe consequences for an organization — including data theft, destruction, financial consequences, ransomware deployment, and reputational harm — companies, naturally, will look for solutions. 

Phishing training programs are a popular tactic aimed at reducing the risk of a successful phishing attack. They may be performed annually or over time, and typically, employees will be asked to watch and learn from instructional materials. They may also receive fake phishing emails sent by a training partner over time, and if they click on suspicious links within them, these failures to spot a phishing email are recorded. 

Why phishing training doesn’t work

UC San Diego Health and Censys researchers said subject matter was important to the success of a phishing email in their study. For example, barely anyone clicked a link to update their Outlook password, whereas over 30% of participants clicked on a link in an email pretending to be an employer update to vacation policies. 

The longer a phishing scheme continued, the more likely an employee was to click a fraudulent link, rising from 10% of participants in month one to over 50% by the eighth month.

Also: This 2FA phishing scam pwned a developer – and endangered billions of npm downloads

“Taken together, our results suggest that anti-phishing training programs, in their current and commonly deployed forms, are unlikely to offer significant practical value in reducing phishing risks,” the researchers said.

According to the researchers, a lack of engagement in modern cybersecurity training programs is to blame, with engagement rates often recorded as less than a minute or none at all. When there is no engagement with learning materials, it’s unsurprising that there is no impact. 

Potential solutions

To combat this problem, the team suggests that, for a better return on investment in phishing protection, a pivot to more technical help could work. For example, imposing two or multi-factor authentication (2FA/MFA) on endpoint devices, and enforcing credential sharing and use on only trusted domains. 

Also: How passkeys work: The complete guide to your inevitable passwordless future

That’s not to say that phishing programs don’t have a place in the corporate world. We should also go back to the basics of engaging learners. As a former teacher, I would suggest that tabletop discussions, in-person seminars, and even gamification could provide the missing link between training and positive outcomes. 



Source link

Tags: employeesLearnphishingSecuritytraining
Previous Post

Starmer warns Burnham’s policies would cause ‘harm’ like Liz Truss

Next Post

German lawmakers end deadlock over top court judge

Related Posts

Google pulls AI-generated videos of Disney characters from YouTube in response to cease and desist
Technology

Google pulls AI-generated videos of Disney characters from YouTube in response to cease and desist

15 December 2025
How iRobot lost its way home | TechCrunch
Technology

How iRobot lost its way home | TechCrunch

15 December 2025
Delivery Hero Chair Kristin Skogen Lund backs CEO Niklas Östberg as the group explores asset sales amid shareholder pressure over its falling stock price (Kieran Smith/Financial Times)
Technology

Delivery Hero Chair Kristin Skogen Lund backs CEO Niklas Östberg as the group explores asset sales amid shareholder pressure over its falling stock price (Kieran Smith/Financial Times)

14 December 2025
The 5 most innovative tech products that surprised us this year (including a first for robot vacs)
Technology

The 5 most innovative tech products that surprised us this year (including a first for robot vacs)

14 December 2025
Shokz’s best running headphones drop to their lowest-ever price on Amazon
Technology

Shokz’s best running headphones drop to their lowest-ever price on Amazon

14 December 2025
Rivian wants your truck to talk back, and it’s happening in 2026
Technology

Rivian wants your truck to talk back, and it’s happening in 2026

14 December 2025
Next Post
German lawmakers end deadlock over top court judge

German lawmakers end deadlock over top court judge

EBRD projects 5.8% growth for Mongolia in 2025

EBRD projects 5.8% growth for Mongolia in 2025

  • Trending
  • Comments
  • Latest
Iran’s airports witness rising passenger traffic

Iran’s airports witness rising passenger traffic

28 February 2025
Antioch High School shooting: One dead and one hurt after gunman opens fire

Antioch High School shooting: One dead and one hurt after gunman opens fire

22 January 2025
Political Distrust and the Populist Alt-View Trap | naked capitalism

Political Distrust and the Populist Alt-View Trap | naked capitalism

19 December 2024
A Microsoft Office Lifetime License is now half the price of a single year paying for Microsoft 365

A Microsoft Office Lifetime License is now half the price of a single year paying for Microsoft 365

27 July 2025
Superfoods Spotlight – Boost Your Health with These Nutrient-Rich Wonders

Superfoods Spotlight – Boost Your Health with These Nutrient-Rich Wonders

18 April 2025
The Power of Plants – Unlocking Nature’s Healing Secrets

The Power of Plants – Unlocking Nature’s Healing Secrets

18 April 2025
Largest study reveals best treatment options for ADHD – news

Largest study reveals best treatment options for ADHD – news

15 December 2025
Perspectives for strategic partnership between Kazakhstan and EU discussed at round table in Brussels

Perspectives for strategic partnership between Kazakhstan and EU discussed at round table in Brussels

15 December 2025
Google pulls AI-generated videos of Disney characters from YouTube in response to cease and desist

Google pulls AI-generated videos of Disney characters from YouTube in response to cease and desist

15 December 2025
Azerbaijan’s current account balance shows positive growth

Azerbaijan’s current account balance shows positive growth

15 December 2025
This is Europe’s last chance to save chemical sites, quality jobs and independence

This is Europe’s last chance to save chemical sites, quality jobs and independence

15 December 2025
Hong Kong democracy advocate and media tycoon Jimmy Lai found guilty of sedition

Hong Kong democracy advocate and media tycoon Jimmy Lai found guilty of sedition

15 December 2025
Shorouk Express

Stay informed with Shorouk Express - your premier destination for global news, in-depth analysis, and updates on current events. Get the latest news from around the world delivered straight to you.

Categories

  • Africa
  • Companies
  • Culture
  • Economy
  • Europe
  • Health
  • Maghrab
  • Policies
  • Security & Defense
  • society
  • Sports
  • Technology
  • Uncategorised
  • Uncategorized
  • World

Latest Updates

  • Largest study reveals best treatment options for ADHD – news
  • Perspectives for strategic partnership between Kazakhstan and EU discussed at round table in Brussels
  • Google pulls AI-generated videos of Disney characters from YouTube in response to cease and desist
  • About Us
  • Advertise with Us
  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2024 Shorouk Express.
Shorouk Express is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • World
  • Europe
  • Africa
  • Maghrab
  • Policies
  • Companies
  • Economy
  • Security & Defense
  • Sports
  • Technology
  • Culture

Copyright © 2024 Shorouk Express.
Shorouk Express is not responsible for the content of external sites.