Phishing has been a known attack for decades, and it still works — not because people are careless, but because it's designed to exploit normal, reasonable behavior. A well-crafted message creates urgency ("your account will be locked"), impersonates someone trusted (a vendor, a colleague, an executive), and asks for exactly the kind of action people take dozens of times a day: click a link, open an attachment, confirm a payment.
Modern phishing has also gotten harder to spot on sight. The obvious spelling errors and broken logos of a decade ago are increasingly rare; attackers now use real branding, correct grammar, and — increasingly — AI-generated text that reads naturally. Visual inspection alone is no longer a reliable defense.
What actually helps: multi-factor authentication limits the damage even when a password is successfully phished, since a stolen password alone usually isn't enough to log in. Email filtering and link-scanning tools catch a real share of attempts before they reach an inbox at all. And a simple, well-known reporting process — one click to flag a suspicious email, no blame attached — means the one employee who does notice something off can protect everyone else, fast.
Training matters, but the framing matters more than the frequency. Training that shames people for clicking a link discourages reporting, which is the opposite of what you want — the goal isn't zero clicks ever, it's fast reporting when one happens. Simulated phishing exercises are most useful when they're paired with immediate, non-punitive feedback, not treated as a test to fail.
The realistic goal isn't an organization where no one ever falls for a phishing attempt — that's not achievable at any scale. It's an organization where a successful phish is caught and contained in minutes, not discovered weeks later.