EDIT: Voice mimicry scam? Verify via known channel before taking action.
EDIT: Voice mimicry scam? Verify via known channel before taking action.
I also think this is a much stricter standard than you're recognizing. In my company's last spearphishing test, they sent out a link purporting to be a company survey immediately after an all-hands meeting announcing there'd be a survey (the real survey link came a few hours later). Expecting that nobody will be distracted enough to fall for such a thing seems unrealistic no matter how well you train them.
The corporate security team sent out the email. It had a link with no actual content, giving an error, but that got you on the list of people with bad security behavior.
The trouble at my office was that most employees were highly capable security researchers. These are people who reverse engineer malware for pay and for fun. Of course they eagerly attempted to download from the link! They wanted fresh new malware. People would typically download via wget in a virtual machine on a PC without important data.
And there is no magic bullet. Trying to educate people gives some results, but mostly just prevents low effort phishing attack.
I have never seen pentest that include social engineering fail. (This might be just our customers. I would expect govt or infrastructure organization to be better)