This is an excessively pessimistic take on security training. How many spear phishing attempts have been thwarted because the employee knew better?
It’s not a solution to the problem, but it certainly helps.
It’s not a solution to the problem, but it certainly helps.
My gut feeling is for engineers, the phising training that most companies use is wholly ineffective at doing anything, and in particular it is especially ineffective against targeted attacks. But i have yet to see any research one way or another.
I suspect less technical users might benefit from such training a bit more (but still not that much)