- A phishing email which can pwn you without user interaction is basically unheard of.
- Even malicious sites generally can't do anything bad simply by visiting them. (and yes, I'm aware browser exploitation exists, but it is exceedingly rare)
- Ultimately, it's entering your credentials in a malicious site which is what puts users at risk. A user must click a malicious link (sometimes two) and then intentionally enter their credentials into the malicious site.
Between this, and the fact that users must read emails, visit sites, and enter their credentials over and over, just to get through their workday, I believe the outcome is that user education doesn't amount to much. It would be much better if a normal user's workflow didn't usually require clicking on email links and then entering their credentials. The fact that this is required means that even a savvy users will eventually be tired / rushed / working on automatic and get owned.