Security awareness is not a control: Rethinking human risk in enterprise security
Organizations have been responding to phishing, business email compromise, and credential theft in essentially the same manner for over ten years. They essentially follow a playbook that involves investing in awareness training, running phishing simulations, and requiring employees to https://www.csoonline.com/article/4152631/security-awareness-is-not-a-control-rethinking-human-risk-in-enterprise-security.html
Security awareness is not a control: Rethinking human risk in enterprise security

Training people to spot phishing is great for culture, but it's a poor safety net; real security means building systems that don't break when someone has a bad day.

CSO Online