---
title: Phishing Education - Maybe 'Best Practice' is not Best After all
description: Good phishing awareness training can educate, entertain, improve your security program and build trust.  Unfortunately, many programs do just the opposite.
image: https://mmisac.org/hubfs/1755021026478.png
---

[Skip to the main content.](https://mmisac.org/mm-isac-blog/phishing-education-maybe-best-practice-is-not-best-after-all#main-content)

[![Mining and Metals Logo without wording](https://mmisac.org/hubfs/Mining%20and%20Metals%20Logo%20without%20wording.svg "Mining and Metals Logo without wording")](https://mmisac.org?hsLang=en)

[![Mining and Metals Logo](https://mmisac.org/hs-fs/hubfs/Mining%20and%20Metals%20Logo.jpg?width=14572&height=7199&name=Mining%20and%20Metals%20Logo.jpg "Mining and Metals Logo")](https://mmisac.org?hsLang=en)

- [Home](https://mmisac.org)
- [About MM-ISAC](https://mmisac.org/about)
- [Membership](https://mmisac.org/membership)
- [Partnership](https://mmisac.org/partnership)
- Programs 
    - [Supply Chain Resilience](https://mmisac.org/supply-chain-resilience)
    - [Working Groups](https://mmisac.org/working-groups)
- [Events](https://mmisac.org/events) 
    - [MM-ISAC Annual Conference](https://mmisac.org/conference_2026)
- [MM-ISAC Blog](https://mmisac.org/mm-isac-blog)
- [Contact Us](https://mmisac.org/contact-us)
- [Member Portal](https://mm-isac.cyware.com/webapp/auth/login/)

Search

Toggle Menu

Search

Toggle Menu

- [Home](https://mmisac.org)
- [About MM-ISAC](https://mmisac.org/about)
- [Membership](https://mmisac.org/membership)
- [Partnership](https://mmisac.org/partnership)
- Programs
  
  
  
    - [Supply Chain Resilience](https://mmisac.org/supply-chain-resilience)
    - [Working Groups](https://mmisac.org/working-groups)
- [Events](https://mmisac.org/events) 
    - [MM-ISAC Annual Conference](https://mmisac.org/conference_2026)
- [MM-ISAC Blog](https://mmisac.org/mm-isac-blog)
- [Contact Us](https://mmisac.org/contact-us)
- [Member Portal](https://mm-isac.cyware.com/webapp/auth/login/)

[Facebook](https://mmisac.org/mm-isac-blog/phishing-education-maybe-best-practice-is-not-best-after-all#0) [Instagram](https://mmisac.org/mm-isac-blog/phishing-education-maybe-best-practice-is-not-best-after-all#0) [Linkedin](https://www.linkedin.com/company/mmisac/) [X](https://mmisac.org/mm-isac-blog/phishing-education-maybe-best-practice-is-not-best-after-all#0) [YouTube](https://mmisac.org/mm-isac-blog/phishing-education-maybe-best-practice-is-not-best-after-all#0) [Medium](https://mmisac.org/mm-isac-blog/phishing-education-maybe-best-practice-is-not-best-after-all#0)

 2 min read

# Phishing Education - Maybe 'Best Practice' is not Best After all

[![Picture of Rob Labbé](https://mmisac.org/hubfs/AGC_Speakers/ROBL%20WebSpeaker2.svg) Rob Labbé](https://mmisac.org/mm-isac-blog/author/rob-labbé) :  Updated on October 28, 2025

[Guidence](https://mmisac.org/mm-isac-blog/tag/guidence) [Resiliency](https://mmisac.org/mm-isac-blog/tag/resiliency) [Phishing](https://mmisac.org/mm-isac-blog/tag/phishing) [Training](https://mmisac.org/mm-isac-blog/tag/training) [Mental Health](https://mmisac.org/mm-isac-blog/tag/mental-health)

![Phishing Education - Maybe 'Best Practice' is not Best After all](https://mmisac.org/hubfs/1755021026478.png)

As security practitioners and leaders, we must contribute to the professionalization of our field by searching out data and evidence-based solutions for our organizations.  For too long, we have been advocating solutions based on best practice, or “That is just the way it is done.”   As time goes on, when studies are done, we often find that the results do not back those conclusions, and we must change.

Last week at Blackhat, a group of researchers released the results of their study into the efficacy of phishing training.  You can read that study [here](https://arianamirian.com/docs/ieee-25.pdf?utm_medium=email&_hsenc=p2ANqtz-9w7jFpyxVGKLasTaJj56zIOTu4hZXdYWQl-mJizXzWI6ZjYB9saU7iMsJSP5ZnGytE9oow1lHBl3GrsCoAd6DDzKXRWA&_hsmi=375510314&utm_content=375510314&utm_source=hs_email).  By applying medical research standards to the problem, they ran an 8-month experiment, randomly separated a significant sample size of over 19,000 employees into a control group receiving no training and four other groups receiving the most common methodologies of security training today.

The results of the research are interesting and should give us all lots to think about.  The key points I pulled out are here:

1. The person who creates the lure message controls the failure rate.  The better the lure, the more people fail.  This leaves the results open to manipulation from the person controlling the lure.
2. Over the 8 months, most of the users failed at least once, leading to the conclusion that over a sufficiently long period, most people will click on something.
3. The frequency of cybersecurity training had no observable benefit.  The percentage of users who failed the test was not markedly different for those who had the training that day or those who had received the training more than a year ago.  The overall average improvement was 1.7% for those who did the training vs the control.
4. In some cases, the training was counterproductive, with employees being slightly more likely to click on the lures than the control group.

(Ho et al., 2025)

Now, this does not mean we should not train our users, but the data indicates we cannot train them out of this problem.  So, what should we do?  I propose that our industry focus on a couple of key areas:

- Security engineering – A user being human and clicking on a link should not, in and of itself, cause a material breach.
- Security training must focus on teaching users to report.  1% of phishing recipients reporting phishing to your team will be more effective than the sub-10% click rate you brag about to your management team.  Reward your reporters, get rid of the wall of shame, and replace it with a wall of fame. Send them gift cards (real ones, not phishing tests) and celebrate them for the cyber heroes they are.

 

By getting away from the game of “gotcha” that we have built into our phishing training programs, we will also realize another happy side effect.  Trust.  In any organization, cybersecurity advances at the speed of trust.  We don’t build trust with users by fooling, tricking, or making them feel dumb.  We build trust by supporting, showing empathy, and helping them reach their business goals.  For too long, phishing training has been an obstacle to building trust.  It is long past time to put gotcha-based phishing training and simulation to pasture – now we have the data that proves it is as ineffective as it is damaging.

- [Tweet](https://twitter.com/share)

[![Building a Phishing Program](https://mmisac.org/hubfs/1741482178116.png)](https://mmisac.org/mm-isac-blog/building-a-phishing-program?hsLang=en)

 1 min read

#### [Building a Phishing Program](https://mmisac.org/mm-isac-blog/building-a-phishing-program?hsLang=en)

![Picture of Rob Labbé](https://mmisac.org/hubfs/AGC_Speakers/ROBL%20WebSpeaker2.svg) [Rob Labbé](https://mmisac.org/mm-isac-blog/author/rob-labbé) : Mar 8, 2025, 12:00:00 AM

Phishing is a significant compromise vector for all companies in all industries. At theMining and Metals ISAC annual conference in November, we...

[Guidence](https://mmisac.org/mm-isac-blog/tag/guidence) [Incident Response](https://mmisac.org/mm-isac-blog/tag/incident-response) [Phishing](https://mmisac.org/mm-isac-blog/tag/phishing) 

[Read More](https://mmisac.org/mm-isac-blog/building-a-phishing-program?hsLang=en)

[![Effective Incident Response Starts Long Before the Incident](https://mmisac.org/hubfs/Planning%20P.jpg)](https://mmisac.org/mm-isac-blog/effective-incident-response-starts-long-before-the-incident?hsLang=en)

 1 min read

#### [Effective Incident Response Starts Long Before the Incident](https://mmisac.org/mm-isac-blog/effective-incident-response-starts-long-before-the-incident?hsLang=en)

![Picture of Rob Labbé](https://mmisac.org/hubfs/AGC_Speakers/ROBL%20WebSpeaker2.svg) [Rob Labbé](https://mmisac.org/mm-isac-blog/author/rob-labbé) : Dec 5, 2025, 1:35:29 AM

Cyber incident response is often viewed as a technical domain, with practitioners skilled in malware reverse engineering, network and host forensics,...

[Guidence](https://mmisac.org/mm-isac-blog/tag/guidence) [Incident Response](https://mmisac.org/mm-isac-blog/tag/incident-response) [Resiliency](https://mmisac.org/mm-isac-blog/tag/resiliency) [Training](https://mmisac.org/mm-isac-blog/tag/training) 

[Read More](https://mmisac.org/mm-isac-blog/effective-incident-response-starts-long-before-the-incident?hsLang=en)

[![Psychological First Aid – A Skill Needed in Resilience](https://mmisac.org/hubfs/AI-Generated%20Media/Images/The%20image%20depicts%20a%20diverse%20group%20of%20IT%20professionals%20gathered%20in%20a%20modern%20welllit%20conference%20room%20They%20are%20engaged%20in%20a%20training%20session%20focused%20on%20P.png)](https://mmisac.org/mm-isac-blog/psychological-first-aid-a-skill-needed-in-resilience?hsLang=en)

 1 min read

#### [Psychological First Aid – A Skill Needed in Resilience](https://mmisac.org/mm-isac-blog/psychological-first-aid-a-skill-needed-in-resilience?hsLang=en)

[Beatrix (Trixie) Bitter](https://mmisac.org/mm-isac-blog/author/beatrix-trixie-bitter) : Oct 13, 2025, 12:00:00 AM

When a cyberattack strikes, the immediate focus is often on technical recovery: restoring systems, protecting data, and resuming operations. But what...

[Resiliency](https://mmisac.org/mm-isac-blog/tag/resiliency) [Mental Health](https://mmisac.org/mm-isac-blog/tag/mental-health) 

[Read More](https://mmisac.org/mm-isac-blog/psychological-first-aid-a-skill-needed-in-resilience?hsLang=en)

[![Mining and Metals Logo without wording](https://mmisac.org/hubfs/Mining%20and%20Metals%20Logo%20without%20wording.svg)](https://www.mmisac.org?hsLang=en)

- Privacy Policy

© 2026 Global Mining and Metals Information Sharing and Analysis Centre

Linkedin YouTube 

Return to top

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Rob Labbé",
    "url" : "https://mmisac.org/mm-isac-blog/author/rob-labbé"
  },
  "dateModified" : "2025-10-28T13:17:15.691Z",
  "datePublished" : "2025-08-12T06:00:00.000Z",
  "headline" : "Phishing Education - Maybe 'Best Practice' is not Best After all",
  "image" : [ "https://mmisac.org/hubfs/1755021026478.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://mmisac.org/mm-isac-blog/phishing-education-maybe-best-practice-is-not-best-after-all",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://mmisac.org/hubfs/Mining%20and%20Metals%20Logo%20-%20200px%20Wide.jpg"
    },
    "name" : "Global Mining and Metals Information Sharing Analysis Centre"
  }
}
```