Back to feed
Dev.to
Dev.to
7/5/2026
Your Phishing Simulation Score Is 99%. Here's Why That Worries Me.

Your Phishing Simulation Score Is 99%. Here's Why That Worries Me.

Short summary

Phishing simulations show 1.5% click rates after years of training—unchanged by training. The problem: simulations are known tests, and attackers study the same compliance frameworks (NIST, ISO 27001) that organizations follow. Real breaches succeed through attacks that look nothing like simulations—voice phishing (+442%), social engineering, configuration errors—exploiting gaps between tools that each assume another layer checked the boundary.

  • Verizon DBIR: phishing simulation training shows zero correlation with reduced click rates
  • Attackers study public compliance frameworks (NIST, CIS, ISO 27001) and exploit assumed trust patterns
  • Real breaches (EtherRAT, Coinbase, Blue Shield) use attacks simulations don't train for—social engineering, voice phishing (+442% surge), configuration drift

Generated with AI, which can make mistakes.

Is this a good recommendation for you?

Comments

Failed to load comments. Please try again.

Explore more