Is phishing simulation training worth the cost?
Cybersecurity training is failing because it focuses on phishing simulations that people learn to ignore. In my last company, we ran monthly mock attacks and everyone just clicked through the warnings. Real threats like ransomware and credential stuffing get far less attention than they deserve. Instead of testing employees with fake emails, shouldn't we be investing in better access controls and monitoring?