Ask most employees if they could spot a phishing email and they'll say yes. Research consistently shows they're wrong — not because they're careless, but because phishing has evolved far beyond the Nigerian prince emails that trained our intuition.
Proofpoint's 2023 State of the Phish report found that 84% of organisations globally experienced at least one successful phishing attack in 2023. CERT NZ data shows phishing as the most reported incident type year after year, with NZ businesses consistently among the targets.
The problem isn't awareness. It's the gap between what employees think they'd recognise and what they actually click on under normal working conditions.
Why modern phishing bypasses trained intuition
The "obvious" signs employees are taught to look for — misspelled domains, strange formatting, unsolicited attachments — have largely been eliminated by sophisticated campaigns.
Business email compromise uses compromised legitimate accounts or near-perfect domain spoofs. The email looks exactly like it came from your CEO or your accountant, because it almost did.
QR code phishing (quishing) bypasses email scanning tools entirely. A legitimate-looking document with a QR code redirecting to a credential harvesting page doesn't trigger any filters.
Adversary-in-the-middle (AiTM) attacks proxy the real login page in real time. The user enters their credentials on what appears to be the real Microsoft login page. The attacker captures the session token, bypassing even MFA.
AI-generated spear phishing — Large language models now produce flawless, contextually relevant phishing emails at scale. The grammatical errors that used to be a reliable signal are gone. The ACSC's 2023 Cyber Threat Report explicitly flags AI-enabled social engineering as an emerging threat to Australian and NZ businesses.
The confidence gap in numbers
A Stanford University/Tessian study found that 88% of data breaches are caused by human error — not malicious insiders, not sophisticated zero-days. People clicking things they shouldn't.
The same research found that employees click on phishing emails most often:
- When they're distracted or under time pressure
- When the email references something familiar (a known supplier, a current project, a colleague's name)
- When the request creates urgency or social pressure
None of these conditions are unusual. They're Tuesday morning.
What actually reduces click rates
Awareness alone — telling people "phishing exists and is bad" — doesn't move the needle. What works is simulated phishing campaigns combined with immediate, contextual training.
When an employee clicks a simulated phishing link and is immediately taken to a short module explaining exactly why that email was suspicious and what the red flags were, click rates drop measurably. Verizon's DBIR 2023 shows organisations with regular phishing simulation see repeat clicker rates fall from ~33% to under 5% over 12 months.
The key word is *regular*. Annual training is not enough. The research shows effect decay within 4–6 months — which means quarterly campaigns at minimum.
What to measure
- Click rate on simulated phishing (baseline + trend)
- Report rate — are employees reporting suspicious emails, not just ignoring them?
- Repeat clickers — who has clicked multiple simulations? They need targeted intervention, not just more of the same training
- Time to report — a fast-reporting culture is as valuable as a low-click rate
For a broader look at how to structure training that addresses all of this, see our guide on phishing training for employees. SecureAZ includes simulated phishing campaigns, auto-enrolled remediation training, and manager dashboards that show you exactly where your exposure is. Start free.