The organizational version of everything in Part 11 is training, and the evidence on training is more mixed than the industry that sells it suggests.
Longitudinal studies of simulated phishing programs find that click rates fall with training and continued simulation, and that the effect decays without reinforcement. That is the honest summary: training works, modestly, while it is maintained.
Two findings complicate the picture and they are the reason this chapter exists.
The first concerns the metric. Most programs measure click rate, and click rate is the wrong primary measure. What limits damage in a real incident is not whether someone clicked but whether they reported it, and how fast — because the response window for a fraudulent payment or a compromised credential is measured in hours. A program that reduces clicks by ten percent while suppressing reporting has made the organization less safe.
And suppression is exactly what blame-based delivery produces. Programs that name and shame people who fail simulations, or that attach performance consequences, teach employees that a mistake is dangerous to disclose, which is the opposite of the required behavior. Several studies have found that punitive framing reduces reporting.
The second complication is susceptibility variance. People are not equally vulnerable at all times. Chapter 329's material applies directly: susceptibility rises with workload, time pressure, fatigue and stress. Which means that a person who has passed a hundred simulations will fail on the day they are covering for a colleague, running late, and have forty unread messages — and that day is when the real attack arrives, because attackers time them to quarter-end, to holidays, and to known organizational events.
The conclusion the evidence supports is that education is a supplement to procedural controls rather than a substitute for them.
The controls that actually hold are the ones from chapter 319 and do not depend on anyone's state. Out-of-band callback verification for any change to payment details, with no exceptions for seniority — the exception for seniority is the attack. Dual control on payments above a threshold. Enforced separation between the person who changes bank details and the person who approves payment. Hardware-backed multi-factor authentication, which defeats credential phishing regardless of whether the credential was given up.
And the cultural requirement, which is the cheapest and the most often missed: reporting a mistake early has to be rewarded, visibly, including when the person clicked.
This counters Law 19.
Counters Law 19 — Let the Crowd Deliver Your Message