Phishing is still the front door. Here is what to train for.
Phishing succeeds because it exploits routine, not ignorance. Training that works targets the moments where routine is easiest to hijack.

Phishing remains the most common way attackers get their first foothold. Not because people are careless, but because a convincing message arrives in the middle of a busy day and asks for something that seems entirely ordinary.
The three patterns that actually land
- The invoice or payment change. A known vendor emails new banking details. This is the costliest pattern we see, because the money leaves voluntarily.
- The authority request. A message appearing to come from an owner or partner asks for gift cards, a wire, or a file, marked urgent and requesting discretion.
- The credential prompt. A login page that looks exactly like your Microsoft 365 sign-in, reached through a link in a shared document notification.
Why annual training does not work
A single yearly session is forgotten within weeks. Short, frequent reinforcement with realistic simulation performs far better, because it keeps the pattern recognition fresh at the moment it is needed.
Simulations should also be treated as measurement rather than a test people can fail publicly. The goal is a staff that reports suspicious messages readily, and blame discourages reporting.
Technical controls carry the rest
Training reduces the click rate; it will never eliminate it. Inbound filtering, impersonation protection, link rewriting, and multi-factor authentication ensure that a single click is not sufficient to cause an incident.