The threat has outpaced the training

Every organization runs some version of security awareness training. Most of it is still built around a premise that stopped being true in 2023: that phishing emails contain typos, awkward grammar, and suspicious sender addresses that a careful reader can spot.

That premise is dead. The 2026 KnowBe4 Phishing by Industry Benchmarking Report puts the baseline phish-prone percentage at 33.1% — meaning one in three untrained employees will click, open an attachment, or enter credentials on a simulated phishing test. The FBI's Internet Crime Complaint Center (IC3) logged $3.04 billion in U.S. business email compromise (BEC) losses in 2025, a new record. And the APWG tracked 3.8 million phishing attacks over the same period.

What changed is not the volume alone. It is the quality. Generative AI now produces phishing emails that are grammatically flawless, contextually relevant, and styled to match internal communications. AI voice cloning needs as little as three seconds of public audio to replicate a person's voice convincingly enough to authorize a wire transfer. Deepfake video has moved from proof-of-concept to production-grade fraud tool. The Verizon 2026 Data Breach Investigations Report attributes 62% of confirmed breaches to the human element, with phishing accounting for 16% of initial access and pretexting adding another 6%.

The defense has to change with it. This guide covers the full landscape: the attack taxonomy, the AI-powered threats that make traditional detection training insufficient, the regulatory frameworks that now mandate specific anti-phishing controls, how to build a phishing simulation program that actually changes behavior, the technical controls that stop attacks before they reach a user, and the incident response process when one gets through.


Key Takeaways

  • Phishing is not one attack — it is a taxonomy of at least 12 distinct vectors (email, spear, whaling, BEC, smishing, vishing, quishing, clone, AitM, evil twin, watering hole, search engine poisoning), each requiring different defenses.
  • AI-generated phishing emails now contain zero grammatical tells. Defense must shift from "spot the mistake" to "follow the verification process."
  • Regulatory requirements are specific and enforceable: NIST SP 800-53 Rev 5 (AT-2), HIPAA §164.308(a)(5), PCI DSS 4.0 (12.6 and 5.4.1), FTC Safeguards Rule, and CMMC 2.0 Level 2 all mandate security awareness training with explicit phishing components.
  • A well-run phishing simulation program reduces click rates from 33% to under 5% within 12 months — but only if simulations run monthly with immediate just-in-time training at the point of failure.
  • Technical controls (DMARC at p=reject, DKIM, SPF, phishing-resistant MFA via FIDO2/passkeys) are not optional supplements to training — they are co-equal defenses. Countries with national DMARC mandates saw phishing success rates drop from 69% to 14%.
  • NIST SP 800-63-4 (July 2025) formally deprecates SMS OTP and downgrades email OTP, making FIDO2 passkeys the standard for phishing-resistant authentication.

The phishing attack taxonomy

Understanding the attack types is not academic — each vector exploits a different trust relationship and requires a different combination of human awareness and technical controls. Here is the working taxonomy as of mid-2026.

Email phishing (mass campaigns)

The broadest category. Attackers send thousands or millions of messages impersonating a trusted brand — a bank, a shipping carrier, a SaaS provider — hoping a small percentage of recipients will click. The economics are simple: at scale, even a 1% click rate is profitable.

What makes it dangerous now: 82.6% of phishing emails now contain AI-generated content, making them indistinguishable from legitimate corporate communications on linguistic quality alone.

Spear phishing

Targeted attacks against specific individuals, crafted using information from LinkedIn profiles, corporate websites, press releases, and social media. The attacker knows the target's name, role, reporting structure, and current projects.

What makes it dangerous now: Generative AI has reduced spear phishing preparation time from hours of manual OSINT research to seconds of automated output. An attacker can feed a LinkedIn profile into an LLM and produce a contextually perfect email in under a minute.

Whaling

Spear phishing aimed at C-suite executives, board members, or other high-authority individuals. The payoff targets are wire transfers, M&A information, or strategic data. Whaling emails often impersonate outside counsel, board members, or regulators.

Business email compromise (BEC)

The attacker compromises or spoofs a legitimate business email account — typically a CEO, CFO, or vendor — and uses it to request a payment, redirect an invoice, or change banking details. BEC is the highest-dollar phishing category: the FBI IC3 reported $3.04 billion in U.S. losses from 21,442 complaints in 2025, averaging $141,000 per incident.

What makes it dangerous now: 40% of BEC emails are now primarily AI-generated. Attackers combine email compromise with AI voice cloning to provide "phone confirmation" of fraudulent requests, defeating the traditional callback verification.

Smishing (SMS phishing)

Phishing via text message. Attackers impersonate banks, delivery services, government agencies, or IT departments. People open texts faster and with less suspicion than email, and mobile browsers make it harder to inspect destination URLs.

The Verizon DBIR 2025 reports that 19% of breaches now originate from smishing or vishing combined, making the phone a breach vector comparable in scale to traditional email.

Vishing (voice phishing)

Scripted phone calls impersonating bank fraud departments, government agencies, IT helpdesks, or executives. Vishing attacks leveraging AI voice cloning surged 442% in 2025. Enterprises report average losses of $680,000 per voice fraud attack.

What makes it dangerous now: AI voice cloning needs as little as three seconds of public audio — a podcast clip, a conference talk, a LinkedIn video — to produce a convincing replica. The first multi-channel campaigns now blend an AI-written email, a deepfake voicemail, and a cloned voice callback in the same attack workflow.

Quishing (QR code phishing)

A malicious URL hidden inside a QR code, delivered via email, printed flyer, parking meter sticker, or even a physical letter. Scanning the code on a mobile device bypasses email filters entirely and lands the user on a credential-harvesting site. Multi-channel AI attacks combining deepfakes, voice cloning, and QR codes increased 680% year-over-year in 2025.

Clone phishing

The attacker intercepts a legitimate email the target has already received — a real invoice, a real shared document link — and resends it from a spoofed or compromised account with the attachment or link replaced by a malicious version. Because the email looks identical to one the target already trusts, detection is extremely difficult.

Adversary-in-the-middle (AitM) phishing

The attacker sets up a proxy server between the user and the legitimate login page. The user enters real credentials on what appears to be the real site; the proxy captures both the credentials and the session token, bypassing standard MFA. This is the primary technique that defeats SMS OTP and app-based OTP — and the reason NIST SP 800-63-4 now requires phishing-resistant MFA at AAL2.

Other vectors

Evil twin Wi-Fi: A rogue access point mimicking a legitimate network, capturing credentials from users who connect and authenticate. Watering hole: Compromising a website frequented by the target population. Search engine poisoning: Placing malicious links in search results for common queries.


AI-powered threats: why "spot the phish" no longer works

The traditional security awareness model taught employees to look for red flags: misspellings, poor grammar, generic greetings, suspicious sender addresses, urgency language. Every one of these tells has been eliminated by generative AI.

The new attack capabilities

AI-generated email: LLMs produce phishing emails that are grammatically perfect, contextually appropriate, and styled to match the target organization's internal communications. An attacker can train a model on a few examples of a CEO's writing style and produce emails that read identically to the real thing.

AI voice cloning: Three seconds of audio — a voicemail greeting, a YouTube interview, a conference panel — is enough to create a real-time voice clone. Attackers use this to place live phone calls impersonating executives, confirming fraudulent wire transfer requests that were initiated via email.

Deepfake video: Production-quality deepfake video is now used in fraud. The most common attack pattern is a fake video meeting where an "executive" instructs a finance team member to process an urgent payment. One documented 2024 case involved a deepfake CFO on a live video call that resulted in a $25 million loss.

Multi-channel orchestration: A single campaign can combine an AI-written email, a deepfake voicemail, a cloned voice callback, and a fake video meeting — defeating every single-channel verification method.

What this means for training

The defense model must shift from detection ("spot the fake") to process ("follow the verification procedure regardless of how legitimate it looks"). This is a fundamental reorientation:

  • Old model: "If the email looks suspicious, verify before acting."
  • New model: "For any request involving money, credentials, data, or access changes, verify through a pre-established out-of-band channel — every time, even when the request looks and sounds perfectly legitimate."

The verification must use a channel and contact method the employee initiates, not one provided in the suspicious communication. Call the person back at a number you already have in your contacts, not the number provided in the email or voicemail.


Regulatory and standards landscape

Phishing defense is no longer just a best practice — multiple regulatory frameworks now mandate specific controls. This section maps the requirements by framework so you can build a compliance matrix.

NIST SP 800-53 Rev 5 (Control AT-2: Security Awareness Training)

Status: Regulatory requirement for federal agencies; consensus standard for private sector

NIST SP 800-53 Rev 5.2.0 (August 2025, responding to Executive Order 14306) requires organizations to provide basic security awareness training to all information system users, including managers, senior executives, and contractors. Training must occur at initial hire, when required by system changes, and at organization-defined intervals thereafter.

NIST SP 800-50 Rev 1, the implementation guide for the AT family, recommends continuous awareness communications (monthly or more frequently), formal training at least annually, training during onboarding, and event-driven micro-modules when new threats or policy changes warrant.

HIPAA Security Rule — 45 CFR §164.308(a)(5)

Status: Regulatory requirement for covered entities and business associates

The HIPAA Security Rule requires every covered entity and business associate to implement a security awareness and training program for all workforce members, explicitly including management. The training must cover protection from malicious software (phishing is the primary malware delivery vector in healthcare), procedures for monitoring login attempts, and password management.

Retraining is required after preventable errors, audit findings, repeated policy violations, phishing simulation failures, or incidents involving staff conduct. This is not optional and cannot be satisfied by a one-time orientation.

PCI DSS 4.0 — Requirements 12.6 and 5.4.1

Status: Regulatory requirement for organizations storing, processing, or transmitting cardholder data (enforceable since March 31, 2025)

PCI DSS 4.0 Requirement 12.6 mandates a formal security awareness program, personnel training at hire and at least annually, and employee acknowledgment collection at least every 12 months. The program must specifically address phishing and social engineering, and acceptable use of end-user technologies.

Requirement 5.4.1 is new in v4.0 and has no v3.2.1 equivalent: it requires processes and automated mechanisms to detect and protect personnel against phishing attacks. This is explicitly not satisfied by training alone — it requires technical controls such as DMARC, SPF, and DKIM implementation.

Non-compliance carries monthly fines from $5,000 to $100,000.

FTC Safeguards Rule (16 CFR Part 314)

Status: Regulatory requirement for financial institutions under FTC jurisdiction

The Safeguards Rule requires all personnel with access to customer information to receive security awareness training, with regular updates addressing new threats. Training must cover MFA enrollment, recovery, and phishing resistance, including a phishing awareness module covering MFA-fatigue and MFA-bypass attacks.

CMMC 2.0 Level 2

Status: Regulatory requirement for Department of Defense contractors handling CUI

CMMC Level 2 requires training on phishing recognition, secure CUI handling, access controls, incident reporting, and insider threat awareness. Contractors must employ role-based phishing simulations. Training is required before system access is granted, with at least annual refreshers and an explicit annual insider-threat module.

SEC Cybersecurity Disclosure Rule (2023)

Status: Regulatory requirement for SEC registrants

While the SEC rule does not mandate specific training, it requires annual disclosure of cybersecurity risk management processes, including how the organization identifies and manages material cybersecurity risks. A phishing incident that constitutes a material cybersecurity event must be disclosed on Form 8-K within four business days.

NIST SP 800-63-4 (July 2025) — Authentication requirements

Status: Consensus standard (binding for federal; widely adopted privately)

NIST SP 800-63-4 formally recognizes FIDO2 passkeys, deprecates email OTP, and significantly downgrades SMS OTP. Device-bound passkeys meet AAL3; synced passkeys meet AAL2. This is the governing document for phishing-resistant authentication and directly impacts how organizations should approach credential protection against phishing.

Summary compliance table

FrameworkTraining RequiredFrequencyPhishing-Specific ContentTechnical Controls RequiredSimulations Required
NIST 800-53 Rev 5 (AT-2)YesOnboarding + org-definedYesAddressed in other familiesRecommended
HIPAA §164.308(a)(5)YesOnboarding + ongoingYes (malware/phishing)Addressed in other sectionsRecommended
PCI DSS 4.0 (12.6 / 5.4.1)YesAnnually + at hireExplicitly requiredYes (DMARC/SPF/DKIM)Recommended
FTC Safeguards RuleYesRegular updatesYes (MFA-bypass/phishing)YesRecommended
CMMC 2.0 Level 2YesAnnually + at hireYesYesRequired
SEC Disclosure RuleDisclosure onlyAnnual (10-K)N/AN/AN/A

Building a phishing simulation program that changes behavior

Phishing simulations are the most measurable component of a security awareness program. Done well, they reduce click rates from 33% to under 5% within 12 months. Done poorly, they erode trust, create resentment, and produce compliance artifacts that mask real risk.

The metrics that matter

Phish-prone percentage (PPP): The share of employees who click, open an attachment, or enter credentials on a simulated phishing test. The KnowBe4 formula is (clicked + entered credentials − reported) / total sent. This is your headline metric.

Report rate: The percentage of recipients who report the simulated phish through the official reporting channel (e.g., a "Report Phish" button in the email client). This matters more than the click rate — you want employees who recognize and report, not just employees who ignore everything.

Repeat clicker rate: The percentage of employees who fail more than one simulation in a rolling 12-month period. This identifies the individuals who need targeted remediation.

Time to report: How quickly the first report comes in after the simulation is sent. Faster reporting means faster organizational response to real attacks.

Benchmark data

The KnowBe4 2026 benchmarking report provides industry-wide baselines:

PhaseAverage Click Rate
Before any training (baseline)33.1%
After 90 days of monthly simulations10–15%
After 12 months of monthly simulations + JIT training4–6%
Mature programs (2+ years)2–5%

Healthcare & Pharmaceuticals (42.7% baseline), Insurance (38.1%), and Retail & Wholesale (36%) are the three most vulnerable industries for two consecutive years.

Program design principles

1. Run a baseline before launching training. Send a realistic phishing simulation to all employees before any awareness training. This establishes your starting PPP and gives you an honest picture of organizational risk.

2. Be transparent about the program's existence, but not about individual tests. Tell employees that phishing simulations will occur, explain that the purpose is skill-building (not entrapment), and frame the program as a team effort. Organizations with transparent programs show 20–45% higher reporting rates. Never reveal the timing or content of specific simulations.

3. Simulate monthly, not annually. Annual simulations produce compliance artifacts. Monthly simulations produce behavior change. The data is unambiguous on this point.

4. Deliver just-in-time training at the point of failure. When an employee clicks a simulated phish, immediately redirect them to a brief (2–3 minute) training module that explains what they missed and what they should have done. This is the single highest-impact intervention in the entire program.

5. Escalate difficulty progressively. Start with obvious red flags (misspelled brand names, suspicious domains). Progress to contextually relevant spear phishing. Eventually include AI-generated content, smishing, and vishing simulations.

6. Segment by role and risk. Finance, HR, executive assistants, and IT administrators face different attack profiles than line workers. Tailor simulation content to each group's actual threat exposure.

7. Never punish; always train. Punitive consequences for simulation failures (public shaming, disciplinary action, loss of access) destroy the reporting culture you are trying to build. The goal is to increase reporting, not decrease clicking through fear.

8. Track and remediate repeat clickers. Employees who fail three or more simulations in 12 months need individualized attention — a brief one-on-one with their manager, an additional training module, or a role-specific briefing on the threats they face.


Technical controls: the other half of the defense

Training alone cannot stop phishing. Technical controls reduce the volume of attacks that reach users and limit the damage when a user is compromised. These are co-equal with training — not supplements to it.

Email authentication: DMARC, DKIM, and SPF

These three protocols work together to prevent email spoofing:

SPF (Sender Policy Framework): A DNS record listing the IP addresses authorized to send email on behalf of your domain. Receiving servers check the sending IP against this list.

DKIM (DomainKeys Identified Mail): A cryptographic signature attached to outgoing emails. The receiving server verifies the signature against a public key published in DNS, confirming the email was not altered in transit.

DMARC (Domain-based Message Authentication, Reporting, and Conformance): A policy layer that requires SPF or DKIM to pass and align with the domain in the visible "From" header. DMARC policies can be set to monitor only (p=none), quarantine (p=quarantine), or reject (p=reject).

Current status: DMARC has been elevated from an informational document to a Proposed Standard with the publication of DMARCbis as RFC 9989, 9990, and 9991 (May 2026). Google, Yahoo, and Microsoft now require SPF, DKIM, and a published DMARC record for any domain sending more than 5,000 messages per day. PCI DSS 4.0 Requirement 5.4.1 explicitly lists DMARC, SPF, and DKIM as anti-phishing controls.

Implementation priority: Deploy DMARC at p=none first to collect reports and identify all legitimate sending sources. Move to p=quarantine, then p=reject. The goal is p=reject on all organizational domains, including parked domains.

Global DMARC adoption is at 52.1%, up from 27.2% in 2023 — but more than half of those domains are stuck at p=none, which provides zero spoofing protection. Countries with national DMARC mandates saw phishing success rates drop from 69% to 14%.

Phishing-resistant multi-factor authentication

NIST SP 800-63-4 (July 2025) establishes FIDO2/WebAuthn as the standard for phishing-resistant authentication:

What qualifies as phishing-resistant: FIDO2 security keys (hardware-bound, AAL3), synced passkeys (AAL2), and smart card/PIV credentials. These authenticators bind the credential to the legitimate server's origin, making them immune to AitM proxy attacks.

What does not qualify: SMS OTP (deprecated), email OTP (deprecated), app-based TOTP (vulnerable to AitM proxying), push notifications (vulnerable to MFA fatigue attacks).

Implementation priority: Deploy FIDO2 security keys or passkeys for all accounts with access to financial systems, email, and administrative consoles. These are the accounts attackers target first after a phishing compromise.

Additional technical controls

Email filtering and sandboxing: Gateway-level filtering that detonates attachments in a sandbox, rewrites URLs for click-time analysis, and applies machine learning to detect anomalous sending patterns.

Browser isolation: Rendering web content in a remote container so that even if a user clicks a malicious link, the exploit executes in an isolated environment rather than on the user's endpoint.

DNS filtering: Blocking known malicious domains at the DNS level, preventing users from reaching credential-harvesting sites even if they click a phishing link.

Endpoint detection and response (EDR): Detecting and blocking malicious payloads delivered via phishing, including macro-enabled documents, PowerShell scripts, and fileless malware.


Incident response: when a phish gets through

No defense is perfect. When a phishing attack succeeds, the speed and quality of the response determines whether the incident is a minor event or a major breach. Every organization needs a documented phishing incident response procedure.

Immediate response (first 60 minutes)

1. Contain the account. Reset the compromised user's credentials immediately. Revoke all active sessions. If MFA was bypassed, revoke and re-provision the MFA token.

2. Assess the scope. Determine what the compromised account had access to. Check email forwarding rules — attackers commonly set up mail forwarding to an external address as a persistence mechanism. Check for OAuth app grants that may have been authorized during the compromise.

3. Preserve evidence. Capture email headers, URLs, and any attachments from the phishing message. Document the timeline: when the email was received, when the user interacted with it, when it was reported or detected.

4. Notify the security team and management. Follow your incident classification procedure. If the compromise involves regulated data (PHI, PCI, PII), engage legal counsel for breach notification assessment.

Investigation (hours 1–24)

5. Search for additional recipients. Use your email gateway's message trace to find every recipient of the same phishing message. Quarantine or delete unread copies.

6. Check for lateral movement. Review authentication logs for the compromised account. Look for logins from unusual locations, access to systems the user does not normally use, or privilege escalation.

7. Scan for persistence. Check for new inbox rules, delegate access grants, app registrations, and any changes to the compromised user's account configuration.

Recovery and lessons learned

8. Restore and monitor. Re-enable the account with new credentials and fresh MFA enrollment. Monitor for 30 days for signs of residual compromise.

9. Conduct a post-incident review. Determine why the attack succeeded: Was it a training gap? A technical control gap? A process gap? Document the root cause and assign corrective actions.

10. Update the program. Add the attack pattern to your simulation library. If the phishing email bypassed email filters, work with your email security vendor to tune detection. If a process was missing (e.g., no callback verification for wire transfers), implement it.


Building a complete anti-phishing program

A mature anti-phishing program integrates training, simulations, technical controls, and incident response into a single managed program. Here is a framework for building one.

Year 1: Foundation

  • Deploy SPF, DKIM, and DMARC (start at p=none, move to p=quarantine by Q2, p=reject by Q4)
  • Run a baseline phishing simulation across all employees
  • Launch monthly phishing simulations with just-in-time training at the point of failure
  • Deploy phishing-resistant MFA (FIDO2 security keys or passkeys) for all finance, HR, IT admin, and executive accounts
  • Establish a phishing incident response procedure
  • Install a "Report Phish" button in all email clients
  • Train all employees at onboarding; deliver annual refresher training covering the current threat landscape

Year 2: Maturation

  • Expand simulation types to include smishing, vishing, and QR code phishing
  • Implement role-based simulation targeting (finance receives BEC scenarios, HR receives data-request scenarios, executives receive whaling scenarios)
  • Deploy FIDO2/passkeys organization-wide
  • Achieve DMARC p=reject on all domains including parked domains
  • Implement a repeat-clicker remediation program
  • Begin tracking report rate as a primary metric alongside click rate
  • Integrate phishing simulation data into your risk register

Year 3: Optimization

  • Introduce AI-generated phishing content in simulations
  • Deploy browser isolation for high-risk user groups
  • Conduct tabletop exercises for phishing-initiated breach scenarios
  • Benchmark against industry data (KnowBe4, Verizon DBIR) quarterly
  • Achieve and sustain sub-5% click rate and above-70% report rate

Common mistakes that undermine phishing defense programs

1. Running simulations annually instead of monthly. Annual simulations are compliance checkboxes. They do not change behavior. The data shows that behavior change requires repeated practice at monthly intervals or more frequently.

2. Punishing simulation failures. Punitive consequences suppress reporting. If employees fear discipline for clicking a simulated phish, they will also fear reporting a real phish. You need more reporting, not less clicking through fear.

3. Stopping at DMARC p=none. More than half of all DMARC-enabled domains are stuck at p=none, which provides monitoring data but zero spoofing protection. The goal is p=reject.

4. Treating training and technical controls as alternatives. "We have email filtering, so we don't need training" and "We train everyone, so we don't need technical controls" are both wrong. The defenses are layered and complementary.

5. Ignoring smishing and vishing. Email-only programs miss 19% of breach vectors. Phone-based attacks are growing faster than email attacks and are less likely to be reported.

6. Relying on SMS OTP as "strong MFA." SMS OTP is vulnerable to SIM swapping and AitM proxy attacks. NIST SP 800-63-4 formally deprecates it. Deploy FIDO2 or passkeys.

7. Not monitoring for email forwarding rules. The first thing many attackers do after compromising an email account is set up a forwarding rule to an external address. If you are not checking for new forwarding rules as part of your incident response, you are missing active compromise indicators.

8. Training once and considering the job done. The threat landscape evolves faster than annual training cycles. AI-generated attacks, deepfake voice, and quishing all emerged or matured within the last 18 months. Training content that is more than six months old is already partially obsolete.


Frequently Asked Questions

What is the difference between phishing and social engineering?

Phishing is a subset of social engineering. Social engineering is the broader category of attacks that manipulate human psychology to gain unauthorized access, information, or actions. Phishing specifically uses electronic communications — email, text, voice, QR codes — to trick targets into clicking links, opening attachments, or providing credentials. Other social engineering techniques include pretexting (fabricating a scenario), tailgating (physically following someone through a secure door), and baiting (leaving infected USB drives in public areas).

How often should we run phishing simulations?

Monthly, at minimum. The KnowBe4 benchmarking data shows that click rates drop from 33% (baseline) to 10–15% after 90 days of monthly simulations, and to 4–6% after 12 months. Annual simulations produce negligible behavior change. Some mature programs run simulations bi-weekly for high-risk groups.

What is a good phishing click rate?

After 12 months of consistent monthly simulations with just-in-time training, a click rate of 4–6% is average and sub-2% is achievable for mature programs. More important than the absolute number is the trend — the click rate should be declining quarter over quarter. Also track the report rate (target: 70%+) and repeat clicker rate (target: under 3% of the workforce).

Are we legally required to do phishing training?

It depends on your regulatory environment. HIPAA, PCI DSS 4.0, FTC Safeguards Rule, and CMMC 2.0 all explicitly require security awareness training with phishing-specific content. NIST SP 800-53 mandates it for federal agencies and contractors. Even if none of these apply, a failure to train could be cited as evidence of negligence in litigation following a breach.

What is phishing-resistant MFA and why does it matter?

Phishing-resistant MFA uses authenticators that cryptographically bind the credential to the legitimate server's origin, making them immune to adversary-in-the-middle (AitM) proxy attacks. FIDO2 security keys and passkeys qualify. SMS OTP, email OTP, and app-based TOTP do not — they can all be captured by a proxy server sitting between the user and the real login page. NIST SP 800-63-4 (July 2025) formally recognizes this distinction and deprecates SMS/email OTP.

How do I protect against AI voice cloning and deepfake attacks?

Three defenses work together: (1) Establish pre-agreed verification codes or passphrases for high-risk transactions (wire transfers, access changes) that cannot be obtained from public audio or video. (2) Require out-of-band verification through a channel the employee initiates — call the person back at a number from your corporate directory, not a number provided in the suspicious communication. (3) Show employees real examples of deepfake audio and video in training so they understand the technology's capabilities.

What should employees do when they receive a suspicious email?

Do not click any links, open any attachments, or reply. Use the "Report Phish" button in the email client to report it to the security team. If the email requests an action that seems urgent (wire transfer, password change, data sharing), verify the request through a separate channel — call the sender at a known number, walk to their desk, or message them on a different platform. Never use the contact information provided in the suspicious email itself.

What is DMARC and why does my organization need it?

DMARC (Domain-based Message Authentication, Reporting, and Conformance) is an email authentication protocol that prevents attackers from sending emails that appear to come from your domain. It works with SPF and DKIM to verify that the sender is authorized and the message has not been altered. As of 2026, DMARC is required by Google, Yahoo, and Microsoft for high-volume senders, mandated by PCI DSS 4.0 Requirement 5.4.1, and has been elevated to an IETF Proposed Standard (RFC 9989–9991, May 2026). Deploying DMARC at p=reject is one of the highest-impact anti-phishing controls available.

How do I handle an employee who keeps clicking phishing simulations?

Do not punish them — that suppresses reporting of real attacks. Instead, implement a graduated remediation process: additional targeted training after the second failure, a brief one-on-one with their manager after the third, and a role-specific threat briefing after the fourth. For employees in high-risk roles (finance, HR, IT admin) who continue to fail, consider restricting their access to sensitive systems until they demonstrate improvement, and ensure their accounts have phishing-resistant MFA.

What is quishing and how do I defend against it?

Quishing is phishing via QR code. Attackers embed malicious URLs in QR codes delivered by email, printed media, or physical placement (parking meters, restaurant menus, conference materials). When scanned on a mobile device, the URL bypasses email filters entirely and lands the user on a credential-harvesting site. Defense requires training employees to treat QR codes from unknown sources with the same suspicion as email links, deploying mobile device management (MDM) with URL filtering, and including QR code phishing in your simulation program.

How much does a phishing attack cost?

Costs vary enormously by attack type. The average BEC incident costs $141,000 (FBI IC3, 2025). Voice fraud attacks leveraging AI cloning average $680,000 per incident. The Verizon DBIR 2026 reports that the median cost of a phishing-initiated data breach exceeds $4.7 million when regulatory fines, legal fees, remediation, and business disruption are included. The cost of a mature anti-phishing program is orders of magnitude lower.

Do small businesses need to worry about phishing?

Yes. Small businesses are disproportionately targeted because they typically have weaker security controls and less training. The 2026 Verizon DBIR shows that small businesses (under 1,000 employees) account for a growing share of confirmed breaches. BEC attacks specifically target small businesses because they are more likely to have a single person authorizing payments without a multi-approval process.

What is the difference between DMARC p=none and p=reject?

DMARC p=none tells receiving mail servers to deliver all email regardless of authentication results and send you reports. It provides visibility but zero protection. DMARC p=reject tells receiving servers to refuse delivery of any email that fails authentication. It is the only DMARC policy that actually prevents spoofing. Most organizations start at p=none to identify all legitimate sending sources, then move through p=quarantine to p=reject.

Can phishing simulations backfire?

Yes, if designed poorly. Simulations that are excessively tricky, use emotionally manipulative content (fake layoff notices, fake health scares), or carry punitive consequences destroy employee trust and reduce reporting rates. The program should be transparent about its existence, fair in its difficulty progression, and educational rather than punitive. The goal is building a skill, not catching people failing.

How does zero trust architecture relate to phishing defense?

Zero trust limits the blast radius of a successful phishing attack. If a user's credentials are compromised, zero trust principles — network segmentation, conditional access, least-privilege role design, continuous verification — mean the compromised account cannot move laterally or access systems beyond its explicitly granted permissions. Zero trust does not prevent phishing, but it dramatically reduces the damage a successful phish can cause.


VETTED's IT & Information Security category includes modules specifically designed to build the skills covered in this guide:


This article is published by VETTED — a workforce safety and compliance training platform delivering 122 expert-built modules across 10 categories. For more information on VETTED's IT & Information Security training, visit vettedsafe.com/modules.