Annual Phishing Training Cannot Keep Up With Today's Attacks

Annual phishing training cannot prepare staff for ClickFix, fake browser windows, and OAuth consent traps. Monthly practice gives firms a better defense.

Huntress recently published a breakdown of phishing techniques that most annual security courses do not cover. The examples include a fake CAPTCHA that tells the victim to press Windows+R and paste a command, a fake Microsoft sign-in window with its own address bar and padlock, malicious application-consent requests hosted on legitimate Microsoft pages, and device codes that authorize an attacker’s computer after the victim completes MFA.

These are not the old emails with misspelled company names and an obviously fake login page. Several of them are designed around the exact advice employees have heard for years: check the URL, look for the padlock, and trust a real Microsoft sign-in page.

That creates a problem for firms that handle security awareness once a year.

The annual-training gap

Annual training usually happens for one of two reasons. The cyber insurance application asks whether employees receive security awareness training, or a compliance requirement says it must be completed. Someone assigns a course, staff members watch it, and the firm saves the completion report.

The firm gets a completed compliance record, but employees get very little practice.

Consider how much phishing changed during the last year. We have written about device code phishing, where a victim authenticates on Microsoft’s legitimate website and unknowingly authorizes the attacker’s device. We covered ClickFix ransomware, which turns a fake CAPTCHA into instructions for running malicious code. We also covered attackers calling employees through Microsoft Teams and pretending to be IT support.

An employee who completed a generic phishing course eleven months ago may never have seen any of those techniques. Even if the course mentioned them, a single exposure is easy to forget by the time a convincing message appears during a busy workday.

Why monthly practice works better

At Artech, we use Huntress Managed Security Awareness Training, formerly Curricula, for our managed clients. Employees receive a lesson each month along with a simulated phishing message. Huntress selects current scenarios based on what its researchers are seeing, then staggers delivery throughout the month so the whole office does not get the same test at once.

The repetition matters. Staff members get regular chances to pause, inspect a message, and decide what to do while the stakes are low. When someone falls for a simulation, the platform can assign recovery training tied to that scenario. Managers receive reporting on lesson completion and simulation results, which makes it possible to see whether the program is being used and where the firm needs more work.

This is closer to how people build any other skill. Reading instructions once may explain what to do. Practice makes the response familiar enough to use under pressure.

Monthly simulations also expose process problems that an annual video cannot find. If several employees recognize a suspicious email but do not know where to report it, the firm has a reporting problem. If a department repeatedly struggles with fake file-sharing notifications, training can focus there. If managers never review the reports, the firm may have purchased a platform without actually running a program.

The goal is not a perfect score

Some firms use phishing simulations as a trap. They send a difficult test, publish a list of people who clicked, and treat the results as proof that certain employees are careless.

That approach makes people less likely to report mistakes. An employee who thinks a bad click will lead to embarrassment or discipline may spend ten minutes hoping nothing happened before calling IT. Those ten minutes can give an attacker time to establish access, create inbox rules, or begin collecting data.

A useful program measures improvement and reporting behavior. Click rates matter, but so does how quickly someone reports a suspicious message or admits they entered information. A fast report gives the security team a chance to reset credentials, revoke sessions, search other mailboxes for the same lure, and determine whether anyone else interacted with it.

Managers should look for patterns rather than one bad result. A person who clicks once and learns from it is different from someone who repeatedly ignores training and does not report mistakes. The reporting helps distinguish those situations.

What your firm should be able to answer

Ask whoever manages your security awareness program:

  • How often do employees receive training and simulated phishing messages?
  • Do the simulations reflect current attacks, or are they still limited to fake password-reset emails?
  • What happens immediately after someone clicks or enters information?
  • Can managers see completion, simulation, and follow-up results?
  • Do employees know exactly how to report a suspicious message or an accidental click?
  • Are new hires enrolled automatically, and are former employees removed?

If the answers are “once a year,” “we save the certificate,” and “IT would probably hear about it,” the firm has compliance documentation but very little evidence that employees are prepared.

Annual training can still have a place for formal policies and required topics. It should not carry the entire security awareness program. Phishing changes too quickly, and people forget too much between sessions.

Short monthly lessons, realistic simulations, manager reporting, and a reporting process employees trust give the firm something more useful than a completion certificate: regular practice responding to the kinds of attacks showing up now.


Artech manages monthly security awareness lessons, phishing simulations, and reporting for its TotalCare clients. If your current program begins and ends with an annual course, we can help you build a better routine.