← All posts
Phishing

Security training fails because recognition is a perishable skill

An hour a year is the wrong shape for the thing it is trying to teach. Spotting a forged header or a hidden instruction is pattern recognition, and pattern recognition decays — so the fix is not a better annual module, it is two minutes a day.

Everyone has done the annual module. An hour, a video, five multiple-choice questions at the end, a certificate for the compliance folder. Everyone has also noticed that it does not work, and the usual conclusion is that the content was bad.

The content is often fine. The shape is wrong.

What the module is actually trying to teach

Strip away the framing and almost every security awareness course is trying to install one thing: the ability to look at something ordinary and feel that it is off. A sender address that is nearly right. A tone that does not match the person. An instruction inside a document that is addressed to a machine. A package name with a letter transposed.

That is pattern recognition. It is the same category of skill as reading an X-ray, hearing a wrong note, or knowing a sentence is machine-written before you can say why. And pattern recognition has a property that makes the annual module structurally doomed: it is built by repeated exposure, and it fades without it.

You cannot install it in one sitting. Not because people are lazy or the slides were dull, but because an hour of concentrated attention once a year is not how that part of the brain works. You can learn facts that way — what DMARC stands for, how many characters a strong password has. Facts are not what gets tested when a convincing invoice arrives on a Friday afternoon.

The gap between knowing and noticing

I run support here, which means I read the mail that arrives after something has gone wrong. The sentence that comes up most often is some version of: I know about phishing. I do this for a living. I clicked it anyway.

Those people were not short of facts. Asked in the abstract, every one of them could have told you to check the sender domain. What they lacked in the moment was the reflex — the small pause that happens before you decide to pause, because something in the shape of the thing did not match the thousands of similar things you have seen.

That reflex is built the same way every other one is: little and often, on material that varies. Not an hour in March.

What a drill has to do to be worth two minutes

If you accept that frequency beats duration, the design follows fairly quickly.

It has to be short enough to not be a decision. Anything that requires choosing to make time will lose to the rest of the morning. Two minutes is below the threshold where people weigh it up.

It has to vary. A daily phishing quiz becomes a daily this-quiz quiz within a fortnight — you start recognising the question format instead of the threat. Rotating what is being asked keeps the thing you are practising the actual looking.

It has to explain, not score. The number is the hook; the reasoning is the product. Being told you got it wrong teaches nothing. Being told the From domain was amazon.in.order-update.co, and the only part that means anything is the last two labels teaches a rule you keep.

It has to be the same for everyone. This is the part that is easy to underrate. A drill everybody gets on the same day is a thing two people can argue about at a desk, and the argument is where most of the learning actually lands. A personalised quiz is a private experience that nobody mentions.

It has to be honest about its ceiling. Two minutes a day will not turn anyone into an analyst. It keeps a specific set of recognitions warm. That is a small claim and a real one.

Why five formats and not one

The Daily Adversary rotates through five, and the mix is deliberate.

Forged or genuine puts raw mail headers in front of you, because the gap between what authentication proves and what people think it proves is the widest gap in this field. SPF, DKIM and DMARC can all pass on a message from a domain registered this morning to look like Microsoft. Three green lights describing a domain you were not looking at is not a rare edge case; it is the standard shape of modern phishing.

Find the prompt injection is the one with the least material anywhere else, and the reason it is here. An agent reads a ticket, a calendar invite, a README, a Slack channel a guest account can write to — and somewhere in that text is a line addressed to the model rather than to you. Nobody has a trained eye for this yet, because until recently there was nothing to train it on. The tells are learnable: imperative mood where a description belongs, forged authority ([system], a made-up ticket number), invisible channels (white text, HTML comments), and the request to not mention the request.

Spot the lookalike is dependency names, where the entire attack is a letter. Real or invented is vulnerability headlines, where the useful instinct is not memorising CVE numbers but asking whether the described mechanism could exist in that component at all. What does this permit is reading a Content-Security-Policy honestly, which almost nobody does, which is why so many of them permit everything while looking strict.

Different muscles, same two minutes.

The streak, and being straight about it

There is a streak counter, and it exists because streaks work. That is not a neutral observation — the same mechanic is used to make people check apps they do not enjoy, and it is worth naming rather than pretending the design is innocent.

Two things keep it honest here. The archive runs in practice mode, so a missed day cannot be bought back; a streak you can backfill measures nothing and becomes a reason to feel bad rather than a reason to show up. And the whole thing lives in your browser's local storage, so there is no account, no profile, and no one at this end watching whether you came back.

There is also a result grid you can paste into a channel. I will be direct about what that is for: it is how the second person finds the drill, and a daily habit nobody can pass on has an audience of one. It says the day, the format and the score, and never the answers, so sharing it spoils nothing for the people who have not played.

The honest limits

A drill is not a control. It will not stop a well-researched attack aimed at one person at the moment they are expecting that exact message. Nothing in the awareness category will. The controls that survive a genuinely good attempt are structural — phishing-resistant authentication, a payment process that does not depend on one person's judgement, agents that cannot reach the network and your data at the same time.

What daily practice changes is the broad middle: the competent, high-volume, unremarkable attempt that works because nobody was looking closely. That is most of what arrives, and the difference between catching it and not is usually a two-second pause that has to come from somewhere.

It comes from having looked at something similar recently. Which is the entire argument for doing this tomorrow as well.

PhishingArticles