Winging It · Implausible Deniability
Every January, without fail, an email arrives. It has the energy of a parking fine and the creative ambition of a terms and conditions update. It is your annual security awareness training, and it would like forty-five minutes of your life that you will never get back.
You know the one. It opens with a cartoon office worker, drawn in that particular style that suggests the illustrator was briefed with the words "corporate, but approachable" and then given fifty dollars and an afternoon. The cartoon office worker is about to make a terrible decision. He's going to click a link. You can tell because he's smiling, and nobody smiles at email unless they're about to do something catastrophic.
What follows is a series of slides that explain, with enormous patience, that you should not give your password to strangers. There are multiple choice questions. The correct answer is always the longest one. There is a section on tailgating that uses a photograph of a door, in case you'd forgotten what those look like. And there is, inevitably, a module on phishing that describes tactics so obvious you'd have to be concussed to fall for them, illustrated with an example email that misspells "Microsoft" and promises you've won a television.
Nobody has ever learned anything from this training. I include myself.
What people have learned is the precise number of times you can click "Next" before the system lets you attempt the quiz. In most platforms, it's somewhere between twelve and nineteen, depending on how much the vendor hates you. There's a small but dedicated community within every organisation that treats this as a speedrun. Their personal best is six minutes. They are, without exception, the same people who will click on an actual phishing email three weeks later and hand over their credentials with the enthusiasm of someone returning a library book.
I've watched this cycle repeat for two decades now. The training lands in January. Completion rates hit 95% by March because someone from HR starts sending increasingly threatening reminders to the stragglers, who are always the same four people, and one of them is always on a leave of absence that nobody told HR about. By April, the organisation has a nice dashboard showing near-total compliance. By May, someone in finance has wired money to a spoofed vendor because the email "looked official" and they were "in a rush."
The dashboard, I should note, still looks wonderful.
There's a particular genius to how the training handles social engineering. It presents scenarios with all the complexity of a children's book. "David receives a phone call from someone claiming to be from IT support. They ask for his password. What should David do?" David should not give them his password. Well done. Gold star. In real life, David gets a call from someone who knows his manager's name, references the system migration that's actually happening next week, and catches him between meetings when he's trying to eat a sandwich. David was never going to remember the cartoon.
Everyone involved knows this doesn't work. The security team knows. They've seen the phishing simulation results. HR knows. They just need the tick in the box. The employees know. They're clicking "Next" with the dead-eyed focus of someone waiting for a terms and conditions page to let them scroll to "Accept." The board knows, or at least suspects, but the compliance report says 95% and that's a number you can put on a slide.
And the vendor who built the training platform absolutely knows, but they've been careful to sell completion rates rather than outcomes, because one of those numbers goes up reliably and the other one is embarrassing.
I sat through one last year that included a section on password hygiene. It recommended using a passphrase. It gave the example "PurpleMonkey42!" which, I have to assume, is now the password for several thousand corporate accounts worldwide. The next slide suggested writing passwords down "in a secure location." It did not define what a secure location was. Under the keyboard, apparently, remains a popular interpretation.
The training is bad, but that's survivable. It exists as a substitute for the things that would help. Proper email authentication. Decent endpoint detection. A culture where someone in accounts can phone the CFO and say "this wire transfer request looks odd" without feeling like they're being difficult. But those things are expensive, or complicated, or require someone senior to admit that the current setup has holes. Annual training costs a few dollars per head and produces a compliance certificate. The economics aren't even close.
Security awareness can stay. What we've built, though, is a system optimised for the appearance of education rather than the reality of it. A forty-five minute slideshow that exists so that, when someone does click the link, management can point to the training record and say "well, they were told."
The employee learned nothing. The organisation knows the employee learned nothing. And yet everybody agrees to pretend that the learning happened, because the alternative is admitting that the entire exercise is a piece of theatre performed annually for an audience of regulators and insurers, neither of whom will ever check whether it changed anyone's behaviour.
Anyway. I've just received an email from IT asking me to verify my credentials. Looks official. Nice logo. I'm sure it's fine.
— Chris
