Cofense Says Phishing Training Should Measure Behavior Change, Not Compliance

· Original article ↗

Summary

Cofense argues that phishing defense should measure employees’ ability to recognize threats and connect that competency with real-world phishing and remediation signals, rather than relying on training completion or risk scores alone.

Key points

  • The article argues that training completion, simulation results and risk scores do not by themselves show whether employees can recognize and respond to phishing.
  • Cofense distinguishes phishing simulations, which provide practice, from observations of how people respond to real malicious emails.
  • Its competency approach assesses knowledge across 26 phishing threat topics to help identify organizational strengths and gaps.
  • Cofense says it plans to connect competency measures with real-world phishing reports and remediation signals from its platform.
  • The article says measurements should guide different actions: targeted learning for knowledge gaps or stronger protection against sophisticated threats.

Article Details

Topic
Measuring phishing-recognition competency alongside real-world reporting and remediation to improve secure behavior

Vendors

Products