Most employees know they shouldn’t click suspicious links.
Yet phishing attacks still succeed.
Why?
Because security failures are rarely about a lack of knowledge.
They’re about context.
When people are under time pressure, influenced by social expectations, or simply acting on habit, knowledge often takes a back seat. In the moment, behavior is shaped by stress, norms, and automatic responses, not by what we learned in a training session months ago