TL;DR SUMMARY: Phishing training still has a place, especially when it helps people recognise suspicious patterns and report quickly. The shortfall comes when phishing simulation software becomes a box-ticking exercise, separated from the way threats unfold in real time. A growing human-centred view of phishing risk points towards contextual, behaviour-led support that helps people pause, verify and act safely at the point of risk, which is where tools such as Redflags can add useful texture.
Why phishing examples need real-world context
Attackers understand something many training programmes still underplay: people don’t make security decisions in a vacuum. They make them between meetings, while replying on mobile, while dealing with customers, while trying not to be the slowest person in the process.
That is why phishing email examples need context. A fake password reset can teach a basic lesson, but it may not prepare someone for a message that references a real supplier, a recent project or an urgent executive request. AI phishing makes that kind of contextual detail easier to generate, which means simulations need to become more realistic without becoming cruel.
The goal of phishing training should not be to catch people out. It should be to build recognisable habits: pause, check, report, verify through a trusted route, and ask whether the request fits the context. Those habits are modest on paper, yet they become much harder when urgency, authority and familiarity arrive together.
Alan Bulley, an experienced CISO, describes integrated attacks in a way that makes the scale harder to ignore. A phishing attempt may begin with a text, continue through an email and end with an AI-generated call that sounds like someone familiar. Once that sequence is set up, “they can do that. And of course, once you set that up once, it can just do it thousands of times.” The user is no longer responding to one suspicious moment; they’re navigating a chain of plausible confirmations.
That changes what organisations should measure. Click rates still have value, but they are only one part of the picture. Reporting rates show whether people are willing to act. Repeat risky behaviour shows where support may be needed. Time to report shows whether the organisation can respond before harm spreads.
Useful phishing simulation data should make these patterns visible and connect mistakes to support. If someone clicks, the next step should help them understand the cue they missed, whether that cue was urgency, authority, familiarity or timing. That turns a failed test into a learning moment, instead of a private embarrassment that people are less likely to talk about.
There is also a role for real-time intervention. If a user is about to enter credentials into a suspicious page, a timely prompt may be more valuable than a quarterly reminder. This is the gap that tools like Redflags are designed to address: not by turning every moment into a test, but by offering contextual support while behaviour is still available to be changed.
Phishing is not going away. AI will make some attacks smoother, faster and harder to spot. The organisations that respond well will treat people as part of the defence system, giving them practical ways to notice risk without making every mistake feel like a personal failure.
Key takeaways
- Phishing simulations need to reflect real-world timing, context and pressure.
- AI phishing increases the importance of realistic, multi-channel training.
- Reporting behaviour is a vital signal of security culture.
- Supportive feedback helps people learn without hiding mistakes.
