Seamless coaching, measurable change
A landmark 2025 IEEE study at UC San Diego Health followed 19,500 employees over 8 months to measure the real-world effectiveness of phishing awareness training.
The findings challenge everything the industry assumesβand the engagement problem applies to security training broadly.
β Back to OverviewThe numbers that should concern every organization
Ho, G., Mirian, A., Luo, E., Savage, S., Voelker, G. M., & Politz, J. (2025). Understanding the Efficacy of Phishing Training in Practice. Proceedings of the 46th IEEE Symposium on Security and Privacy (S&P Oakland 2025), San Francisco, CA, USA.
Read the full paper βWhy the status quo doesn't work
Why 37-51% of phishing training sessions have literally zero impact
The "Acknowledge" button is the root cause. Users skip through instantlyβ37-51% spend zero seconds on content.
Zero friction, 3 minutes total. No portal, no videosβjust a quick Slack conversation that proves understanding before marking complete.
See where Catpilot leads on engagementβthe root cause of training failure
| Capability | KnowBe4 | Proofpoint | Catpilot |
|---|---|---|---|
| β οΈ Engagement β The Root Cause of Training Failure | |||
| Requires real responses (no skip button) | β | β | β |
| Forces multi-turn dialogue | β | β | β |
| Verifies comprehension before completion | β | Quiz only | β |
| AI-graded free-text responses | β | β | β |
| Adapts follow-up based on responses | β | β | β |
| Tracks time-on-page | β | β | β |
| Training Delivery | |||
| Annual security awareness modules | β | β | β |
| Embedded post-click training | β | β | β |
| Delivers via Slack/Teams (no portal) | β | β | β |
| Phishing Simulation | |||
| Phishing simulation campaigns | β | β | Integrates |
| Template library | β | β | Integrates |
| Coaching within 60 seconds of click | Redirect | Redirect | β |
| Developer Security (AppSec) | |||
| Secret detection coaching | β | β | β |
| SAST/DAST finding coaching | β | β | β |
| AI Guardrails (Copilot/Cursor rules) | β | β | β |
| GitHub/GitLab integration | β | β | β |
| Integration | |||
| Works alongside existing tools | β | β | β |
| Vanta/Drata compliance sync | β | β | β |
Highlighted rows indicate capabilities directly addressing engagement failures identified in the research.
Catpilot works alongside your existing security tools. See how it works β
[1] Ho, G., et al. (2025). "Understanding the Efficacy of Phishing Training in Practice." IEEE S&P Oakland 2025. PDF β
[2] Lain, D., et al. (2022). "Phishing in Organizations: Findings from a Large-Scale and Long-Term Study." IEEE S&P 2022. PDF β
[3] Caputo, D. D., et al. (2014). "Going Spear Phishing: Exploring Embedded Training and Awareness." IEEE Security & Privacy. PDF β
[4] Franz, A., et al. (2021). "SoK: Still Plenty of Phish in the Sea." SOUPS 2021. PDF β