Why preventing phishing is so difficult, and what we can do about it

Michael Joyce (Executive Director · Human-Centric Cybersecurity Partnership (HC2P))

NorthSec 2025 · Day 2 · Ville-Marie · Conference

Overview

Michael Joyce, Executive Director of the Human-Centric Cybersecurity Partnership (HC2P) and a PhD researcher at the Université de Montréal, presents findings from one of Canada's largest independent phishing behavior studies — covering over a quarter of a million phishing simulations across more than 700 organizations. The core argument: security professionals are systematically unqualified to make intuitive judgments about how ordinary users behave, and the dominant frameworks for addressing phishing (awareness training, technology controls, individual accountability) are grounded in faulty assumptions about human cognition. The data tells a more nuanced story, and the solutions it suggests are less intuitive than the industry typically accepts. ---

Watch on YouTube

Visual summary for Why preventing phishing is so difficult, and what we can do about it by Michael Joyce
Visual summary for Why preventing phishing is so difficult, and what we can do about it by Michael Joyce

Key moments

  1. 4:30 Dunning-Kruger: security pros overestimate user cyber awareness
  2. 12:02 Dataset: 500+ orgs, 250K+ simulations, first cross-org study
  3. 15:02 Awareness Month cuts click rate 11-12% but effect is temporary
  4. 16:33 Phishing reporting drops during Awareness Month: fatigue signal
  5. 19:34 Training decay: risk appetite should determine retraining frequency
  6. 21:04 3.5% click immediately after training: irreducible minimum exists
  7. 24:06 Monday 8-9AM peak: 15% of weekly clicks in one hour slot
  8. 25:36 Holiday Mondays: -81% reporting, email accumulation not susceptibility

Why Preventing Phishing Is So Difficult, and What We Can Do About It

Speaker: Michael Joyce (Human-Centric Cybersecurity Partnership — HC2P)

Conference: NorthSec 2025 — May 15–16, 2025, Marché Bonsecours, Montreal

Watch on YouTube: https://www.youtube.com/watch?v=nmOjzAAOiIw

Reading time: ~7 minutes

TL;DR

Michael Joyce, Executive Director of the Human-Centric Cybersecurity Partnership (HC2P) and a PhD researcher at the Université de Montréal, presents findings from one of Canada's largest independent phishing behavior studies — covering over a quarter of a million phishing simulations across more than 700 organizations. The core argument: security professionals are systematically unqualified to make intuitive judgments about how ordinary users behave, and the dominant frameworks for addressing phishing (awareness training, technology controls, individual accountability) are grounded in faulty assumptions about human cognition. The data tells a more nuanced story, and the solutions it suggests are less intuitive than the industry typically accepts.

Introduction

Phishing has been a dominant attack vector for decades. Awareness campaigns, simulated phishing programs, and security training are multi-billion-dollar industries built on the premise that if users know better, they will do better. The problem, as Michael Joyce frames it at NorthSec 2025, is that this premise reflects how security professionals think humans work — not how humans actually work.

Joyce brings an unusual research profile to a security conference. As Executive Director of the HC2P — a federally funded Canadian research partnership involving roughly fifty researchers from domestic and international universities — and a PhD candidate at the Université de Montréal's Cybercrime Prevention Lab, he operates at the intersection of cybersecurity and the social sciences. His five-year research program, partially enabled by a large dataset provided by phishing simulation provider Boceron Security, represents one of the most statistically rigorous examinations of organizational phishing behavior conducted in Canada.

The talk is structured around a core claim: the security community is overconfident in its ability to understand and predict the behavior of non-technical users, and that overconfidence is degrading the quality of defenses. The data presented challenges several assumptions the industry treats as settled.

The Dunning-Kruger Problem in Security

Before presenting his research findings, Joyce establishes an epistemic framework for understanding why the security community gets phishing wrong. He invokes the Dunning-Kruger effect not in its popular form (incompetent people overestimate their ability) but in its more specific application to specialized expertise: experts in one domain tend to overestimate the baseline abilities of novices in that domain.

For security practitioners, this manifests in two symmetrical errors. First, security professionals overestimate how well ordinary users understand cybersecurity concepts. They assume a level of digital literacy and risk awareness that most users do not have. Second, security professionals overestimate their own ability to understand non-technical user behavior — they apply their own mental models of "what is obviously a phishing email" to populations who do not share those models.

The practical consequence is that training materials, simulation design, and policy recommendations are calibrated for an imagined user who does not exist. The actual user is described by a different set of principles.

▶ Watch: Dunning-Kruger and Security Practitioners (4:00)

Five Principles of Human Cognition That Shape Phishing Susceptibility

Joyce proposes five general principles drawn across scientific disciplines that characterize how humans actually make decisions — principles that, he argues, must be integrated into any realistic phishing defense strategy.

People think efficiently. Human cognition is not lazy; it is metabolically optimized. The brain allocates attentional resources to problems that require them and offloads everything else to automatic processing. Security events that do not register as requiring deliberate evaluation will not receive it.

People satisfice, not optimize. Decision-making under uncertainty does not produce optimal outcomes — it produces the first acceptable outcome. When evaluating an email, users are not running through a checklist of phishing indicators; they are seeking a plausible interpretation of the message that allows them to respond and move on.

People think dualistically. The two-system model of cognition (popularized by Kahneman's "Thinking Fast and Slow") describes an automatic, low-effort processing system running in parallel with a controlled, deliberate system. Most email interactions are handled entirely by the automatic system. Training that assumes users will engage the deliberate system when evaluating every message is training for an unlikely use case.

People learn imperfectly. Memory is not a recording device. What is retained depends heavily on context, emotional salience, and recency. Security awareness training delivered in one context may produce no behavioral change in a different context — even if the user "remembers" the training content.

People have bodies. The human decision-maker is not a stable computational process. Fatigue, stress, hunger, time of day, and emotional state all influence the quality of security decisions. The person who carefully reads an unusual email at 10 AM on a Tuesday is not the same decision-maker at 11 PM after a long day. Phishing campaigns timed to exploit physiological vulnerability states are exploiting a real and underappreciated attack surface.

▶ Watch: Five Principles of Human Cognition (8:00)

What the Data Actually Shows: Cybersecurity Awareness Month

The empirical portion of the talk draws on phishing simulation data from more than 500 organizations in 2023 and more than 700 in 2024, representing over a quarter of a million simulated phishing attempts. The dataset allows for analysis at a scale and generalizability that single-organization studies cannot achieve.

The first question examined is whether Cybersecurity Awareness Month — the October government-coordinated awareness program operating in Canada since approximately 2012 — produces measurable behavioral changes. The findings are cautiously positive. Organizations increase the volume of phishing simulations by 13% in October 2023 and 23% in October 2024, indicating organizational responsiveness to the campaign. The phishing simulation click rate drops by approximately 11–12% during the same period, suggesting that heightened awareness does produce short-term behavioral change.

More striking is the finding on real phishing reporting. Reports of actual phishing emails — those that bypassed all filtration systems and reached users' inboxes — also increase during October. This is not a negative finding: it indicates that heightened awareness causes users to report suspicious emails they would otherwise ignore or delete. The awareness campaign is generating useful security signal, not just compliance theater.

▶ Watch: Cybersecurity Awareness Month Data (14:00)

Technology Is Not a Silver Bullet: The Knife Analogy

Joyce addresses the common industry response that technology will eventually solve the phishing problem. He uses the knife as a counterpoint. Knife technology is approximately 3.6 million years old — predating Homo sapiens. The United States alone records over a thousand knife-related injuries per day presenting to hospitals. If any technology could be made entirely safe through engineering, knives would have been that technology by now.

The analogy carries a structural lesson: some technologies produce residual risks that engineering alone cannot eliminate. Computer-mediated communication — the substrate on which phishing operates — is likely one of them. Security practitioners have been working on phishing since at least 1967 by Joyce's count, with limited progress on the fundamental problem. A solution framework that accounts for this reality must integrate human-adaptive controls, not just technological ones.

He draws on occupational health and safety's hierarchy of controls — elimination, substitution, engineering controls, administrative controls, personal protective equipment — as a model for layering security interventions. The hierarchy reminds practitioners that placing all responsibility on individual users (the equivalent of PPE) is the weakest control in the hierarchy and should be the last resort, not the default.

▶ Watch: The Knife Analogy and Hierarchy of Controls (6:00)

Notable Quotes

"If you are one of the people who go around saying that humans are the weakest link in cybersecurity, you're kind of right — but you're right in that cybersecurity is weakest at dealing with humans. Let's not blame the people. Let's start looking at the things that we can change."

"We are entirely unqualified as a group of people to talk about what normal people do when it comes to cybersecurity."

"The decision-maker at two AM is not the same decision-maker at two PM."

"You can't patch people."

Key Takeaways

  • Security practitioners systematically mismodel user behavior. The Dunning-Kruger effect applies to expertise: security professionals overestimate users' security literacy and their own ability to predict user responses.
  • Cybersecurity Awareness Month produces measurable effects. Both simulated click rates and real phishing reports shift meaningfully during October — awareness campaigns have empirical value, though the effect is likely time-limited.
  • Human cognition is not a failure mode. Efficiency-oriented thinking, satisficing, and dual-process cognition are features of human cognition, not bugs. Defense strategies that treat them as pathologies will underperform.
  • Temporal factors matter. Physiological state influences decision quality. Phishing campaigns timed to exploit fatigue or stress states exploit a real vulnerability that training cannot fully address.
  • Technology cannot solve phishing. The knife analogy grounds a realistic expectation: residual risk cannot be engineered to zero in communication technologies.
  • The hierarchy of controls applies to security. Organizations that rely primarily on user-level controls (training, awareness) are operating at the weakest point of the hierarchy. Engineering and administrative controls should be prioritized.
  • Large-scale cross-organizational data is rare and valuable. The HC2P dataset — quarter-million simulations across 700+ organizations — offers a generalizability that single-organization studies cannot match. The field needs more of this kind of research.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

HC2P researcher presents findings from 250,000+ phishing simulations across 700+ Canadian organizations, applies cognitive science frameworks to explain why awareness training underperforms, and proposes a hierarchy-of-controls approach to phishing defense.

Heather Calloway (CISO) — MUST SEE

This is a governance talk dressed in research clothing, and Joyce is correct about things the security industry has been wrong about for twenty years. The finding that security professionals are systematically unqualified to model non-technical user behavior is not a new observation, but Joyce is the first person I've seen prove it with a dataset that a regulator or board could actually engage with. The industry's default response to phishing — blame the user, run more training — is a market failure, and he names it.

→ Top-rated talks at NorthSec 2025

All talks from NorthSec 2025