Foundry4

Cybersecurity 7 min read

Phishing got fluent. Training did not

Training taught staff to spot bad grammar. That tell was an artefact of the attacker's budget and it has gone. What still works is procedural, not perceptual.

The reason bad phishing emails had bad grammar was never that criminals are stupid. It was that the person writing to a British finance clerk frequently did not speak English as a first language, and hiring someone who did was an expense that scaled badly against a campaign sending a million messages. The tell was a budget artefact.

The NCSC said as much in its assessment of the near-term impact of AI on the cyber threat, published on 24 January 2024. Generative AI, it judged, can already be used to enable convincing interaction with victims including the creation of lure documents, without the translation, spelling and grammatical mistakes that reveal phishing. It assessed that AI would almost certainly increase the volume and heighten the impact of cyber attacks over the following two years, with the most significant uplift in social engineering, and that commoditisation of criminal capability made it almost certain that capable groups would monetise AI-enabled tools and widen access to less skilled actors.

That is a specific and limited claim, and the specificity matters. The NCSC did not say attackers had acquired a new capability. It said a cost barrier had fallen. Everything that follows for defenders comes from that distinction.

The British numbers do not show a phishing explosion, and that is the interesting part

DSIT and the Home Office publish an annual survey of breaches, and the 2025/2026 edition, out on 30 April 2026 and carried out by Ipsos across 2,112 businesses and 1,085 charities, found phishing remained by far the most prevalent breach type, experienced by 38% of businesses and 25% of charities, and the most disruptive, cited by 69% of those that had any breach at all. But the headline prevalence has fallen, not risen, since 2023/2024, when it stood at 42%. Impersonation breaches fell to 12% from 17% two years earlier. Ransomware among businesses dropped to 1%, from 3% in each of the two preceding years.

Underneath that, one figure moved the other way. Among organisations that experienced any breach, the proportion experiencing phishing and nothing else rose to 51% of businesses from 45% the previous year, and to 57% of charities from 46%. In the qualitative interviews, participants said they perceived phishing had become easier to commit and that volumes were rising.

Read those together and the picture is coherent. Phishing is not becoming more common in absolute terms in this sample. It is becoming a larger share of what happens, as the other categories decline. A survey measures what organisations noticed, so this is partly a statement about detection, and a fluent message is by construction harder to notice. It would be a mistake to read the fall as good news and an equal mistake to read the phishing-only rise as an AI signal without further evidence. Both readings are being sold at conferences.

The training industry was built on the wrong layer

The NCSC’s own phishing guidance sets out four layers of defence: make it difficult for attackers to reach users, help users identify and report what does get through, protect the organisation from the messages that succeed anyway, and respond quickly to incidents. Most British organisations have invested overwhelmingly in the second layer, because it is the one you can buy as a subscription and report to a board as a percentage.

The guidance is unusually blunt about that layer’s limits. No training package, it says, including phishing simulations, can teach users to spot every phishing attempt, and asking users to examine every email they receive in depth will not leave enough hours in the day for work. It is equally direct that blaming users for clicking on links does not work, because people click for reasons that are situational as much as anything else, and punishment destroys the reporting culture you need.

That was true before generative models. It is now true with the one remaining prop removed. A training programme whose core content is a list of visual tells is teaching a heuristic that has expired, and the organisation is paying for it annually.

What survives is procedural

The controls that still work do not ask anybody to judge whether a message is genuine.

Make the impersonation fail at the protocol layer. Anti-spoofing controls on your own domain, meaning SPF, DKIM and DMARC properly configured rather than published in monitor mode and forgotten, remove an entire class of attack that no amount of fluency can substitute for. This is the first layer in the NCSC’s list and it is the one with the clearest cost-benefit case, because it is a configuration task with no ongoing user burden.

Make credential theft insufficient. Phishing-resistant multi-factor authentication changes the outcome of a successful lure from compromise to nothing. The evidence that this is still not done sits in the enforcement record. The ICO’s £3.07 million fine against Advanced Computer Software Group turned on attackers reaching health and care systems through a customer account that had no MFA on it.

Make the payment change impossible over a channel the attacker controls. The specific loss most British organisations should worry about is not malware, it is a well-written request to change bank details. The control is out-of-band verification against a record the requester cannot edit, applied without exception, including to the chief executive. Organisations that carve out an exception for seniority have not implemented the control; they have documented where to aim.

Make detection survive the fluency. The ICO’s May 2026 fine of £963,900 against South Staffordshire is the case study nobody wants. The attack began with a successful phishing email and an opened attachment. What made it a £963,900 event rather than an incident was what happened next: malicious software that went undetected for 20 months, monitoring and logging covering only 5% of the IT environment, obsolete software including Windows Server 2003 still running, and privilege escalation from an initial foothold. The personal information of 633,887 people ended up published. The breach was only identified when IT performance problems prompted an internal investigation.

That is the whole argument for moving spend from layer two to layers three and four. Someone will click. The question the ICO asked was not why they clicked.

The fourth layer barely exists in most of the economy

Layer four is responding quickly, and the national picture on that is worse than the picture on training. The breaches survey found that in 2025/2026 only 25% of businesses and 19% of charities had a formal incident response plan. The distribution is what you would expect and it is stark: 76% of large businesses, 57% of medium-sized ones, 21% of micro businesses. Where a breach did occur, 81% of businesses told their directors and 62% kept an internal record, but only 40% reported the most disruptive incident outside the organisation at all.

Set that against an attack that begins with a fluent message. The chain from first delivery to material loss runs through detection, decision and containment, and two of those three are organisational rather than technical. An organisation with no plan does not fail at the moment of the click. It fails at hour six, when nobody is sure who can authorise disconnecting a system.

The remedy is unglamorous and cheap at the point of writing. A named person with authority to disconnect, a written statement of who must be told and when, a tested route to restore from a backup nobody’s compromised credentials can reach, and one rehearsal a year. None of that requires a product, which is presumably why so little of the market bothers to sell it.

Change what you measure

Click rate is a bad metric and it survives because it is easy. It punishes the people most exposed to external email, it produces a number that trends downward for reasons unrelated to risk, and it measures the layer the NCSC says cannot be perfected.

Two better numbers exist and both are already collectable. Median time from first delivery to first report, which measures whether your people will tell you quickly, and coverage, meaning what proportion of your estate is actually monitored. A council cyber lead interviewed for the DSIT-commissioned study of local council cyber risk framed the purpose of their phishing exercises in exactly those terms, describing the point as understanding how quickly the first person will flag a message so it can be blocked. That is the correct use of a simulation. It tests the reporting pipeline, not the eyesight of the workforce.

One further figure from the breaches survey is worth sitting with. Asked unprompted where they get cyber security information, 1% of businesses and 1% of charities named the National Cyber Security Centre. The best free guidance in this field, written by the national technical authority, reaches almost nobody who has not already gone looking for it.

What we are not asserting

There is a great deal of commentary attaching precise percentages to the share of phishing now written by a model. We have not found a British source that can support such a figure, and it is not obvious how one could be produced, since the artefact left behind is a message and the message no longer carries the tell. Where a number of that kind appears without a named method, treat it as marketing. The NCSC’s assessment is stated in likelihood language for exactly this reason.

Wider coverage of how compromise reaches British organisations sits under cybersecurity, and the architectural question of what an attacker can do once inside is taken up in the parts of zero trust that survived the budget.

Sources

  1. NCSC, The near-term impact of AI on the cyber threat, 24 January 2024 ncsc.gov.uk
  2. NCSC, Phishing attacks: defending your organisation ncsc.gov.uk
  3. DSIT and Home Office, Cyber security breaches survey 2025/2026, 30 April 2026 gov.uk
  4. ICO, Fine of nearly £1m issued against South Staffordshire Plc and South Staffordshire Water Plc, 11 May 2026 ico.org.uk
  5. WSP for DSIT, The changing cyber threat profile and potential impact on local councils, published 9 June 2026 gov.uk
  6. ICO, Software provider fined £3m following 2022 ransomware attack, 27 March 2025 ico.org.uk