For us they just make the people that click them do some online training. I don’t think anyone learns anything during that but I suspect not having to do the training serves as a great incentive to be careful.
It doesn’t help though that we’ve had multiple cases of obvious phishing mails everyone just deleted that were followed up by a “no those mails were legit please click the link” by HR…







Removed by mod