Lesson 02 · 3 min · 5 things to do
Phishing is arithmetic
Work out why a low success rate is enough.
A message is sent to 10,000 employees and 30 respond. Was it a failure?
- Yes.The attacker needs one. The defender needs everyone, every time. That asymmetry is the whole reason this technique persists despite everybody knowing about it.
- Not quite.The rate is not the measure. The count of successes is, and thirty successes is a large number.
- Not quite.It affects how much each one is worth, and any of the thirty is a way in.
The attacker needs one person to be having a bad day. The defence has to work for everybody, every time, forever.
Slide the number of messages sent and watch the arithmetic.
1001,000100,0000 of 100 · people who respond
100At a 0.3% response rate, probably nobody. A small organisation might be missed entirely.
3 of 100 · responses, per 1,000 sent
1,000Three responses. One of them is enough.
30 of 100 · responses, per 10,000 sent
100,000Three hundred, across many organisations, for almost no cost.
Sending costs almost nothing. What does that do to the defender's position?
- Yes.A defence that works 99% of the time fails once every hundred attempts, and there are millions of attempts. This is why the good defences are the ones that remove the possibility rather than reduce the rate.
- Not quite.Cheap sending funds targeted, well-researched messages as well as crude ones.
- Not quite.Most attempts do fail. The successes accumulate anyway, because the attempts are effectively unlimited.
Move the control to see what changes.
Which of these make a message more likely to work?
Urgency — something must be done in the next ten minutes.
Coming from someone the recipient reports to.
Arriving during a genuinely busy period.
Perfect spelling and grammar.
A convincing logo.
Yes.The effective levers are about the person's situation — pressure, authority, timing — not about the polish of the message. Training that focuses on spotting typos is defending against the wrong thing.A defence stops 99% of attempts. A hundred thousand attempts are made in a year. How many get through?
attemptsYes.A 99% success rate sounds excellent and is a thousand failures. This is why security thinking moves from 'reduce the rate' to 'make the successful attempt useless' — which is what the next lesson is about.Why is blaming the person who clicked the wrong approach?
- Yes.It is also practical: an organisation that punishes the click is one where nobody reports it, and the hours between the click and the report are the ones that decide how bad the incident becomes.
- Not quite.Sometimes they could. It still does not make individual vigilance a workable control at scale.
- Not quite.Training reduces the rate measurably. It cannot get the rate to zero, which is what the design was relying on.
Lesson complete
The attacker needs one success; the defence has to work every time.
Next: One account is never one account →