An organization has just completed a phishing simulation and found that 35% of employees clicked a simulated GenAI-crafted spear-phishing email that referenced each employee's specific project names. What should the training emphasize as the primary lesson?
- A.The organization should immediately implement an AI-generated email detection tool to prevent future spear-phishing campaigns
- B.Employees should be more careful reading email headers to identify spoofed sender addresses
- C.The presence of accurate personal context (project names, colleagues' names) in an email is NOT evidence of legitimacy - attackers can obtain this context from LinkedIn, company websites, and data breaches - so employees should verify unexpected requests through a separate channel regardless of how accurate the email appears