An organization has just completed a phishing simulation and found that 35% of employees clicked a simulated GenAI-crafted spear-phishing email that referenced each employee's specific project names. What should the training emphasize as the primary lesson?
- A.The organization should immediately implement an AI-generated email detection tool to prevent future spear-phishing campaigns, since LLM-written phishing keeps fixed telltale phrasing
- B.The presence of accurate personal context (project names, colleagues' names) in an email is NOT evidence of legitimacy - attackers can obtain this context from LinkedIn, company websites, and data breaches - so employees should verify unexpected requests through a separate channel regardless of how accurate the email appears
- C.Employees should be more careful reading email headers to identify spoofed sender addresses