The role sits on the fault line
Lesson one described the assistant as a gatekeeper. That position is valuable to an organisation for the same reasons it is valuable to an attacker.
What an assistant has that an attacker wants. Access to the executive's accounts, calendar and correspondence. Knowledge of what is happening, including things not yet public. Standing to make requests of other people in the organisation, who will act on them. And in many organisations, the ability to initiate or approve payments and to change details on them.
What an assistant is trained to do that makes exploitation easier. Respond quickly. Act on instructions from someone senior without interrogating them. Handle things discreetly, without involving others. And solve problems rather than escalate them.
Every one of those is a professional virtue, and every one of them is exactly what a social engineering attack needs.
That combination, privileged access plus a professional obligation to be responsive to authority, is why this role is disproportionately targeted rather than incidentally caught.
Which means security awareness for an assistant is not a generic training module. It is a specific, role-shaped problem: how do you stay responsive and discreet, which is your job, without those qualities being the vulnerability.
The answer, developed through this lesson, is a small number of habits applied without exception, particularly to the requests that most feel like exceptions.

