The advice that stopped working
For two decades, security awareness training taught a set of signals. Look for spelling mistakes. Watch for awkward phrasing that suggests a non-native speaker. Check for a generic greeting like Dear Customer. Hover over the link and look for a misspelled domain.
That advice worked because it described real constraints on attackers. Writing fluent, personalised messages at scale was expensive. A criminal sending a hundred thousand emails could not tailor them, and one working in a second language produced text that read wrong.
Those constraints have gone. Fluent text in any language is now free, and personalising each message to its recipient costs almost nothing.
What that means for the training most people have received. The specific signals it taught are no longer diagnostic. Worse, they are actively harmful, because someone who has learned to check for bad grammar and finds none concludes the message is genuine. The training now produces false confidence, which is a worse position than no training.
This is the same structural problem the journalists cursus described about deepfake tells. Any published detection signal is a defect being engineered away, so a defence built on recognising the current generation of attacks decays continuously.
What has not changed is the shape of the request, which the executive assistants cursus set out and which this lesson develops. Attacks still need you to do something. That requirement is what defences should target, because it is structural rather than cosmetic.

