Security awareness training
Security awareness training was built to reduce risk by teaching employees to recognize phishing.
Platforms run simulated campaigns, score click rates, and deliver follow-up training to those who click.
That model requires users to make the right call, every time. Modern browser-based attacks are specifically designed to make that harder.
Stop testing users. Start stopping attacks
The problem with modern phishing attacks is that spotting one reliably requires expert-level pattern recognition that most users can't be expected to apply consistently, under real-world conditions, every time. Putting that burden on individuals is an unreliable security model.
Push doesn't test judgment. It detects and blocks attacks in the browser before the user even needs to make a decision.
| Dimension | Push Security | Security awareness training |
|---|---|---|
| Security approach | Yes — Detects and blocks attacks in the browser | Partial — Trains users to recognize suspicious signals |
| Protection model | Yes — Works regardless of whether the user recognizes the threat | No — Depends entirely on the user making the right call |
| Sophisticated attacks (AiTM, ClickFix, AI-generated) | Yes — Detects automatically at the technical level — no reliance on user pattern recognition | No — Requires users to spot signals that demand expert-level knowledge to identify reliably |
| When a user clicks | Yes — Blocks credential entry and the malicious page in real time | No — No intervention — the attack proceeds |
| Security education | Yes — In-browser warnings when real attacks are blocked — employees learn from actual threats at the moment they matter | Partial — Periodic simulations using fictional scenarios |
| Attack channels | Yes — Any channel that delivers phishing to the browser — email, SMS, QR codes, search ads | No — Email-focused simulations |
Frequently asked questions
The evidence is weak. The largest controlled study (Purdue, 12,511 employees) found no significant effect on click rates. A UCSD study (19,789 personnel) found annual training reduced click likelihood by just 2%. Even favorable evidence applies exclusively to email-based phishing, while the dominant attack channels have diversified — ClickFix arrives via search engines, AiTM operates on legitimate login pages.
Push provides technical detection controls that don't depend on user judgment. Read the evidence.
Modern phishing is designed to defeat trained judgment. AiTM uses legitimate IdP pages — nothing for a trained user to spot. ClickFix mimics familiar CAPTCHAs. AI-generated lures are increasingly indistinguishable from legitimate communications. Phishing arrives through non-email channels that training doesn't prepare users for.
Push removes the dependency on user judgment by detecting and blocking attacks automatically. See why training falls short.
Technical controls that detect phishing automatically — without depending on the user to identify the attack. Browser-based behavioral detection catches phishing pages by analyzing structure and behavior, regardless of how convincing they look.
Push detects AiTM, cloned login pages, ClickFix, and credential harvesting inside the browser. Every blocked attack also becomes a contextual learning moment — the user sees what was blocked and why. See Push's approach.
Yes. AI eliminates the grammatical errors and awkward phrasing that training teaches users to look for. Studies found AI chatbots achieved ~50% compliance rates versus <20% for human scammers in social engineering scenarios.
The solution is technical controls that detect page behavior — which remains consistent regardless of how the lure is crafted. Read about AI and phishing.
Browser-based behavioral detection that identifies phishing pages automatically. Push detects AiTM kits, cloned login pages, ClickFix, and credential harvesting by analyzing page behavior. In Block mode, users never reach the phishing page. In Warn mode, they see an explanation before deciding.
This eliminates the dependency on human judgment. See Push's automated detection.
Training tries to make users better at recognizing phishing — a human-dependent, probabilistic defense. Automated detection analyzes page behavior technically — a system-dependent, deterministic defense. Training fails when phishing is convincing; automated detection catches it regardless.
The two are complementary. Training raises baseline awareness; automated detection catches browser-based attacks that training can't reliably prevent. See the comparison.
Many frameworks (PCI DSS, HIPAA, SOC 2, Cyber Essentials) require security awareness programs. However, the requirement is typically for a security awareness program, not specifically simulation-based phishing training. Technical controls that provide contextual education (like Push's in-browser warnings) can contribute to compliance.
Check your specific regulatory obligations. Learn about compliance.
Browser-based behavioral phishing detection. Push detects AiTM, ClickFix, cloned login pages, and credential harvesting inside the browser — catching attacks that bypass both email security and user awareness.
Combine email security (reducing lure volume), browser-based detection (catching what gets through), and credential hygiene enforcement (reducing impact of compromised credentials).
The evidence is mixed. The largest controlled study found no significant effect. Smaller studies with favorable designs show modest results but tend to have methodological limitations.
Even favorable evidence applies only to email-based phishing. Simulations don't prepare users for ClickFix, AiTM, or device code phishing. Technical controls address all these vectors. Read the evidence.
Browser-based behavioral detection to catch phishing automatically, credential hygiene enforcement to reduce impact of compromised credentials, and session monitoring to detect stolen token replay.
Push provides all three: behavioral phishing detection, credential security at login, and session integrity via marker injection.
Latest resources


