Use real attack data whenever possible. Generic templates can support baseline education, but they rarely teach the signals employees need to recognise in live traffic. Confirmed malicious emails make coaching more relevant because they reflect the organisation's actual threat surface, not an invented scenario. That usually improves recall, reporting quality and employee trust in the programme.
Why Real Attack Data Teaches Better Than Generic Phishing Templates
Generic templates are useful for onboarding and for teaching the basic structure of a phishing email, but they quickly become predictable. Real attack data shows how adversaries actually write, time and disguise messages, which is what improves pattern recognition. The practical difference is not just realism, it is relevance to the organisation’s own inbox, vendors, brands and workflows.
That matters because employees do not fail on textbook phish alone, they fail on the message that looks close enough to normal work to pass a quick glance. Training built from real malicious messages gives you examples that reflect current lures, not older training tropes.
When teams want a deeper view of how real campaigns are assembled and where the initial deception sits in the attack path, Mailchimp breach 2022 is a useful reminder that social engineering often succeeds by blending into ordinary business process.
What Changes in Recall, Reporting and Trust
Real attack data tends to improve recall because the examples contain the cues employees are most likely to miss in practice, such as sender impersonation, urgency framing, OAuth consent prompts or unusual attachment paths. It also improves reporting quality because people learn what suspicious messages look like in context, not in an abstract template that feels obviously fake.
Trust is another material factor. If staff can see that training mirrors the threats they actually receive, the programme feels like a live defence measure rather than a compliance exercise. That usually increases engagement and reduces the scepticism that can come from overused, obviously synthetic examples.
For a concrete example of how realistic phishing can extend beyond email into consent and token theft flows, CoPhish OAuth phishing via Copilot Studio shows why modern training needs to reflect current interaction patterns, not only legacy message formats.
How to Build a Better Training Mix
The best programme usually uses both, but for different jobs. Generic templates are fine for introducing concepts, standardising baseline awareness and teaching first principles. Real attack data should carry the higher-value exercises, especially for role-based training, reported-message coaching and targeted follow-up after incidents.
Pick examples that match your actual threat surface, then vary them enough that staff do not memorise the answer pattern. If your environment sees supplier impersonation, invoice fraud, consent phishing or credential harvesting, those should be the dominant cases in the programme. The goal is not novelty for its own sake, it is behavioural transfer from training to inbox triage.
Where you need a broader view of how real attacker behaviour evolves across phishing, credential theft and lateral movement, CISA cyber threat advisories and MITRE ATT&CK Enterprise Matrix are useful reference points for shaping scenarios around current techniques.
Risk and Threat Considerations
Training that relies too heavily on generic templates can create false confidence. Staff may learn to spot obvious bait while still missing the smaller cues used in live attacks, especially when the lure is tailored to the organisation’s vendors, approvals, brand or tooling. That leaves a gap between training performance and real-world resistance.
Failure mechanism: the exercise becomes too predictable, so people learn the template rather than the threat. Attackers then succeed by using slightly different wording, trusted relationships or realistic workflow cues that were never practised.
Impact: lower detection quality, weaker reporting and slower escalation when a genuine malicious message arrives. In mature environments, that can also distort programme metrics by making training scores look better than actual defensive behaviour.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AT-01 — Awareness and Training Policies, Processes, and Procedures | Training content must reflect realistic threat conditions to build usable awareness. |
| Recommendation — Base phishing training on current attack patterns and update scenarios as threats change. | ||
| CIS Controls v8 | 14 — Security Awareness and Skills Training | The question is about improving awareness training effectiveness against phishing. |
| Recommendation — Use realistic phishing examples in recurring awareness exercises and role-based training. | ||
| MITRE ATT&CK | T1566 — Phishing | Phishing is the attack pattern being simulated and taught through training examples. |
| Recommendation — Map training scenarios to observed phishing techniques so users practise against current attacker methods. | ||
| NIST SP 800-53 Rev 5 | AT-2 — Awareness Training | Awareness training must be aligned to real threats to improve user response quality. |
| Recommendation — Refresh awareness content with confirmed malicious examples and measurable user reporting outcomes. | ||
Practitioner Guidance
What to prioritise: Use a small set of generic templates only for baseline onboarding, then move quickly to organisation-specific examples built from confirmed malicious emails, phishing simulations informed by real campaigns, and current threat intel.
What to verify: Make sure the training set reflects the message types employees actually see, including sender impersonation, payment pressure, document lures and authentication prompts. If it does not mirror real inbox conditions, it will train recognition, not judgement.
Practitioner takeaway: Generic templates are acceptable as a starting point, but real attack data is what turns awareness training into operationally useful detection practice.
Related resources from NHI Mgmt Group
- How can organisations use one confirmed phishing attack to improve broader detection?
- Should organisations use synthetic data or real user data for RAG testing?
- What should organisations do before allowing agents to use real tools and data?
- How can organisations use attack surface data to improve remediation decisions?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org