Following a phishing incident, IT security teams experience a specific kind of fatigue. It’s more like the slow, grinding exhaustion of people who know they cleaned up one mess today and will probably have to deal with another one next week than the dramatic kind you’d see in a thriller. It’s difficult to avoid drawing the conclusion that one of the most underappreciated expenses in contemporary business is the financial burden of phishing defense when one observes this pattern recurring across industries.
They can’t read the numbers comfortably, and they don’t lie. In 2024, the average cost of phishing-related breaches to organizations was $4.8 million. The obvious line items—legal fees, regulatory fines, and immediate containment costs—are included in that figure, but businesses are frequently caught off guard by the indirect damage. System outages. lengthy cycles of remediation that span several departments. For weeks at a time, IT teams worked on critical infrastructure projects, caught in what one security expert called a “never-ending cycle of playing catch-up.” The fact that the phrase is accurate is why it landed. In breach response, there is only a point at which things become stable enough for people to breathe again; there is no finish line.
The extent to which AI has changed the attack landscape is what makes the current situation especially challenging. There were once telltale signs of a phishing email, such as awkward wording, glaring grammatical mistakes, and a general feeling that something wasn’t quite right. Most of those days are long gone. The average click-through rate for AI-crafted phishing messages is now 54%, while traditional phishing attempts have an average click-through rate of about 12%. For attackers, that is a significant shift in the threat’s nature rather than a slight improvement. These messages create customized lures that can pass for executives, coworkers, or vendors by scraping social media, business profiles, and public records. Nowadays, campaigns that used to take days to develop can be started in a matter of seconds. The attacker-defender sophistication gap has grown significantly.
Companies may still be underestimating the amount of ground they’ve lost on the human side of this equation. Although most cybersecurity budgets still include security awareness training as a standard line item, there is actually conflicting evidence regarding its effectiveness on a large scale. Research from Dashlane’s 2025 State of Credential Security report revealed that 22% of workers would prefer to sit in traffic during rush hour than go to a required security training session. A root canal would be preferred by 11%. The compliance-driven model of security education, in which staff members click through an annual training module and check a box, may not be producing the desired behavioral change, according to these statistics. Additionally, when employees fall for a phishing attempt, they frequently choose to remain silent rather than report the incident out of fear of professional repercussions. It is in that quiet that minor violations subtly grow into major ones.

Additionally, phishing has expanded far beyond email, which makes defense considerably more difficult. Smishing attacks, or phishing via text message, increased by 22% in just the third quarter of 2024. Concurrently, there is an increase in voice phishing, in which attackers call workers while posing as executives or IT personnel. When a threat appears as a text message with a single link or as a phone call from someone who sounds authoritative and urgent, workers who have been trained on suspicious emails might be much less ready. Security budgets have not always increased in tandem with the growth of the attack surface.
Here, it’s important to make a more comprehensive systems argument, which some organizations are starting to acknowledge more openly: phishing is essentially a systems issue rather than an employee issue. It is unrealistic and unfair to place the entire burden of defense on individual employees, who are frequently multitasking, busy, and occasionally under stress. Since phishing is a social engineering attack with no malicious code to scan and quarantine, antivirus and anti-malware programs are of limited assistance. Strong email filtering, multifactor authentication, and AI-powered real-time phishing alerts that can identify dubious websites before credentials are entered are all necessary for an effective defense. Reducing the number of situations in which a single human choice could jeopardize millions of dollars is the aim.
Principal and vice president of JD+A Chelsea Richardson put it succinctly in a way that stuck: a breach takes the trust your company has worked so hard to earn, not just your security. A financial report never neatly displays that expense. It can be found in challenging client conversations, the scrutiny that follows a public disclosure, and the subtle decline in trust that is difficult to measure but impossible to overlook. Yes, the cost of protecting against phishing attacks is extremely high. However, the reputational cost is what keeps executives up at night in many businesses.
