"Company: Stop clicking on links to third party sites.
Also Company: All of IT, HR, benefits, cloud storage, customer management, and employee portal is moving to its own third party platform!"
Smart companies validate and tag those third party emails as "partner" or similar. That way the users are only using the extra scrutiny on the non-partner external emails.
Yes although this runs the risk of what you commonly see at daycares and schools.
There'll be a sign that says "Peanut free zone" and everyone will read it and respect it.
Then there'll be a sign that says "Please be sure to pick your kid up by x o'clock." And everyone will read it and respect it and silently stop looking at it cause they know.
And then there will be a sign that says "Please keep your child at home if you suspect they might be sick." And everyone will read it and be a little offended because why would they do that knowingly?
After a while the entrance will be plastered with notices and warnings that get put up and not taken down. And nobody reads them because they probably already know and it's not worth spending 20 minutes reading the entire wall.
I get the external/partner emails. And a notice that outlook removed extra line breaks from the message (whew). And a notice that if there are problems reading the email I can view it in a web browser. And a helpful suggestion that Copilot can give me the tldr.
What’s to stop a phishing email putting a “verified by IT anti-phishing software” line at the top of the email? People don’t pay attention to special verification flags when they are there, so they don’t see them when they’re missing.
You have ingress filters that strip the subject tag out of anything and only add it back if it is verified. It's really not that hard and the training is supposed to train people. Nothing is perfect, nor does it need to be with defense in depth.
Also Company: All of IT, HR, benefits, cloud storage, customer management, and employee portal is moving to its own third party platform!"
Smart companies validate and tag those third party emails as "partner" or similar. That way the users are only using the extra scrutiny on the non-partner external emails.