💢 Decoded – The cost of phishing keeps rising, so companies decided to spend less (WTF)

Phishing is the number one way into a company right now.
Right on cue, breached firms cut their planned security spend from 63% to 49%.

Here is a number from IBM’s 2025 breach report that should have made more noise: after getting breached, 49% of organizations said they planned to increase security investment. The year before, that figure was 63%.
Read the direction of travel: companies got hit, tallied up the cost of phishing and everything that rides in behind it, and concluded that the move was to spend less. Not flat. Less. The reflex kicked in, trim the line item, protect the quarter, and it kicked in hardest exactly where the bleeding was.

When the cost of phishing was low, cheap defence made sense

Let’s walk this back with the right eyes, because there was a moment when that instinct was defensible 👀

For a long time, phishing earned its reputation as the dumb attack: the Nigerian-prince register, typos, a logo stretched to the wrong aspect ratio, a sender address one letter off if you squinted. You could train for that with a slide deck and a fifteen-minute video renewed every January. The control was cheap because the attack was cheap, and everyone in the room knew it. Spotting a bad template is a low-skill task, so the training that taught it was a low-cost task, and finance filed it under compliance-theatre-you-have-to-buy.

Nobody genuinely pretended the annual module changed behaviour.
It just changed the audit checkbox, that was the arrangement, and it was honest in its own way.

So in that world, minimising the awareness budget wasn’t negligence. It was.. well, arguably rational.
The threat was a known-shape thing you could catch with pattern-matching, and pattern-matching is the one skill you can drill into a whole workforce for the price of a lunch-and-learn and the math held because the attacker’s effort and the defender’s effort were roughly matched at the very bottom of the cost curve. Cheap attack, cheap defence, everybody goes home. For about fifteen years, that was a fair fight.

Then only one side of the table got the AI discount, ka-chiiiing!

Then the bottom of the cost curve moved, just not on both sides at once.

In IBM’s 2025 numbers, phishing is now the single most common way into a breached company: 16% of all breaches, at an average cost of $4.8 million each. Not the exotic zero-day the vendor slides love.
The email.
And the thing that used to make phishing cheap to catch (the tells, the typos, the clumsy pretext) has quietly disappeared; generative AI dropped the time to write a convincing lure from roughly sixteen hours to five minutes. The grammar is clean, the tone matches your CFO’s actual cadence and the pretext cites a real invoice, because the sender read your supplier’s public case study before writing to you.

The payoffs are not hypothetical, right?
The FBI’s IC3 logged $2.77 billion in business email compromise losses in 2024 alone ($17.1 billion since 2015, geez) from attacks that carry no malware, no exploit, no link a gateway can quarantine. Just a person, a plausible message, and a wire that leaves on time.

So the attacker’s cost per attempt collapsed toward zero while the quality went up. That is the whole story of the year in one line: the cost of phishing to run went down for them, and the cost of phishing to absorb went up for you. And into that widening gap, the boardroom reached for the lever it always reaches for when a number turns scary. Cut. Trim the spend, defer the tooling, keep the fifteen-minute video because it is already paid for. The reflex that was rational when the attack was cheap is now pointed straight at the most expensive front door you own.

Untested is not neutral: it is a bet you did not know YOU placed

Both sides of this are running the identical playbook.
Attacker and defender are both optimising for cost.
The attacker cut their cost with a language model and used the savings to scale the attack.
The defender cut their cost with a budget line and, without meaning to, used the savings to scale the exposure.
Same verb, opposite blast radius.

And the reason the defender’s cut feels safe is that nothing happens the day you sign it: the invoice for that decision doesn’t arrive on a schedule you control. It arrives on a Tuesday, when someone in finance opens a flawless email from a vendor they’ve paid forty times, and pays it a forty-first.

Untested is NOT neutral. Untested is a workforce holding a completed-training certificate and exactly zero evidence they would behave any differently under a real, well-built pretext. The certificate cost you money. The evidence is the thing you decided not to buy.

We build social-engineering simulations for a living, so let me put the uncomfortable version plainly: the only number that tells you whether your people can survive a modern lure is the one you get from firing a modern lure at them and watching what they do. Everything upstream of that is a self-assessment wearing a compliance badge. You can defer that spend. You cannot defer the attacker, and he already took the upgrade.

Somewhere a CFO signed off on a leaner security budget this quarter and felt responsible for having done it. The numbers went down. Good governance. Somewhere else, someone with a language model and a free afternoon just lowered his cost of phishing your company to about five minutes and a coffee.

Two people cut costs this week. Only ONE of them is going to get paid for it.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top