Earlier quoted context omitted.
I agree in a theoretical way. But in the real world corporations don't have skilled infosec/cyber people and they wouldn't even know how to find them [1]. So they end up with incompetent departments imposing ridiculous limitations for theater. And these worsen end user aversion to security. Younger generations care less and less about security and privacy. And the growing corporate disdain of employees (in particular…
Training can help to reduce failures, but it can never prevent failures, because even at the minimum, human err at scale is guaranteed. If a monkey randomly types on a typewriter for an infinite amount of time, it will eventually produce any given text, including ̶t̶h̶e̶ ̶c̶o̶m̶p̶l̶e̶t̶e̶ ̶w̶o̶r̶k̶s̶ ̶o̶f̶ ̶S̶h̶a̶k̶e̶s̶p̶e̶a̶r̶e̶.̶ opening a ransomware attachment
Sure,and indeed the goal is to have better security, not prefect security. If you look for the perfect solution, you will never find it.