Earlier quoted context omitted.
Did they run the tests without training first? What’s the point? If Security/IT is so dense that they see any value in testing before training, we’ve already identified a problem: culture or a “our employees are too smart for this issue”.
> Did they run the tests without training first? What’s the point? How do you know if your training is working if you have no baseline?
I’m also curious about what training methods work best (including a no-training control group).