~60% less risky clicking after AI spearphishing exercises
539 employees in four groups, measured from November 2024 to June 2025. Training improved attitudes, but the biggest change in what people actually did came from realistic exercises. The three-page report is free, with no form to fill in.


Leveraging AI-enabled spearphishing to enhance cybersecurity
Led by Dr. Carlo Pugnetti of the Lucerne University of Applied Sciences and Arts (HSLU) and Palo Stacho of Cyberdise, with GLB Group as a study partner. Baseline in November and December 2024, one intervention per group in May 2025, and a final exercise in May and June 2025 to measure the change.
- Can AI spearphishing work in Europe, where less personal data is public?
- Which changes behavior more, training or realistic attacks?
- What does each approach do to attitude, and what to behavior?
What changed behavior
Source: AISP study
From the study into the product
The exercises in the study were built from public information about each person. That work first appeared in Cyberdise in V2.7 as OSINT reconnaissance and is now part of Behavioral Defense Engineering, together with a generator that writes a phishing message for each recipient. The report also found that one well-run campaign no longer showed an effect on attitude after five months, so Cyberdise runs practice as a continuous loop.

Related research
Who ran the study?
Is the study peer reviewed?
What does ~60% refer to?
Does this mean awareness training is useless?
Do I have to fill in a form to get the report?
Run the exercises from the study with your own people.
In 30 minutes we show you how Cyberdise writes a personal exercise for each recipient and follows up on every click and every report.