Issue031 15 September 2026

I Work in Sales. I Don’t Know Anybody.

Amy Stokes-Waters 3 Min Read

“Don’t click links in emails from people you don’t know.”

We’ve all said it. It’s on the poster. It’s in the module. It’s in the little reminder on every email you get because someone in IT turned on email protection. And when I talked to Kieren Niĉolas Lovell 🇬🇮 on the podcast, a CISO who’s heard every version of this advice, he did the salesperson voice straight back to me: “Fine. I work in sales. I don’t know anybody.”

In sales, your entire job is opening emails from people you don’t know. Same for recruitment. Same for accounts payable. And customer service. Especially customer service whose whole day is an inbox full of people they’ve never met, most of whom are cross. We’re handing a rule to the workforce when half the building can’t even follow it if they want to actually do their job. And when they ignore it, we act surprised.

Of course they ignore it. What did we think was gonna happen?

And it’s not the only security advice people have to ignore. “Check for the padlock.” I bought a lookalike social media domain a while back. It cost me £4. And I had a convincing fake sitting on it within a couple of hours. Nice padlock on there. Because a padlock doesn’t mean it’s safe. It means it’s encrypted. And hackers like encryption just as much as the rest of us do. So that’s another piece of advice we’ve been drilling into people for a decade that does absolutely nothing.

“Hover over the link.” Redirects exist. “Check the sender address.” When it’s a display name and the real address is four clicks away? “Look for spelling mistakes.” Have you SEEN a phishing email recently? They’re better written than most internal comms.

This is the advice. This is what’s in the deck. And we wonder why it doesn’t change anything. Because it doesn’t. Give people a training module on how to spot a phishing email and measure how much better they get at it versus doing nothing at all. The study on it has already been done. The difference is 1.7%.

So a year of tricking your own colleagues buys you… roughly nothing. And I mean we know this right? But we run the sim anyway because the sim produces a chart, and the chart goes in the board pack, and “we’re doing something” is easier to say than “the thing we’re doing doesn’t work.”

All of the advice we give assumes the person on the other end of it has nothing better to do than audit every URL character by character. Except they do have something better to do. Their job. Their job that isn’t cyber security. It’s selling, or hiring, or paying invoices, or getting angry customers to be a bit less angry. Every rule we give them that costs time and for the most part produces nothing will get dropped almost immediately.

Which is fine. Because that’s what people do. It’s not a people problem. It’s an advice problem. So this week, I want you to go and get your phishing guidance. The poster or the module or the email you sent round. Read every line of it and ask one question about each bit of guidance: could someone in sales or customer service or accounts ACTUALLY follow it and still do their job properly?

That's it for this week. Reply and tell me what you think.

Amy

Amy Stokes-Waters · Founder, The Cyber Escape Room Co.