@cR0w the thing that pisses me off is that we do all this 'learn the three signs of phishing' crap (links, a grammatical error, from an external address), but then every quarter we are required, immediately, to open the employee satisfaction email, from an external sender, click the link, and enter our credentials.
Stop requiring us to 'get faux-phished' by management, but also not 'get test-phished' by security and also not 'get real phished' by phishers.