This year marks the 30th anniversary of the first phish. For three decades, we have been on the back-foot trying to counter this tactic. The last decade, thanks in large part to vendors, it has all been about the phishing simulation. Phish our users. That’ll teach them. But simulated phish tests have failed to meaningfully change user behavior. And simulated phish tests provide a false sense of security. Worse, the tests have done real damage to real people, the very same people we need to protect. F’that. This talk is rallying cry to kill the simulation, stop blaming people, and embrace better technical controls.