skip to content

The Research Budget

Mass, spear and executive-aimed lures are one cost curve, not three techniques, and research time does not scale. Interviewers ask because people assume the most targeted operation is the strongest.

on this pageshow

explore

questions

4

Across bulk, spear and executive phishing lures, which rung pays most per operator hour?

level: middleimportance: must knowfreq 62%

answer

  1. divide by hours, never by messages
  2. one crew, one month, one budget
  3. fixed research shared across recipients
  4. forty trials beats one coin flip
  5. bulk returns unselected accounts

basics

~20 s

Usually the middle rung. Spear reuses one block of organisation-level research across dozens of named recipients, so success per recipient rises steeply while hours per recipient stay small. Bulk yields commodity accounts; executive stakes a week on one attempt.

solid answer

~50 s

Price the same three-person crew over one month. Bulk is one template against 400,000 addresses: perhaps twenty hours all in, an enormous denominator of messages and a tiny per-message rate, and what falls out is unselected commodity accounts, mostly not at any target you chose. Executive is one recipient with a week of preparation: forty hours spent on a single attempt whose outcome is one coin flip. Spear sits between: forty named recipients at roughly two hours each, but most of those hours are organisation-level facts collected once and reused, so the marginal cost of the fortieth recipient is small. That combination - a shared fixed research cost, a steep lift in per-recipient credibility, and enough attempts to survive variance - is what makes the middle rung pay. The denominator that matters is operator hours, never messages sent.

go deeper

for a junior

Know the three rungs and roughly what each costs to prepare: one template for everyone, a couple of hours per named person, or a week on a single individual.

for a middle

Explain the arithmetic out loud. Operator hours are the denominator, organisation-level research is a fixed cost shared across recipients, and the per-person increment is small.

for a senior

Show you can separate yield rate from expected value, and say which rung a given objective implies - selected access inside one company, or a single large authorisation.

for a principal

Own the strategic reading: if the middle rung is cheap and getting cheaper, planning that assumes tailored lures are rare is planning against last decade's cost curve.

### The right denominator Every comparison of phishing rungs goes wrong at the same place: people divide by messages. Messages are close to free at the bulk end, so per-message rates flatter bulk and punish everything else. The scarce input is operator time. Three people for one month is roughly 480 working hours, and every rung is competing for the same block of hours. Yield per operator hour is the only comparison that reflects the constraint the crew actually faces. ### The three rungs, priced **Bulk.** One template, one landing page, a list of 400,000 addresses. Fixed cost is small - call it twenty operator hours for the template, the infrastructure and the sending - and the marginal cost per additional address is effectively zero. The per-message success rate is tiny, but multiplied by a very large number it still returns something. The problem is the product, not the arithmetic: what returns is unselected. Whoever fell for a generic message is whoever they are, at whatever organisation, holding whatever access. If the crew wanted a specific company, bulk almost certainly did not deliver it. **Executive.** One recipient, a week of preparation: reading everything published about the person, understanding the specific approval they can grant, timing the message to something real. Forty hours for a single attempt. Even if the per-attempt probability is high, the whole spend resolves as one outcome. Variance is total: a month of this is at most four trials. **Spear, the middle rung.** Forty named recipients at a nominal two hours each. The naive reading is eighty hours, but that overstates it badly, because the research decomposes: ``` organisation-level facts collected once reused x40 person-level increment ~20-40 minutes per recipient ``` The expense system's name, the hostname pattern, who signs payments, the shape of the approval chain - all of that is paid for once. What is genuinely per-person is the reporting line, the current project and the timing, and that is a fraction of an hour. So the effective spend is a fixed block plus a small increment forty times, not two hours multiplied out. ### Why the middle rung wins the arithmetic Three effects compound. 1. **Amortisation.** The fixed research is divided across every recipient, so the average cost per recipient falls as the target set grows within one organisation. 2. **A steep credibility gradient.** The move from a generic message to one that names the system, the process and the person is not a marginal improvement in plausibility; it changes the reader's default from suspicion to recognition. Small hours buy a large jump. 3. **Enough trials to beat variance.** Forty attempts means the crew does not need any particular one to land. Two or three landings out of forty is a working month; the executive rung has no equivalent margin. And unlike bulk, every landing is inside the organisation the crew chose, which is what makes the yield worth anything. ### When the top rung is still rational Yield per hour is not the same as expected value. If a single executive can authorise a payment or an access change worth more than forty ordinary mailboxes combined, then a week on one person can dominate on expected value while losing badly on yield rate. The top rung is a bet on payout size, not on efficiency, and it is chosen when the objective is something only that one person can grant. ### The claim to be careful about The curve is not fixed. As the cost of producing fluent, contextually specific text falls, the hours of writing stop being the binding constraint and the research becomes the whole cost - which pushes the middle rung's economics further in its favour and erodes the old assumption that a well-written, specific message must have been expensive. Any answer that treats production cost as the reason tailored lures are rare is describing a market that has already moved. ### The wrong answer to avoid 'Bulk pays best because volume is free.' Volume is free; the operator hours that turn volume into usable, selected access are not, and bulk does not produce selected access at all. Comparing rungs by click rate per message reproduces exactly that error.

  • If the middle rung pays best per hour, why does anyone spend a week on one executive?
    Because yield rate and expected value are different quantities. One person who can authorise a large payment or a privileged change may be worth more than forty ordinary mailboxes, so the top rung can dominate on expected value while losing on efficiency. It is chosen when the objective is something only that individual can grant.
  • What is wrong with comparing rungs by per-message success rate?
    It divides by the input that is free. Sending is near-costless at the bulk end, so per-message rates make bulk look efficient regardless of what it returns. The scarce input is operator time, and the useful comparison is yield per operator hour, weighted by whether the yield is inside the organisation the crew actually wanted.
  • Once the organisation-level research is done, where does the marginal hour go?
    Into the person layer and the timing: reporting line, current project, what this individual plausibly does weekly, and when the request would land naturally. That increment is tens of minutes, which is precisely why per-recipient tailoring is cheap enough to do forty times.

Bulk is a leaflet drop, executive is a single bespoke sales pitch, and spear is one afternoon of reading about a company followed by forty tailored calls into it.

saying these in an interview costs you the question

  • Compares rungs by click rate per message
  • Assumes research cost scales linearly with recipient count
  • Says bulk campaigns are obsolete
  • Treats a week on one person as always irrational
  • Ignores that bulk yields unselected accounts

context

open as a page

Which company-published facts make a phishing lure credible at zero research cost?

level: juniorimportance: should knowfreq 50%

basics

~10 s

The organisation's own published surface: job adverts naming internal systems and approval chains, certificate transparency and DNS entries naming hostnames, regulatory filings naming who signs, and conference bios naming who reports to whom.

open as a page

How do you price the claim that serious attackers write a bespoke phishing lure per person?

level: seniorimportance: should knowfreq 45%

basics

~10 s

In operator hours the claim is cheap: forty recipients at two hours each is roughly two operator-weeks, and much of that reading is shared across all forty. Tailoring prices the message, not the sender.

open as a page

HR's job adverts name your internal tools. What do you ask them to change, and what does it buy?

level: principalimportance: nice to knowfreq 30%

basics

~20 s

Ask only for details with high lure value and low hiring value: internal system names and approval chains. It buys an operator an hour or two, not immunity, since filings and certificate transparency entries cannot be withdrawn.

open as a page