"The user clicked a phishing link" is a symptom, not a root cause.
Walk a typical account compromise backward and the real questions show up:
- Why did the email get delivered? Auth results, filtering verdict, policy exceptions
- Why did the credentials work? MFA coverage, legacy protocols, session handling
- Why did nobody notice? Forwarding rules, sign-in anomalies, alerts that fired and got ignored
- Why was the damage possible? Permissions, payment processes, approval steps
Each answer is a different fix. Training the user fixes one of them, maybe.
Root cause analysis is how you turn one bad day into a control that keeps working. Stop at the click and you'll be investigating the same incident again next quarter.