Aren’t users / social engineering make up the actual majority of real-world vulnerabilities, and pose the most prevalent extant threat in the entire software ecosystem?
Beyond that, I've already addressed phishing at our company, it just didn't seem worth pointing out.