"Organizations should train users"
Yeah, they should.
But that costs money and spending money on a problem that hasn't yet happened isn't in their DNA.
They'll run around like headless chickens when they've been pwned. Then spending money will be justified.