When your Risk Management department starts phishing the company in an effort to develop job security or increase their perceived relevance.
I didn't really get phished much until Risk and Compliance started Phish Pharming us every few days.