This doesn't seem like much of a reason to try and dissuade employees from discussing these things though.
I think there are probably a great many sysadmins, security analysts, and ciso's who can only dream of a day when run-of-the-mill employees are having casual conversations about phishing and identity security at the office.