"I don't believe it's a problem companies have to solve."
While I agree everyone is personally responsible for their own online security, I don't agree that 'companies' don't belong under that umbrella.
Bottom line is, EVERYONE is responsible. Honestly, in today's world, anyone who falls for a phishing attack at work should just be fired. Quite literally they are simply too incompetent to be allowed access to a company's internal networks.
On the other hand, any service that still allows brute force attacks on their servers are also exhibiting an unacceptable level of incompetence.
These are two types of attacks that have been around for well over a decade, and they are EASILY defeated. People still succumbing to phishing attacks doesn't surprise me, there will always be incompetent people out there, but large organizations succuming to brute force attacks... that's just plain inexcusable.