The attacks that get through filtering
Filtering stops bulk malicious mail. What reaches people is the targeted remainder: a message from a genuine compromised account at a vendor the organization actually uses, a payment change request timed to a real invoice, a mailbox rule quietly forwarding a copy of everything to an outside address.
Those need controls rather than better filtering: multi-factor authentication on mailboxes, alerting on forwarding rules and impossible-travel logins, external sender marking, and a payment verification procedure that does not depend on email confirming email. The last one is a business process and it prevents more loss than any product.