← All articles

Phishing training that changes behaviour

·2 min read·By Adrian

Also available in ES, RO

Every company runs security awareness training. Most of it produces a completion certificate and no measurable change.

Why the annual session fails

It is an hour, once a year, delivered as a video with a quiz. Phishing arrives every day, from a different angle, when the recipient is busy. The formats do not match, and neither does the frequency.

What works instead

Simulations, monthly, realistic. Send the kinds of message your staff genuinely receive — a delivery notice, an invoice, a password expiry warning, a message that appears to come from a director. Generic templates train people to spot generic templates.

Immediate, short feedback. Someone who clicks should see a one-minute explanation at that moment, pointing at the specific signals in the specific message. Not a course booking for next month.

No punishment, ever. The instant clicking has consequences, reporting stops. You will still have the same click rate and you will lose all visibility into it.

Make reporting trivial. One button in the mail client. Measure reports, not just clicks — a rising report rate is the metric that actually predicts a good outcome.

The number that matters

Not the click rate. The time to first report. In a real campaign, what protects you is somebody raising the alarm within minutes, so the message can be pulled from every other mailbox before it is opened.

A company where fifteen percent click but somebody reports in four minutes is in a far better position than one where five percent click and nobody says anything for a day.

Aim the effort

Finance and management receive targeted attacks that others never see — convincing, well-researched, and specific to a transaction in progress. Give those teams separate, harder exercises, and pair them with a rule no email can override:

Any change to payment details is confirmed by phone, on a number already on file, before it is actioned.

That single rule stops the most expensive category of attack outright.

We run programmes like this within cybersecurity.

← Blog