Ask any insurer or incident responder what starts most break-ins and you get the same answer: somebody clicked. Not a zero-day, not a cracked firewall. A plausible email landed in the accounting inbox and someone was having a rushed morning. You can spend a fortune on perimeter tooling and still leave the front door manned by a person, because that is exactly where every attacker aims.
What a real phish looks like these days
Nobody sends you a virus anymore. They send you a login page that looks right. A Microsoft re-verification notice, a DHL delivery-fee prompt, a quote attachment from a "supplier" whose logo they copied from your own vendor list. Locally, the favorite is the email that appears to be payment proof and asks you to confirm new banking details. The tells are few and boring: manufactured urgency, borrowed authority, and one small deviation from the normal. Your bank does not email from a gmail address asking you to re-validate a card. If a supplier changes their account number over email alone, that is the whole scam.
What training actually works
The annual slide deck nobody reads is compliance theater, and every security person knows it. What changes behavior is short and frequent. Three examples in the company chat each month, one spot-the-fake quiz, ten minutes total. Run simulated phishing attacks, but keep them blameless. When someone fails a simulation they get a two-minute explanation, not a name on a list. The moment you humiliate people they start hiding their mistakes, and then you have no data at all. Measure the reporting rate, not the click rate. A team that clicks 5% of lures but flags 80% of them is in better shape than one too scared to admit they clicked.
Then put a process under it
People will click regardless of how well you train them. Training raises the odds; the process is what saves you. No banking detail change is accepted without a phone call to a number you already had on file. New payees need two approvals. Email gets MFA, because that one control turns most stolen credentials into a non-event, as we covered last week. The nice thing about these rules is they are cheap. They cost a phone call, not a product licence.
Where we fit in
We set up the mail side so most fakes never reach an inbox: SPF, DKIM and DMARC configured properly, spam filtering tuned, and our business email plans enforce all of that from day one. Then we run the baseline phishing test so you can see where your team actually stands before an attacker does.
Curious how your staff would score? We run an hour-long baseline simulation, blameless by design, and hand you the numbers. Most clients find the first report is worth more than a year of slides.