How do you stop phishing attacks from succeeding?
You stop phishing with three things no filter can supply on its own. Staff who recognise the pressure tactics, a no-blame reporting habit, and a verification rule that any payment or banking change is confirmed by voice on a number you already hold. Your firewall is world-class. Your antivirus is updated. Your endpoints are hardened. None of that matters when an attacker sends your finance manager an email that says: "Hi Sarah, I need you to process this invoice immediately. I'm in a meeting and can't discuss, please pay today. CEO" with a convincing fake email address.
Technical controls catch 99% of obvious spam and malware. The 1% that gets through is usually highly targeted, well-researched, and psychologically manipulative. Hackers have realised that the human brain is a much softer target than corporate firewalls.
Why does phishing work on sensible people?
Phishing works because it manufactures urgency, borrows authority and offers a single easy action, which together bypass deliberate thought in exactly the way good design intends. Phishing works because it exploits how humans naturally think. We're wired to respond to authority ("The CEO said so"), urgency ("Pay this NOW"), and helpfulness ("Can you do me a quick favour?"). Attackers know this and craft their messages accordingly.
Business Email Compromise (BEC) costs South African businesses millions annually. The attack is simple: impersonate someone with authority, create urgency that prevents careful thinking, and request something that seems reasonable in isolation.
What are the warning signs staff should look for?
- Urgency and Pressure: "Pay this invoice immediately or we lose the account." "Your account will be suspended in 24 hours." Hackers rely on panic to bypass critical thinking. Legitimate requests rarely have artificial urgency. When you feel pressured, that's the moment to slow down.
- Mismatched Domains: Look at the actual email address, not just the display name. "Microsoft Support"
is NOT from Microsoft. Hover over links before clicking to see where they actually lead. If an email claims to be from your bank but the link goes to "secure-banking-login-verify.suspicious-site.com", it's fake. - Generic Greetings: "Dear Customer" or "Dear User" instead of your actual name. Legitimate services know who you are. They use your name.
- Requests for Credentials: No legitimate organisation will ever ask you to "verify" your password via email. If you receive such a request, it's phishing. Always.
- Unusual Payment Instructions: "We've changed our banking details" emails are almost always fraudulent, even if they appear to come from known suppliers. Always verify banking changes via phone call to a known number, not a number provided in the email.
| Red flag | What it looks like | The correct response |
|---|---|---|
| Urgency | "Within 24 hours", "final notice", "account suspended" | Slow down; genuine deadlines survive a phone call |
| Lookalike sender | One character changed in the domain, or a subdomain trick | Read the full address after the @ sign, right to left |
| Banking change | A supplier says their account details have changed | Phone them on the number you already hold, never the one in the email |
| Unexpected attachment | An invoice or CV you were not expecting | Confirm with the sender before opening |
| Credential prompt | A link that opens a Microsoft or Google sign-in page | Type the address yourself instead of clicking |
How do you build a phishing reporting culture?
Build a reporting culture by making reporting effortless and never punishing anyone who reports a click, because the reports arrive fast enough to protect everyone else only when people are not afraid. The best defence is a culture where it's not just okay, but actively encouraged, to ask "Is this real?" before clicking or acting. Staff who fear punishment for "asking stupid questions" stay silent. Silent staff fall for phishing.
Create a simple reporting mechanism. At minimum: "If something feels off, forward it to IT before clicking anything." Even better: implement a "Report Phishing" button in your email client that alerts the security team automatically.
When someone reports a suspicious email, even if it turns out to be legitimate, praise them publicly. Celebrate the cautious behaviour you want to see. Make security awareness a team achievement, not an individual burden.
Do simulated phishing campaigns actually help?
Yes, when they are used to measure and coach rather than to catch people out. Run them quarterly, report the trend rather than naming individuals, and follow every failure with short training instead of a reprimand. We recommend running simulated phishing campaigns. Not to punish staff, but to give them a safe environment to fail and learn. Getting caught by a fake phishing test is embarrassing but harmless. Getting caught by a real attack isn't.
After each simulation, run brief training for those who clicked. Focus on the specific technique that fooled them. Over time, your organisation develops collective immunity to common tactics.
What should you do if you clicked a phishing link?
If personal information was exposed, POPIA notification duties start the moment you discover it: our POPIA compliance guide sets out who to tell and when.
Disconnect the device from the network, phone IT rather than emailing them, change your password from a different clean device, and report it immediately even if nothing appears to have happened. Speed is everything. Don't hide it. Don't hope nobody notices. Don't try to fix it yourself.
Reporting immediately allows IT to reset passwords, revoke active sessions, and check for damage before data is stolen or ransomware spreads. The difference between "Sarah clicked a link" and "We've lost all our client data" is often just minutes.
Shame causes silence, and silence causes breaches. If someone admits they clicked something suspicious, thank them for telling you quickly. Their honesty might have just saved the business. If you want help building this culture, our cybersecurity service includes staff awareness training and simulated phishing campaigns.
