Back to Insights
security8 min read

Phishing Prevention: Training Your Team

Phishing is behind most breaches. How to train your team to spot spear phishing, whaling and QR-code scams before one click costs your business.

The "Urgent Invoice" Scam

Your firewall is world-class. Your antivirus is updated. Your endpoints are hardened. None of that matters when an attacker sends your finance manager an email that says: "Hi Sarah, I need you to process this invoice immediately. I'm in a meeting and can't discuss, please pay today. CEO" with a convincing fake email address.

Technical controls catch 99% of obvious spam and malware. The 1% that gets through is usually highly targeted, well-researched, and psychologically manipulative. Hackers have realised that the human brain is a much softer target than corporate firewalls.

Understanding the Psychology

Phishing works because it exploits how humans naturally think. We're wired to respond to authority ("The CEO said so"), urgency ("Pay this NOW"), and helpfulness ("Can you do me a quick favour?"). Attackers know this and craft their messages accordingly.

Business Email Compromise (BEC) costs South African businesses millions annually. The attack is simple: impersonate someone with authority, create urgency that prevents careful thinking, and request something that seems reasonable in isolation.

Red Flags to Teach

  • Urgency and Pressure: "Pay this invoice immediately or we lose the account." "Your account will be suspended in 24 hours." Hackers rely on panic to bypass critical thinking. Legitimate requests rarely have artificial urgency. When you feel pressured, that's the moment to slow down.
  • Mismatched Domains: Look at the actual email address, not just the display name. "Microsoft Support" is NOT from Microsoft. Hover over links before clicking to see where they actually lead. If an email claims to be from your bank but the link goes to "secure-banking-login-verify.suspicious-site.com", it's fake.
  • Generic Greetings: "Dear Customer" or "Dear User" instead of your actual name. Legitimate services know who you are. They use your name.
  • Requests for Credentials: No legitimate organisation will ever ask you to "verify" your password via email. If you receive such a request, it's phishing. Always.
  • Unusual Payment Instructions: "We've changed our banking details" emails are almost always fraudulent, even if they appear to come from known suppliers. Always verify banking changes via phone call to a known number, not a number provided in the email.

Building a Reporting Culture

The best defence is a culture where it's not just okay, but actively encouraged, to ask "Is this real?" before clicking or acting. Staff who fear punishment for "asking stupid questions" stay silent. Silent staff fall for phishing.

Create a simple reporting mechanism. At minimum: "If something feels off, forward it to IT before clicking anything." Even better: implement a "Report Phishing" button in your email client that alerts the security team automatically.

When someone reports a suspicious email, even if it turns out to be legitimate, praise them publicly. Celebrate the cautious behaviour you want to see. Make security awareness a team achievement, not an individual burden.

Simulated Phishing Campaigns

We recommend running simulated phishing campaigns. Not to punish staff, but to give them a safe environment to fail and learn. Getting caught by a fake phishing test is embarrassing but harmless. Getting caught by a real attack isn't.

After each simulation, run brief training for those who clicked. Focus on the specific technique that fooled them. Over time, your organisation develops collective immunity to common tactics.

What to Do If You Clicked

Speed is everything. Don't hide it. Don't hope nobody notices. Don't try to fix it yourself.

Reporting immediately allows IT to reset passwords, revoke active sessions, and check for damage before data is stolen or ransomware spreads. The difference between "Sarah clicked a link" and "We've lost all our client data" is often just minutes.

Shame causes silence, and silence causes breaches. If someone admits they clicked something suspicious, thank them for telling you quickly. Their honesty might have just saved the business. If you want help building this culture, our cybersecurity service includes staff awareness training and simulated phishing campaigns.