Staff training and phishing
Short sessions and simulated phishing, because most breaches start with a click, not with a firewall.
A fake supplier invoice with a changed IBAN passes every firewall, because it is an ordinary message. It is stopped by a person who checks the sender address and calls the number from the contract rather than the number in the message.
Lecture, workshop or simulation
One big lecture a year ticks the formal box, but most of it is forgotten by the following month. The examples tend to be generic and look nothing like the mail staff actually receive.
Short one hour workshops for small groups hold attention and leave room for questions. They are worth the most when they are built on real messages the company has received.
Simulated phishing messages show how people behave when they do not know they are being tested. On their own they teach little, but they show where more explaining is needed.
What we recommend and why
A combination of workshop and simulation. The workshop first, a test campaign a few weeks later, then a short review of results by department, with no names. Anyone who clicks a test message immediately sees a page explaining what they should have noticed, because that is when the lesson sticks best.
The workshop deals with what actually gets past the filters:
- messages posing as the director asking for an urgent payment or gift cards
- fake Microsoft 365 sign in pages that look like the real thing
- requests to approve a two factor sign in the user did not start
Most important of all, reporting a suspicious message is never punished. An employee who admits to clicking is worth more than one who keeps quiet.
Fitting it to who does the work
In tourism part of the staff is new every season, and reception gets messages from strangers all day long. For them we prepare a shorter version focused on messages posing as booking platforms and guests with an attachment or a link, because that is a common lure precisely during the season.
In a smaller company the workshop can be a single session for everyone. What matters is that the people who approve payments are in the room, because they are exactly who the urgent payment messages are aimed at.
Common questions
Will staff know they are being tested?
They know in advance that test messages will arrive over a certain period, but not when or what they will look like. Results are shown by department, not by name.
What happens to the data from the simulation?
Management approves the campaign, staff are told in advance, and the only things recorded are whether a message was opened and whether it was clicked. Anything typed into the test page, passwords included, is not stored.
How much does the training cost?
It depends on the number of employees, the number of sessions and whether a test campaign goes with the workshop. We put a quote together after a short conversation about how many of you there are and how you work.