All Guides
Email Security

Phishing Prevention and Staff Training

Around 90 percent of attacks start with phishing. This guide covers every type, the red flags, technical controls, training that actually works, simulated campaigns, and how to build a reporting culture.

Last reviewed August 2026

Why Phishing Still Works

Technical controls have improved, but attackers evolved. Modern phishing uses lookalike domains, real stolen email threads, AI-generated copy, and adversary-in-the-middle proxies that defeat standard MFA. Staff click because the emails look exactly like the real thing.

~90%

of breaches start with phishing

1 in 5

staff click in unprotected environments

70%

fewer successful attacks with monthly simulation

Types of Phishing

Mass email phishing

Untargeted. Low quality, sent to millions. Basic filters catch most of it.

Spear phishing

Targeted at a specific person with research. Named, contextual, much harder to spot.

Whaling

Targets executives. CFO, CEO, general counsel. High-value and usually well-researched.

Business Email Compromise (BEC)

Attacker takes over a legitimate account and uses it. Email looks real because it is real.

Invoice fraud / payment redirection

Fake supplier invoice with new bank details. Targets accounts payable. Costs Australian businesses millions annually.

Smishing / Vishing

SMS or voice phishing. Fake delivery, MyGov, ATO, bank fraud alerts.

AiTM / credential proxy phishing

Reverse-proxy the real login page. Capture credentials, MFA codes, and session cookies in real time.

Red Flags to Train Into Staff

Sender address does not match the claimed organisation
Urgency or consequence pressure (act now, account suspended)
Request for credentials, MFA code, or payment
Generic greeting (Hello, Dear Customer)
Mismatched or shortened links
Poor grammar or unusual phrasing
Unexpected attachments (zip, html, iso, macro-enabled Office)
Reply-to address different from display name
First-time sender from external domain
Request to change bank details for a supplier

Technical Defences That Actually Work

Email authentication

SPF, DKIM, DMARC at p=reject. Stops domain spoofing. See our Email Auth guide.

Related guide

Advanced anti-phishing

M365 Defender for Office 365, Google Workspace security, or Abnormal Security. AI-based anomaly detection.

Phishing-resistant MFA

FIDO2 and passkeys for admins. Blocks AiTM cookie theft.

Related guide

Safe Links / URL rewriting

Real-time check on every link click. Blocks pages weaponised after delivery.

DNS filtering

Blocks lookups to newly registered and known-malicious domains at the network level.

Related guide

Banner warnings

Clear banner on every external email. "This message came from outside the organisation."

Training Program That Sticks

Annual tick-box training does not work. Short, frequent, specific training does.

New starter induction

15 minutes on day one. Phishing recognition, reporting, what to do if unsure.

Monthly micro-learning

Short 3-5 minute modules. Tied to current threat trends.

Quarterly simulated campaigns

Measure click and report rates. Feedback to those who fail.

Role-specific training

Finance: invoice fraud. Exec: whaling and CEO impersonation. IT: helpdesk social engineering.

Executive awareness

Whalers research LinkedIn, press releases, and annual reports. Executives need specific training.

Post-incident lessons

When a real phish lands, share (anonymised) what happened across the business.

Running Simulated Campaigns

Simulated phishing sends controlled fake phish to staff to test recognition. Done right, it builds awareness. Done wrong, it breeds resentment.

Do

  • Start with realistic but not-cruel lures
  • Increase difficulty gradually
  • Provide immediate positive feedback for clicks
  • Track click rate AND report rate (report rate matters more)
  • Celebrate people who report

Do not

  • Use cruel lures (bonuses, redundancies, personal loss)
  • Publicly shame staff who fail
  • Tie results to performance reviews
  • Send during major events or crises
  • Forget to inform HR and legal before launch

Building a Reporting Culture

The single best indicator of security maturity is how fast staff report suspicious emails. Speed depends on culture.

Reward reports, never punish clicks

If people are punished for mistakes, they hide them. Report rate collapses.

Make reporting one click

Report Phish button in Outlook / Gmail. No forms, no procedures.

Acknowledge every report

Automated thank-you, then a personal follow-up for confirmed threats.

Share wins

"This week, 14 staff reported a real phishing attempt. Blocked before damage." Normalise reporting.

Measure and improve

Target 20%+ report rate on simulations. High report rate is the goal, not zero clicks.

BEC and Invoice Fraud

Business Email Compromise is the most expensive phishing outcome for Australian businesses. Attackers sit inside a mailbox for weeks, learn payment processes, then redirect an invoice. ACCC Scamwatch reports BEC losses in the hundreds of millions annually.

Controls that specifically block BEC:

  • Phone-verify any bank detail change for suppliers, using a number you already hold
  • Dual approval for payments above a threshold
  • Never approve payment changes requested by email alone
  • Phishing-resistant MFA on all mailbox access
  • Monitor for suspicious inbox rules (auto-forwarding, delete rules)
  • Impossible travel alerts in Entra ID

Common Mistakes

Annual training only

Staff forget within weeks. Monthly micro-training is the minimum effective dose.

Shaming staff who click

Kills reporting culture. People hide mistakes instead of reporting them.

No technical controls, only training

Training is layer two. Without DMARC, anti-phish, and MFA, training carries too much weight.

Weak offboarding

Attackers use ex-staff credentials. Revoke mailbox, session tokens, and MFA at termination, not next week.

Executives exempt from training

They are the highest-value targets. They need more training, not less.

Build a Phishing-Resistant Culture

We run managed phishing simulation campaigns, staff training, and deploy M365 / Google anti-phishing technical controls end to end.