Why Phishing Still Works
Technical controls have improved, but attackers evolved. Modern phishing uses lookalike domains, real stolen email threads, AI-generated copy, and adversary-in-the-middle proxies that defeat standard MFA. Staff click because the emails look exactly like the real thing.
~90%
of breaches start with phishing
1 in 5
staff click in unprotected environments
70%
fewer successful attacks with monthly simulation
Types of Phishing
Mass email phishing
Untargeted. Low quality, sent to millions. Basic filters catch most of it.
Spear phishing
Targeted at a specific person with research. Named, contextual, much harder to spot.
Whaling
Targets executives. CFO, CEO, general counsel. High-value and usually well-researched.
Business Email Compromise (BEC)
Attacker takes over a legitimate account and uses it. Email looks real because it is real.
Invoice fraud / payment redirection
Fake supplier invoice with new bank details. Targets accounts payable. Costs Australian businesses millions annually.
Smishing / Vishing
SMS or voice phishing. Fake delivery, MyGov, ATO, bank fraud alerts.
AiTM / credential proxy phishing
Reverse-proxy the real login page. Capture credentials, MFA codes, and session cookies in real time.
Red Flags to Train Into Staff
Technical Defences That Actually Work
Email authentication
SPF, DKIM, DMARC at p=reject. Stops domain spoofing. See our Email Auth guide.
Related guideAdvanced anti-phishing
M365 Defender for Office 365, Google Workspace security, or Abnormal Security. AI-based anomaly detection.
Safe Links / URL rewriting
Real-time check on every link click. Blocks pages weaponised after delivery.
DNS filtering
Blocks lookups to newly registered and known-malicious domains at the network level.
Related guideBanner warnings
Clear banner on every external email. "This message came from outside the organisation."
Training Program That Sticks
Annual tick-box training does not work. Short, frequent, specific training does.
New starter induction
15 minutes on day one. Phishing recognition, reporting, what to do if unsure.
Monthly micro-learning
Short 3-5 minute modules. Tied to current threat trends.
Quarterly simulated campaigns
Measure click and report rates. Feedback to those who fail.
Role-specific training
Finance: invoice fraud. Exec: whaling and CEO impersonation. IT: helpdesk social engineering.
Executive awareness
Whalers research LinkedIn, press releases, and annual reports. Executives need specific training.
Post-incident lessons
When a real phish lands, share (anonymised) what happened across the business.
Running Simulated Campaigns
Simulated phishing sends controlled fake phish to staff to test recognition. Done right, it builds awareness. Done wrong, it breeds resentment.
Do
- Start with realistic but not-cruel lures
- Increase difficulty gradually
- Provide immediate positive feedback for clicks
- Track click rate AND report rate (report rate matters more)
- Celebrate people who report
Do not
- Use cruel lures (bonuses, redundancies, personal loss)
- Publicly shame staff who fail
- Tie results to performance reviews
- Send during major events or crises
- Forget to inform HR and legal before launch
Building a Reporting Culture
The single best indicator of security maturity is how fast staff report suspicious emails. Speed depends on culture.
Reward reports, never punish clicks
If people are punished for mistakes, they hide them. Report rate collapses.
Make reporting one click
Report Phish button in Outlook / Gmail. No forms, no procedures.
Acknowledge every report
Automated thank-you, then a personal follow-up for confirmed threats.
Share wins
"This week, 14 staff reported a real phishing attempt. Blocked before damage." Normalise reporting.
Measure and improve
Target 20%+ report rate on simulations. High report rate is the goal, not zero clicks.
BEC and Invoice Fraud
Business Email Compromise is the most expensive phishing outcome for Australian businesses. Attackers sit inside a mailbox for weeks, learn payment processes, then redirect an invoice. ACCC Scamwatch reports BEC losses in the hundreds of millions annually.
Controls that specifically block BEC:
- Phone-verify any bank detail change for suppliers, using a number you already hold
- Dual approval for payments above a threshold
- Never approve payment changes requested by email alone
- Phishing-resistant MFA on all mailbox access
- Monitor for suspicious inbox rules (auto-forwarding, delete rules)
- Impossible travel alerts in Entra ID
Common Mistakes
Annual training only
Staff forget within weeks. Monthly micro-training is the minimum effective dose.
Shaming staff who click
Kills reporting culture. People hide mistakes instead of reporting them.
No technical controls, only training
Training is layer two. Without DMARC, anti-phish, and MFA, training carries too much weight.
Weak offboarding
Attackers use ex-staff credentials. Revoke mailbox, session tokens, and MFA at termination, not next week.
Executives exempt from training
They are the highest-value targets. They need more training, not less.
Build a Phishing-Resistant Culture
We run managed phishing simulation campaigns, staff training, and deploy M365 / Google anti-phishing technical controls end to end.

Remote Support