Phishing Awareness: How to Train Your Teams Without Pissing Them Off



Phishing awareness training is designed to reduce human errors when dealing with fraudulent emails, text messages, QR codes, or phone calls, but it fails when it feels like a punishment. A good program combines realistic simulations, brief explanations, a reporting button, clear metrics, and the right to make mistakes. For an SME, plan on a few weeks of planning, followed by quarterly campaigns rather than a single large annual training session that’s forgotten three days later.


Phishing Awareness: How to Train Your Teams Without Pissing Them Off

Phishing Awareness: What Really Changes for an SME

Phishing involves tricking someone into clicking a link, revealing a password, paying a fake invoice, or installing malware. The issue is therefore not just an IT matter. It affects the treasury, business continuity, brand reputation, and sometimes even the liability of company executives.

A credible campaign no longer needs to rely on blatant mistakes. AI-generated emails, fake delivery notifications, HR follow-ups, and malicious QR codes make attacks more sophisticated, faster, and harder to detect. To understand this trend, here’s an overview of the Convincing fraudulent emails generated using AI usefully complements a training program.

The primary benefit of a well-executed phishing awareness program is not to turn every employee into a security expert. It is to instill a simple reflex: slow down, verify, report. An employee who has doubts and reports the information within thirty seconds protects the company better than an employee who is afraid of being judged and silently deletes the message.

The budget depends on the size of the team, existing tools, and the level of support required. In France, for an SME, a serious initial effort can start at around a few thousand euros per year if it builds on an existing Microsoft 365 deployment, and can increase further with a specialized platform, business-specific workshops, and managerial oversight. With this budget, it’s better to invest in fewer but more targeted training modules.

How can you train your employees to recognize phishing attempts without alienating them?

Former without infantilizing people requires starting from a simple principle: collaborators are not the weak link; they are a line of detection. This nuance changes everything. Training that humiliates those who clicked leads to concealment; training that explains the mechanism leads to reporting.

NIST, the leading U.S. authority on cyber security, recommends in its 2024 publication SP 800-50r1 that simulations be used as learning opportunities, that clicks and reports be tracked, and that capabilities such as “report phishing” be added , and to avoid punitive measures or “name and shame” tactics. In other words: we measure to improve, not to rank the worst performers.

A good training session starts with real-life scenarios that are close to everyday situations: a fake supplier invoice, a fake Microsoft 365 message, an urgent request from a manager, a QR code in an email, or a delivery text message. Only then do we move on to the rules. The ordre approach works because employees retain information better when they recognize it.

  • Announce that drills may take place at any time, without specifying exact dates.
  • Explain the goal: to learn how to detect and report, not to set traps.
  • Include a button or a simple way to report issues, ideally within the messaging app.
  • Respond to reports, even briefly, to show that they are useful.
  • Discuss trends by team or by scenario, but never mention names in meetings.
Read also  How to use Google Suggest to optimize your business

In the projects we’re working on, we often encounter a very real obstacle: the company launches a simulation before deciding how to handle the reports. As a result, employees go through the motions once, then lose interest. The feedback loop is just as important as the exercise itself.

Do phishing simulations really work?

Yes, but not the way it’s sometimes marketed. Phishing simulations—that is, fake messages that look dangerous but are harmless—can improve reflexes if they are repeated, contextualized, and followed by a brief training session. A 2019 JAMA Network Open study conducted at six U.S. healthcare institutions, involving 95 campaigns and nearly 2.97 million emails, found an overall click-through rate of 14.2 %.

The same study linked repeated campaigns to a decrease in the likelihood of clicking: an adjusted odds ratio of 0.511 for 6 to 10 campaigns, then 0.335 for more than 10 campaigns, compared to 1 to 5 campaigns. It’s not a magic wand. But structured repetition seems to help.

Other studies take a more cautious approach. A study published in 2025 on arXiv, “Anti-Phishing Training (Still) Does Not Work,” found no significant main effect of training interventions on click-through or reporting rates, with p-values of 0.450 and 0.417. It also highlighted that the difficulty of the phishing lure strongly predicted the response: click rates rose from 7.0% on easy lures to 15.0% on difficult ones.

The reasonable interpretation is this: a standalone simulation primarily measures the quality of the scenario. An ongoing program gradually shapes a culture. Honestly, a mandatory one-hour annual training session—without any practical application or a reporting button—is only justified as a way to check a compliance box.

Measuring More Than Just the Click-Through Rate

The click-through rate stands out because it’s simple. Too simple. If you look only at this number, you risk penalizing a team facing a very plausible scenario and praising another that received a ridiculous email.

In 2023, NIST published the Phish Scale guide, a method that assesses how difficult it is to detect a message based on its visible clues and how well it aligns with the context of the target audience. A fake health insurance email sent right after an internal HR campaign is not as difficult to detect as a generic lottery message. Comparing the two makes no sense.

Microsoft Defender for Office 365 Attack Simulation Training, documented in 2026, follows this approach with realistic but harmless simulations, tracking metrics such as opening, deletion, credential entry, reporting, and completion of for simulations. The tool also accounts for QR code phishing payloads, which is useful when attacks go beyond simple email attachments.

Indicator What it measures Limit to be aware of Recommended Use
Click-through rate Percentage of recipients who clicked It depends entirely on the difficulty of the lure To be tracked by trend, not as an individual rating
Reporting Rate Percentage of recipients who reported the message Low if the reporting channel is unclear Culture Safety Indicator prior
Entering Login Credentials The Transition from Click to Risky Action Sensitive—handle with care HR Initiate immediate microlearning
Reporting Deadline Time until first internal alert Varies by region and industry Useful for estimating the reaction rate
Phish Scale Difficulty Scenario Detection Level It requires a bit of organization Compare Similar Campaigns
Read also  How to create an effective showcase website?

The bord dashboard fits on a single page. It shows trends in clicks, reports, login credentials, and response times, along with the difficulty level of the campaigns. A department understands where to focus its efforts: training, email configuration, multi-factor authentication, and payment validation processes.

Budget, Timelines, and Planning a Realistic Program

For an SME with 20 to 200 employees, a realistic timeline isn’t long, but it must be well-defined. Allow two to four weeks to define the target audiences, scenarios, internal messages, reporting channels, and metrics. The first campaign can then be launched quickly, provided that the messaging and security policies are in place.

The cost varies widely. If Microsoft 365 E5 or Defender for Office 365 Plan 2 is already included in the scope, the cost depends mainly on configuration, governance, and content. With a specialized platform such as Proofpoint, KnowBe4, or SoSafe, the budget often includes licenses, templates, training modules, and support. Depending on the provider, an SME may find offers starting at a few euros per user per month, sometimes with initial support included.

The common pitfall for non-technical users: launching a fake phishing campaign without checking deliverability rules. SPF, DKIM, and DMARC are mechanisms that help servers to authenticate emails. If configured incorrectly, they can skew results or degrade the performance of the actual email system. On a website or in an application, the same technical security best practices apply to the risks described in the Cybersecurity Fundamentals.

Another decision to make: Should we target the entire company or only the exposed functions? To start, the entire company needs to understand the basics. Next, the scenarios should be tailored: accounting for fake bank details, HR for job application attachments, management for CEO fraud, and customer support for incoming links.

What Education Will Never Replace

Phishing awareness campaigns cannot compensate for a weak security architecture. If all accounts use weak passwords, if multi-factor authentication isn’t enabled, and if administrator privileges are granted too broadly, a single click may be all it takes. Phishing awareness training limits the risk; it does not eliminate it.

Technical defenses remain essential: email filtering, sandboxing (isolated analysis of attachments), MFA, tested backups, access segmentation, and connection logging. For a website or business platform, this approach also extends to protection against data breaches on a website and the security of application interfaces, particularly the mobile API vulnerabilities.

Read also  Capturing a full screenshot of a web page: a simple guide for PC and smartphone

In 2024, Proofpoint reported that its “State of the Phish” report was based on 183 million simulated attacks and 2.8 trillion emails analyzed over a 12-month period. The same report noted that 71.1% of employees surveyed admitted to engaging in risky behavior, and that 96.1% of them were aware of the risks. The problem, therefore, is not just a matter of awareness. It also involves pressure, urgency, habit, and the design of internal processes.

From an agency’s perspective, the natural instinct is to link awareness efforts to real-world workflows: confirming a wire transfer, resetting a password, inviting users to a SaaS tool, or accessing an administration console. When the business process is unclear, phishing exploits that gap.

Building a Culture of Reporting, Not Fear

The right question is simple: What happens when someone clicks? If the answer is “we call them in,” you’ll have less transparency. If the answer is “we isolate it, verify it, and explain it,” you’ll have a faster or organization.

A well-designed program accounts for human error. It includes a clear procedure: flag the message, notify IT or the service provider, change the password if necessary, verify the connections, and inform the people involved. The RGPD, which has been in effect since 2018, also requires that incidents involving personal data be taken seriously, with notification to the CNIL in certain cases of a breach.

Training can be kept brief. Three- to five-minute micro-training sessions, sent after a simulation or as part of a quarterly refresher, are often better received than a long, generic module. The content should explain why the message was credible, what clues were present, and what to do next time.

Defining the scope of this type of project early on helps avoid most unpleasant surprises: choosing scenarios, HR policies, metrics, and integration with Microsoft 365, OVH, Cloudflare, or existing tools. An outside perspective is especially helpful in distinguishing between pedagogical, technical, and organizational aspects.

FAQ on Phishing Awareness

How often should a phishing awareness campaign be conducted?

For an SME, one campaign per quarter is a good starting point, with brief reminders between campaigns. High-risk groups, such as those in finance or government, may receive more frequent campaigns.

Should employees be notified before a phishing simulation?

Yes, it is necessary to announce that exercises may take place, without specifying the dates or scenarios. This transparency reduces the feeling of being set up and is consistent with NIST’s non-punitive recommendations.

What is a good click-through rate for simulated phishing?

There is no universal rate, because the difficulty of the message makes all the difference. It’s best to follow the trend, compare scenarios of similar difficulty, and also look at the reporting rate.

Is a phishing training course enough to keep you safe?

No. It must be combined with multi-factor authentication, email filtering, backups, access control, and clear approval procedures for payments or sensitive access.

English