
Awareness training fails because modern phishing is not suspicious. It is well written and correctly branded. What works instead is a small number of specific habits.
Security awareness training usually fails for a reason nobody says out loud: it tells people to spot suspicious emails, and modern phishing is not suspicious. It is well written, correctly branded, references a real supplier, and arrives at a plausible moment. Telling staff to look for bad spelling prepares them for an attack that stopped being common years ago.
What works better is replacing vigilance with habits — a small number of specific behaviours that hold up even when someone is busy, tired, or being deliberately hurried.
The habit that prevents the most expensive incident
If your organisation adopts one rule, make it this: any change to payment details, and any unexpected payment request, is verified by contacting the person on a number you already had. Not the number in the email. Not the number on the new invoice. A number from a previous contract, your own records, or the supplier's website.
Invoice fraud works because it requires no technical compromise. Someone emails an accounts inbox claiming bank details have changed, and payment goes to a criminal. It is one of the more costly incidents that hits small businesses, and it is entirely prevented by a phone call to a number the attacker does not control.
Write the rule down, apply it to everyone including the finance director, and make it explicit that no genuine supplier will object to being verified.
Urgency is the signal, not spelling
The reliable indicator across almost every social engineering attempt is manufactured time pressure combined with a request to bypass normal process. The payment must go today. The account will be suspended within hours. The senior person is in a meeting and cannot be called.
That combination is worth treating as the alarm in itself, independent of how the message looks. Legitimate business rarely requires that a control be skipped, and where it genuinely does, a two-minute delay to verify costs nothing.
Teach the pattern rather than the indicators. Indicators change; the pattern does not, because the pressure is what makes the attack work.
Credentials: three rules that cover most of it
Never enter a password on a page you reached by clicking a link
This is the practical version of "check the URL", which people cannot reliably do under time pressure and which increasingly fails against convincing lookalike domains.
The habit: if a message asks you to log in, do not use its link. Open the service the way you normally do — a bookmark, the app, or typing the address. If the request was genuine, whatever needed attention will be waiting for you there.
Unique passwords, held in a password manager
Reused passwords mean one breached service compromises several. A password manager makes uniqueness practical, and its autofill behaviour provides a quiet secondary benefit: it will not offer to fill your credentials on a lookalike domain, because the address does not match. That silence is a useful warning.
Treat a multi-factor prompt you did not trigger as an alert
An unexpected approval request means someone already has your password. The correct response is to deny it and report it immediately, not to dismiss it as a glitch. Attackers sometimes send repeated prompts hoping the target approves one out of irritation, so persistence is a stronger signal, not a weaker one.
Devices, wherever people are working
The practical rules are few. Lock the screen when leaving the desk, including at home if others have access. Keep updates on and install them rather than postponing them indefinitely. Do not install software from outside approved sources, particularly browser extensions, which frequently request permission to read everything on every page. Report a lost device immediately, because remote wipe is only useful before someone has explored it.
On public wi-fi, the risk is often overstated — most traffic is encrypted in transit now — but the sensible position is to use a VPN for work systems and avoid administrative tasks on a network you do not control. Making devices managed rather than personal is what makes all of this enforceable, and our IT support team handles that side.
Where company data is allowed to go
Most data loss in small businesses is not theft. It is convenience: a file emailed to a personal address to work on at home, a document uploaded to a free conversion site, customer details pasted into a consumer AI tool to draft a reply.
That last one has become common enough to name explicitly. Whether information pasted into a public tool is retained, and whether it may inform future outputs, depends on the product and its settings. If your organisation has not made a decision about this, staff will make their own, individually and silently.
The workable approach is to say clearly which tools are approved for work data, and to provide a sanctioned option for the thing people are trying to do. A prohibition without an alternative produces workarounds rather than compliance.
Reporting: the part that determines the outcome
Every organisation says staff should report mistakes. Fewer make it safe to do so, and the gap decides how bad an incident becomes.
Someone who clicks a link and reports it within ten minutes gives you a chance to reset credentials and check for access before anything happens. Someone who spends the afternoon hoping it was nothing hands the attacker uninterrupted time.
Three things make reporting reliable: a stated policy that reporting is never punished — and visible adherence to it the first time someone tests it; a single obvious way to report that takes seconds; and a thank-you rather than an interrogation. The organisation's response to the first honest report sets the pattern for every one afterwards.
What managers should do differently
Two things undermine staff training more than anything the staff do.
The first is senior people exempting themselves from controls, which teaches everyone that the rules are optional for those with the most access. The second is normalising the behaviour attackers imitate — urgent out-of-hours requests to move money quickly, sent by message. If that is how your organisation genuinely operates, an impersonation is indistinguishable from routine.
Establishing that payment requests always follow the same verified process, regardless of who is asking, removes the ambiguity attackers rely on. Writing that process down in a way people actually follow is part of what our IT consultancy team does.
Frequently asked questions
How often should we run training?
Short and regular beats an annual session that is endured and forgotten. A brief reminder attached to a real, recent example is more effective than an hour of general content once a year. Simulated phishing is useful for measurement, provided it is used to identify where support is needed rather than to embarrass people — punitive simulations reliably reduce reporting, which is the opposite of the goal.
Is it realistic to expect staff to spot every attack?
No, and designing around that expectation is a mistake. Assume some attempts will succeed and build controls that limit the consequences: multi-factor authentication, restricted access, standard rather than administrator accounts, and backups that are out of reach. Staff behaviour is one layer among several. The controls are covered in our small business cybersecurity checklist.
What should someone do the moment they realise they have been caught?
Report it immediately, then change the password for the affected account from a different device and check for unexpected mailbox rules or forwarding — attackers frequently set these up to hide their activity. Speed matters far more than certainty; report even if unsure.
Are password expiry policies useful?
Forced regular changes have fallen out of favour with security guidance, because they push people toward predictable variations of the same password. Length, uniqueness and multi-factor authentication are more effective. Change passwords when there is reason to believe one is compromised.
Can we just block risky websites instead?
Filtering helps and does not substitute for the habits above, because the highest-value attacks arrive as legitimate-looking email from real, uncompromised domains. Technical controls reduce volume; the verification habit handles what gets through.
The short list
If you distil this to what people will actually remember: verify payment changes by phone using a number you already had; never enter a password on a page you reached by clicking a link; treat unexpected multi-factor prompts as an alert; and report mistakes immediately, knowing you will be thanked.
Four habits, none requiring technical knowledge, covering the majority of what actually happens. Our web security team helps businesses put both the training and the underlying controls in place. Get in touch if you would like a hand.



