Phishing attacks have been around since the mid-1990s. They're still the most successful initial attack vector for breaches worldwide. Not because people are careless — because attackers have gotten extremely good at making fake emails look real.
The Anti-Phishing Working Group tracks hundreds of thousands of unique phishing attacks per month. Google's Transparency Report shows millions of phishing sites detected every week. This isn't a niche threat — it's the dominant one.
Training your team to recognise phishing isn't optional if you have any data worth protecting.
What Modern Phishing Actually Looks Like
"Don't click links from strangers" was useful advice in 2005. Modern phishing is considerably more sophisticated.
Spear phishing targets specific individuals using researched, personalised content. An attacker might impersonate your CEO, your bank, a key supplier, or a government agency — using real names, correct job titles, and contextually appropriate requests. These emails pass most spam filters because they're not bulk-sent.
Business Email Compromise (BEC) involves either compromising a real email account or spoofing a trusted sender's domain. A BEC attack might look like your CFO asking your accounts team to urgently transfer funds to a new supplier account. The FBI's IC3 report identifies BEC as the highest-cost cybercrime category, with losses in the billions annually.
Smishing (SMS phishing) and vishing (voice phishing) follow the same principles but use text messages and phone calls. These bypass email security controls entirely.
What Your Training Should Cover
How to inspect a sender's actual email address. The display name can say anything — "Microsoft Support" or "Your CEO" — but the actual sending address often reveals the deception. Train people to click through and check.
URL inspection before clicking. Hovering over a link shows the destination. A link that displays as "nzta.govt.nz" but points to "nzta-renewal-portal.xyz" is a phishing link. This one skill prevents a significant proportion of successful attacks.
Urgency and pressure as red flags. Phishing emails almost universally create artificial urgency: "Your account will be suspended," "Immediate action required," "Wire transfer must be completed today." Teach your team that urgency is a manipulation tactic, not a reason to bypass normal verification steps.
What to do when unsure. This is the most underteached element. Most people who suspect an email is suspicious do nothing — they don't want to look foolish if it turns out to be legitimate. Your training needs to normalise reporting: "When in doubt, forward it to [IT contact] before you do anything else."
How attackers use context. During tax season, expect tax-themed phishing. During software renewals, expect software vendor impersonation. Attackers read the news and tailor campaigns accordingly. Seasonal threat awareness is part of good training.
How to Make the Training Actually Work
The research on security awareness training is clear on one point: one-off annual training has minimal lasting effect on behaviour. Security awareness experts consistently find that short, frequent training significantly outperforms long, infrequent sessions.
The practical format that works:
- Short modules (10-15 minutes) covering one topic each
- Realistic scenarios using examples that look like your actual business context
- Knowledge checks at the end of each module — not to catch people out, but to surface gaps
- Regular refreshers — at least quarterly, and when new threat campaigns are active
Simulated phishing tests — sending fake phishing emails to your own staff — are one of the most effective tools for identifying who needs additional training and for driving real behaviour change. An employee phishing test works by delivering a realistic fake email (an IRD refund lure, an NZ Post delivery failure, a Microsoft 365 password alert) directly to staff inboxes and tracking who clicks, who submits credentials, and who reports it.
Used well, phishing tests identify your highest-risk staff before an attacker does. Used poorly — with public shaming or no follow-up training — they create distrust without changing behaviour. The rules that make them work: follow every failed test with immediate just-in-time training, share results at aggregate level not by name, and run them quarterly not once. For the full guide to running an employee phishing test that changes behaviour, see phishing tests for employees: how to run one.
Free phishing awareness quizzes like the Google Jigsaw phishing quiz are useful for self-service awareness building but do not replace in-inbox simulation. A staff member who scores well on a phishing quiz may still click a well-crafted IRD-themed email in a busy inbox. In-inbox simulation under real conditions is what the research shows drives click rate reduction.
SecureAZ's phishing awareness module covers all of the above in a format your team can complete in under 15 minutes — with a quiz, completion certificate, reminder system, and optional simulated phishing so you know who's done it and how they perform under test conditions.