Awareness
Phishing awareness and simulation: your first firewall
Training teams and testing them without humiliating anyone, measuring progress rather than failure, and accounting for what AI has changed.
Key points
- An informed employee is not a perfect barrier, but it is the cheapest one to install.
- Punitive simulation produces concealment: people stop reporting, they do not stop clicking.
- The useful metric is the reporting rate, not the click rate.
- AI has made phishing undetectable by eye: the countermeasure becomes procedural.
Why technical controls alone no longer suffice
Because the messages that get through filters are precisely those with no technical signal: no attachment, no known malicious link, a legitimate address because it was compromised. They request a transfer, a change of banking details, an urgent approval. No filter can decide on the person's behalf.
That shift accelerated with text generation tools. Spelling mistakes and awkward phrasing (the cues people were taught to rely on)have disappeared. A fraudulent message today is better written than the average internal email.
Voice and face cloning add another step. An urgent request confirmed "by phone" in a recognizable voice no longer proves anything.
The consequence is that the countermeasure moves from detection to procedure. You no longer ask people to recognize a fake; you ask them to verify by another route.
How do you test without breaking trust?
By announcing that campaigns will happen, without saying when. By never naming publicly the people who click. And by making reporting (not the absence of clicks)the metric that counts. A punitive campaign produces better numbers and a less secure organization.
The mechanism is easy to understand. If clicking invites a reprimand, the person who clicks says nothing. They will also say nothing the day the message is real, and that is precisely the day minutes matter.
- Announce the principle, not the schedule. Teams know simulations happen. Nobody feels trapped, and the reflex takes hold.
- Never name publicly. Results are presented by group, never by individual. Individual follow-up happens discreetly.
- Measure reporting. An organization where 40% of people report a suspicious message is safer than one where 5% click but nobody speaks up.
- Increase difficulty gradually. Starting with crude messages teaches nothing. The level rises as the reflex settles.
What does the programme contain?
A short initial training session, progressive simulated campaigns, quarterly measurement of reporting, and an out-of-band verification procedure for financial requests. That last point is what actually stops executive-impersonation fraud.
- Initial training. Short, concrete, adapted to the role. Accounting and production are not exposed to the same scenarios.
- The campaigns. Progressive, non-punitive, with an immediate educational page for anyone who clicks, not a warning.
- Measurement. Reporting rate, average time to report, and progression by group. Click rate is tracked but is not the objective.
- Out-of-band verification. A written rule: any transfer request or change of banking details is confirmed through a separate channel, on a number known in advance. Never by replying to the message.
What Law 25 expects regarding awareness
The law requires security measures proportionate to the sensitivity of the information held, and staff training is part of that. It does not prescribe a format: what matters is being able to demonstrate that the people handling personal information have been informed of their obligations.
In practice that demonstration rests on three items: dated training material, a record of who completed it, and a policy describing expected behaviour.
Those items serve elsewhere too. Insurance questionnaires and supplier questionnaires almost all contain a question on awareness, and a documented answer is reused directly.
That is one more reason to keep the record: the same effort answers three separate demands.
Frequently asked questions
Not if they are designed properly, and that is a condition we set. No individual result is circulated, whoever clicks lands on an educational page rather than a warning, and statistics are presented by group. A campaign experienced as a trap produces better numbers and a less secure organization, because it teaches people to stay quiet.
Regularly rather than intensively. A single annual campaign produces a spike of attention that fades within weeks; a lighter but continuous rhythm builds a reflex. The exact frequency depends on your staff turnover and your exposure: we adjust it with you rather than imposing it.
Through the reporting rate and its delay, not the click rate. A fast report lets you block a sender, warn other recipients and cut a live campaign short, that is a measurable gain. Click rate never reaches zero, and making it the objective leads to designing campaigns that are too easy.
For simulated campaigns, yes, and several products do it well. But the tool is not the point: what determines the outcome is how campaigns are designed and how results are presented. We resell no licences, and we work with the tool you already own when it does the job.
That is the scenario you prepare for. What matters then is speed: report it, change the affected password, check the mailbox's forwarding rules, and look at whether any access was used. Those steps must be written in advance and known: improvising at that moment costs the minutes that count.
Sources
- Canadian Centre for Cyber Security: phishing · indicators, scenarios and recommended measures
- Commission d'accès à l'information du Québec · requirement for proportionate security measures, including training
- Canadian Anti-Fraud Centre · fraud typologies, including executive impersonation
Is your infrastructure ready for the next threat?
An initial assessment, free and without commitment, to evaluate your security posture.