Phishing Recognition & Response: Employee Security Training
Employees who can recognise phishing attempts and know how to respond are a genuine security asset. This guide covers what to look for in phishing emails, how to build a culture of reporting, and what to do when an attack gets through.
AMVIA Team
Editorial
Why does employee training matter for phishing defence?
Technical controls catch most phishing, but never all of it. The final line of defence is the person reading the email. An employee who pauses, checks the sender, and reports a suspicious message closes the gap no email gateway can fully cover.
This is not about blaming people for being deceived. Phishing is engineered by professionals to exploit urgency, authority, and routine. According to the UK Government's Cyber Security Breaches Survey 2025, 85% of businesses and 86% of charities that experienced a breach identified phishing as the cause. Training raises the odds that a malicious email is caught before it does harm, and it cuts the impact when one gets through. It works best alongside layered controls such as phishing protection and Microsoft Defender for Business.
What are the warning signs of a phishing email?
Most phishing emails share a small set of tells. Train staff to check five things on any unexpected message: the real sender address, the tone of urgency, the nature of the request, where the links actually point, and whether an attachment was expected. Any one of these warrants a closer look.
| Indicator | What to check | Red flag |
|---|---|---|
| Sender address | The actual address, not the display name | `refund@hmrc-gov-uk.com` posing as HMRC; lookalike domains like amvla.co.uk |
| Urgency | Pressure to act now | "Account suspended in 24 hours", "immediate action required" |
| Request type | What is being asked for | Credentials, bank-detail changes, payments outside normal process |
| Links | Hover to reveal the true URL | Display text says microsoft.com but the link points elsewhere; shortened bit.ly URLs |
| Attachments | Whether you expected the file | Macro-enabled Office docs,.zip/.7z archives, "enable editing to view" prompts |
Sender address and lookalike domains
The display name on an email can be set to anything. The real address, visible by clicking or hovering on the sender, reveals the true origin. A display name of "HMRC Refunds" sitting on `refund@hmrc-gov-uk.com` is plainly fraudulent. Lookalike domains, such as amvla.co.uk instead of amvia.co.uk, are subtler but spottable if you slow down and read.
Urgency, unusual requests, and payment changes
Phishing manufactures urgency to override careful thinking. Legitimate organisations rarely demand action without time to verify. Treat any email requesting credentials, personal data, a payment outside the normal process, or a change to bank details with scepticism, no matter who it appears to come from. The NCSC's guidance on phishing attacks makes the same point: criminals impersonate senior staff and known suppliers to make fraudulent requests feel routine. The correct response to any unexpected financial instruction is telephone verification on a number you already hold.
How do you build a reporting culture?
The single most valuable trait for phishing resilience is a culture where people report suspicious emails without fear of looking foolish. An employee who quietly deletes a phishing email removes the chance for IT to investigate, warn colleagues, and stop a wider attack. Make reporting effortless and judgment-free.
Two things drive this. First, leadership must model the behaviour, openly sharing when they have received and reported a suspicious message. Second, reporting must be one click. A report button in Outlook, available through Microsoft Defender, sends the email straight to your security team for analysis. When reporting is frictionless and praised rather than punished, volume goes up and your real-world detection improves.
Do simulated phishing exercises actually work?
Yes. Simulated phishing, sending controlled fake attacks to test staff, is the most effective single training method because it teaches in the moment. An employee who clicks a simulation gets immediate, contextual feedback explaining exactly what they missed, which sticks far better than an annual awareness slide deck.
Calibrate simulations to be challenging but not demoralising. The aim is learning, not a pass-or-fail test. A few guidelines AMVIA applies in practice:
- An initial click rate of 20–35% is normal for organisations with no prior training.
- Click rates above 30–40% signal a need for foundational training before harder simulations.
- Most organisations see meaningful improvement within two to three cycles, and reach under 10% within six months.
- A sustained rate under 5% indicates strong, organisation-wide awareness.
The trend over time matters more than any single result. Track it, report it without naming individuals, and use the data to target follow-up training.
What should you do when an attack gets through?
When a link is clicked or credentials are entered, speed decides the outcome. Attackers often reach a compromised account within minutes. The priority is to cut access, reset credentials, and revoke active sessions before the attacker sets up forwarding rules or moves laterally. Have a written, rehearsed routine ready.
Train every employee to take these steps the moment they realise they have been caught:
- Stop using the affected device and disconnect it from the network if malware may be installed.
- Report to IT immediately through a non-email channel, in case email is compromised.
- Change the password for any account whose credentials may have been entered.
- Revoke active sessions; Microsoft 365 lets you sign out of all sessions from account security settings.
Your IT or security team should then review email logs for rogue forwarding rules, check for OAuth apps granted access to the mailbox, and assess whether a personal-data breach must be reported. Under UK GDPR, a notifiable breach must reach the ICO within 72 hours. This is where a defined incident response process and 24/7 security monitoring turn a panic into a procedure.
How Would Your Team Perform Against a Real Phishing Attack?
A simulated phishing exercise reveals your team's current awareness level and provides targeted training where it is needed most.
Frequently Asked Questions
A simulated phishing exercise sends controlled, realistic fake attacks to employees to test recognition and response. Anyone who clicks a link or enters credentials lands on an educational page explaining what made the email suspicious. Results go to management without naming individuals, and the programme repeats over time to track improvement.
An initial click rate of 20–35% is common for organisations without prior training. After about six months of regular simulation and training, most reduce that to under 10%, and a sustained rate under 5% signals strong awareness. The trend over time is far more meaningful than any single simulation result.
No. Punishing people for failing a simulation backfires, creating anxiety that suppresses reporting and engagement. A click should trigger immediate, educational feedback, not discipline. The goal is to help the employee recognise the pattern they fell for so they are more alert next time. Phishing is also the most disruptive breach type for the majority of UK businesses, per the Cyber Security Breaches Survey 2025, so engagement matters more than blame.
Call the requester on a telephone number from your own records, never a number supplied in the email. Do not use email to verify an email, because a compromised account will simply confirm the fraud. A short verification call is the most reliable way to separate a genuine urgent request from a business email compromise attack.
Vishing is voice phishing, a phone call designed to extract credentials, personal data, or authorisation. Common forms include fake IT support requesting remote access and fake bank fraud teams requesting account verification. Staff should never hand over credentials or remote access on an inbound call, however convincing it sounds. Hang up and call back on a known number.
Immediately. Attackers often access compromised accounts within minutes of obtaining credentials, so password changes and session revocation should happen the moment compromise is suspected. Every minute of delay raises the chance the attacker has set up forwarding rules, exfiltrated data, or escalated into connected systems. Speed of response is the decisive factor in limiting damage.
Related Reading
Email Phishing: Keeping Your Business Safe
Technical and procedural controls that reduce phishing risk across your organisation.
Password Protection & Authentication
How MFA limits the damage when credentials are stolen in a phishing attack.
Business Email Security
The complete approach to protecting business email from phishing, spoofing and malware.
Protect your business → Get Cybersecurity Assessment