Cybersecurity

Phishing Recognition & Response: Employee Security Training

Employees who can recognise phishing attempts and know how to respond are a genuine security asset. This guide covers what to look for in phishing emails, how to build a culture of reporting, and what to do when an attack gets through.

AT

AMVIA Team

Editorial

7 min read·Mar 2026

Why does employee training matter for phishing defence?

Technical controls catch most phishing, but never all of it. The final line of defence is the person reading the email. An employee who pauses, checks the sender, and reports a suspicious message closes the gap no email gateway can fully cover.

This is not about blaming people for being deceived. Phishing is engineered by professionals to exploit urgency, authority, and routine. According to the UK Government's Cyber Security Breaches Survey 2025, 85% of businesses and 86% of charities that experienced a breach identified phishing as the cause. Training raises the odds that a malicious email is caught before it does harm, and it cuts the impact when one gets through. It works best alongside layered controls such as phishing protection and Microsoft Defender for Business.

What are the warning signs of a phishing email?

Most phishing emails share a small set of tells. Train staff to check five things on any unexpected message: the real sender address, the tone of urgency, the nature of the request, where the links actually point, and whether an attachment was expected. Any one of these warrants a closer look.

IndicatorWhat to checkRed flag
Sender addressThe actual address, not the display name`refund@hmrc-gov-uk.com` posing as HMRC; lookalike domains like amvla.co.uk
UrgencyPressure to act now"Account suspended in 24 hours", "immediate action required"
Request typeWhat is being asked forCredentials, bank-detail changes, payments outside normal process
LinksHover to reveal the true URLDisplay text says microsoft.com but the link points elsewhere; shortened bit.ly URLs
AttachmentsWhether you expected the fileMacro-enabled Office docs,.zip/.7z archives, "enable editing to view" prompts

Sender address and lookalike domains

The display name on an email can be set to anything. The real address, visible by clicking or hovering on the sender, reveals the true origin. A display name of "HMRC Refunds" sitting on `refund@hmrc-gov-uk.com` is plainly fraudulent. Lookalike domains, such as amvla.co.uk instead of amvia.co.uk, are subtler but spottable if you slow down and read.

Urgency, unusual requests, and payment changes

Phishing manufactures urgency to override careful thinking. Legitimate organisations rarely demand action without time to verify. Treat any email requesting credentials, personal data, a payment outside the normal process, or a change to bank details with scepticism, no matter who it appears to come from. The NCSC's guidance on phishing attacks makes the same point: criminals impersonate senior staff and known suppliers to make fraudulent requests feel routine. The correct response to any unexpected financial instruction is telephone verification on a number you already hold.

How do you build a reporting culture?

The single most valuable trait for phishing resilience is a culture where people report suspicious emails without fear of looking foolish. An employee who quietly deletes a phishing email removes the chance for IT to investigate, warn colleagues, and stop a wider attack. Make reporting effortless and judgment-free.

Two things drive this. First, leadership must model the behaviour, openly sharing when they have received and reported a suspicious message. Second, reporting must be one click. A report button in Outlook, available through Microsoft Defender, sends the email straight to your security team for analysis. When reporting is frictionless and praised rather than punished, volume goes up and your real-world detection improves.

Do simulated phishing exercises actually work?

Yes. Simulated phishing, sending controlled fake attacks to test staff, is the most effective single training method because it teaches in the moment. An employee who clicks a simulation gets immediate, contextual feedback explaining exactly what they missed, which sticks far better than an annual awareness slide deck.

Calibrate simulations to be challenging but not demoralising. The aim is learning, not a pass-or-fail test. A few guidelines AMVIA applies in practice:

  • An initial click rate of 20–35% is normal for organisations with no prior training.
  • Click rates above 30–40% signal a need for foundational training before harder simulations.
  • Most organisations see meaningful improvement within two to three cycles, and reach under 10% within six months.
  • A sustained rate under 5% indicates strong, organisation-wide awareness.

The trend over time matters more than any single result. Track it, report it without naming individuals, and use the data to target follow-up training.

What should you do when an attack gets through?

When a link is clicked or credentials are entered, speed decides the outcome. Attackers often reach a compromised account within minutes. The priority is to cut access, reset credentials, and revoke active sessions before the attacker sets up forwarding rules or moves laterally. Have a written, rehearsed routine ready.

Train every employee to take these steps the moment they realise they have been caught:

  • Stop using the affected device and disconnect it from the network if malware may be installed.
  • Report to IT immediately through a non-email channel, in case email is compromised.
  • Change the password for any account whose credentials may have been entered.
  • Revoke active sessions; Microsoft 365 lets you sign out of all sessions from account security settings.

Your IT or security team should then review email logs for rogue forwarding rules, check for OAuth apps granted access to the mailbox, and assess whether a personal-data breach must be reported. Under UK GDPR, a notifiable breach must reach the ICO within 72 hours. This is where a defined incident response process and 24/7 security monitoring turn a panic into a procedure.

How Would Your Team Perform Against a Real Phishing Attack?

A simulated phishing exercise reveals your team's current awareness level and provides targeted training where it is needed most.

Frequently Asked Questions