Technical controls stop technical attacks. Social engineering bypasses them entirely by targeting the one element no firewall can protect — your people. Building a security-aware culture is the most underinvested defence in most organisations.
You can deploy the best firewall on the market, implement MFA on every account, and run a 24/7 SOC — and still be compromised by a single employee who receives a convincing phone call from someone pretending to be the IT helpdesk.
Verizon's Data Breach Investigations Report consistently attributes 74% of breaches to human involvement — whether through phishing, pretexting, credential theft, or simple error. Social engineering is the most reliable attack vector precisely because it bypasses technical controls entirely. Attackers do not hack systems; they hack people.
The question is not whether your employees will be targeted. They will be, today, by automated campaigns running at scale across millions of organisations simultaneously. The question is whether they will recognise the attempt — and what they will do about it.
Phishing: Mass email campaigns impersonating trusted organisations — banks, Microsoft, HMRC, courier companies — designed to harvest credentials or deliver malware. The lowest-sophistication attack and still the most common because it scales to millions of recipients at near-zero cost.
Spear Phishing: Targeted phishing campaigns that use specific knowledge about the recipient — their name, role, manager, recent projects, or business relationships — to create a highly convincing personalised message. With AI, the research and writing effort that once took hours now takes seconds.
Vishing: Voice phishing. A caller impersonates IT support, a bank security team, a government agency, or an executive to extract credentials, authorise transactions, or obtain sensitive information. AI voice cloning now enables real-time impersonation of known individuals with hours of training audio available on YouTube or podcast recordings.
Smishing: SMS-based phishing. Text messages impersonating parcel delivery services, banks, or government agencies with links to credential harvesting pages. Mobile users click links far more readily than desktop users — the small screen makes URLs harder to scrutinise.
Pretexting: Creating a fabricated scenario — a fake identity, role, and context — to manipulate a target into taking an action they would otherwise refuse. The attacker who calls your accounts payable team claiming to be a supplier updating their bank details is running a pretext.
Deepfake attacks: The emerging frontier. Video calls with AI-generated faces and cloned voices of executives or colleagues, convincing enough to authorise wire transfers or disclose credentials to people who do not exist.
The standard approach to security awareness — a 45-minute e-learning module completed once a year to satisfy a compliance checkbox — has been studied extensively and shown to produce negligible lasting behaviour change. Employees complete the module, pass the quiz, and forget 80% of the content within a week.
Behaviour change requires repeated exposure, immediate feedback, and relevance to real-world scenarios employees actually encounter. A compliance module about a hypothetical phishing email from 2019 does not prepare someone to recognise a deepfake call claiming to be their CFO in 2025.
Simulated phishing campaigns: Monthly phishing simulations using realistic, current lures — not obviously fake test emails — measure susceptibility across the workforce and identify individuals who need additional training. When someone clicks a simulation link, immediate in-context training is far more effective than a retrospective module weeks later.
Role-specific training: Finance teams face different threats than developers, who face different threats than executives. Generic training delivers generic results. Segment training by role, focusing on the specific attack scenarios each group encounters.
Micro-learning: Replace annual modules with monthly five-minute lessons on a single, specific topic. Short, frequent, targeted training maintains awareness and builds knowledge incrementally. Spaced repetition — the same concept revisited weeks or months later — significantly improves retention.
Reward reporting, not just prevention: Create a culture where reporting suspicious messages is celebrated. When an employee reports a phishing email, they should receive positive feedback — not silence, and certainly not a response that questions their judgement. Every report is an intelligence signal that may protect every other employee on the same campaign.
Tabletop scenarios: Walk teams through realistic attack scenarios in workshop format. "The CFO just called your mobile and asked you to transfer £50,000 immediately — what do you do?" Working through the scenario in a low-stakes environment builds the muscle memory to make the right call under pressure.
Technical training addresses knowledge gaps. Culture addresses the environment in which decisions are made. Employees in organisations with cultures that punish mistakes hide security incidents. Employees in organisations that treat security as a shared responsibility report incidents within minutes.
Leaders set the tone. When the CEO completes security awareness training publicly, includes security in all-hands presentations, and talks openly about phishing attempts they have received, the entire organisation recalibrates its attitude to security. When security is seen as something IT does, the human firewall never fully activates.
Track phishing simulation click rates over time — a downward trend indicates the programme is working. Measure report rates — the percentage of employees who report suspicious messages — which should increase as awareness improves. Conduct pre- and post-training knowledge assessments to quantify learning. Survey employees quarterly on their confidence to recognise and report attacks.
CyberPhoenix designs and delivers security awareness programmes that combine simulated phishing, micro-learning, and culture change initiatives — tailored to your organisation's specific threat profile and workforce. Contact us to discuss a programme that actually moves the needle.