Skip to content

Most breaches start with a person, not a server.

It is easier to trick someone than to break in, and small teams rarely get tested. Training is how you close that gap.

68%

of breaches involved a non-malicious human element: someone who was tricked or made a mistake.

Source: Verizon 2024 Data Breach Investigations Report

What phishing looks like now

Attackers copy the tools and people your team trusts, on every channel they answer.

Email

Real branding and real urgency at 2pm on a Tuesday. Not a prince with a fortune to share.

Accounts Payable · billing@vendor-invoices.co

Invoice #4471 overdue

Please settle the attached invoice today to avoid a late fee.

Phone calls

A call from “IT” asking for the code on your phone sounds routine, and AI makes the voice convincing.

Incoming call · 2 min 14 s

Call from 'IT support'

“Hi, it's Dave from IT. We're resetting everyone's sign-in this morning, have you got two minutes?”

Video calls

Deepfake video calls have already been used to talk finance staff into sending large payments.

Meeting invite · 0:38 video

Quick call: supplier bank details

“Hi, we've moved banks. Can you update our details before today's payment run?”

Can you spot all five red flags?

This is the kind of message PhishPlease sends in a simulation. Each flag is something your team learns to check.

Accounts Payable · billing@vendor-invoices.co

Invoice #4471 overdue

Please settle the attached invoice today to avoid a late fee.

  1. Lookalike sender. vendor-invoices.co is not your supplier's domain

  2. Invented urgency. “today to avoid a late fee” is there to rush you

  3. Generic greeting. Your real supplier knows your name

  4. Link that doesn't match. The button points somewhere other than the vendor

  5. Unusual request. New bank details should always be checked by phone

Why training works

  1. 01

    People learn right after a mistake

    A short lesson the moment someone clicks sticks better than a yearly video.

  2. 02

    Practice beats warnings

    “Be careful with attachments” doesn't change behaviour. Realistic practice does.

  3. 03

    Reporting makes everyone a sensor

    A team that reports suspicious messages catches the ones that get through filters.

Your insurer probably already asks about this.

Many cyber insurance applications ask whether you run phishing simulations and security training. Answering yes needs evidence.

How PhishPlease helps with insurance

Find out who'd click.

Send your first simulation and see the results in your dashboard.

14-day free trial · No credit card required