Call NowFree Quote
Cybersecurity

How to Train Perth Staff to Spot Phishing Attacks

No security tool in the world stops a staff member from willingly handing their credentials to an attacker. Phishing relies on convincing people - not breaking through technical defences. That's why security awareness training is a critical part of any Perth business's cybersecurity posture.

Why Phishing Works

Phishing attacks have evolved far beyond the obvious "Nigerian prince" emails. Modern phishing is targeted, professional, and often indistinguishable from legitimate correspondence at a glance. Common tactics:

  • Spear phishing - targeted emails using the recipient's name, role, and company details gathered from LinkedIn, company websites, or social media
  • Business email compromise (BEC) - emails impersonating your CEO, accountant, or a supplier asking for an urgent payment or credential reset
  • Brand impersonation - fake Microsoft, ATO, Xero, or bank emails designed to capture login credentials
  • Invoice fraud - fake invoices with changed bank account details, sent to your accounts payable team
  • Callback phishing - emails asking the recipient to call a number, where a fake IT support agent then talks them into giving remote access

The Australian Signals Directorate (ASD) consistently reports that phishing is the most common initial access technique in Australian cyber incidents.

The Warning Signs Staff Need to Know

Train your staff to look for these red flags before clicking any link or responding to any request:

Check the sender address - not just the display name

An email can display as "Microsoft Support" while actually coming from support@m1cr0soft-help.net. Always check the actual email address, not just the name shown. In Microsoft Outlook, hover over the sender name to see the real address.

Urgency and pressure

Phishing emails create artificial urgency: "Your account will be suspended in 24 hours", "Urgent payment required today", "Immediate action needed". Legitimate organisations give you time. If an email is pressuring you to act immediately, slow down.

Requests that bypass normal process

A CEO who normally approves expenses through your accounting system does not email you asking to wire funds urgently. A supplier does not change bank account details by email alone. Any request that bypasses your normal process should be verified through a separate channel - call the person directly using a known number, not one provided in the suspicious email.

Mismatched or suspicious links

Before clicking any link, hover over it to see the actual URL. If an email claims to be from Microsoft but the link goes to microsoftsupport-login.com, it is a phishing site. Legitimate Microsoft links go to microsoft.com, login.microsoftonline.com, or similar official domains.

Unexpected attachments

An unsolicited PDF, Word document, or ZIP file from an unknown sender - or even a known sender if unexpected - should be treated with suspicion. Word documents and Excel files can contain malicious macros; PDFs can contain malicious links or exploits.

How to Run Security Awareness Training

Simulated phishing campaigns

The most effective training method is simulated phishing - sending fake phishing emails to your own staff and tracking who clicks. Staff who click are immediately given brief, non-punitive training explaining what they missed. Microsoft Attack Simulator (included with Microsoft 365 Business Premium) and various dedicated security awareness platforms provide this capability.

Run simulations quarterly. Click rates typically drop significantly after the first simulation - the experience of nearly falling for a test is far more memorable than any slide presentation.

Regular short training, not annual marathons

A two-hour annual security training session is far less effective than 5-minute monthly micro-learning modules. Short, relevant, scenario-based content - focused on real examples of phishing that have targeted Australian businesses - produces better retention.

Clear reporting procedures

Staff need to know what to do when they receive a suspicious email. Make reporting easy: a dedicated email address, a button in Outlook (Microsoft provides a Report Message add-in), or a simple process like forwarding to IT. Reward reporting - never punish staff for flagging a suspicious email, even if it turns out to be legitimate.

What to Do If Someone Clicks

Despite training, clicks will happen. A clear, blame-free response process is essential:

  1. Staff member reports the click immediately to IT - make this easy and non-punitive
  2. IT isolates the device from the network if malware may have downloaded
  3. Change the passwords for any credentials that may have been entered on the phishing site
  4. Revoke and reissue any active sessions for affected accounts
  5. Assess whether any data was accessed or exfiltrated
  6. Determine if the incident meets the threshold for a Notifiable Data Breach under the Privacy Act

Speed matters. The faster a compromised credential is changed, the less time an attacker has to use it.

Frequently Asked Questions

What's 'callback phishing' and how is it different from a normal phishing email?

Instead of a malicious link, the email asks you to call a phone number, where a fake support agent then talks you into installing remote access software or handing over credentials over the phone. It's effective because it moves the attack away from email, where people are more cautious, into a phone conversation where they let their guard down.

How often should we run phishing simulations?

Quarterly is a reasonable rhythm for most small businesses. Click rates typically drop noticeably after the first simulation, since nearly falling for a realistic test tends to stick in people's memory far better than a slide presentation ever does.

Should staff be worried about getting in trouble if they click a simulated or real phishing email?

No, and that's important to make clear upfront, staff who click during a simulation should get brief, non-punitive guidance on what they missed, not a reprimand. The same applies to real incidents, punishing people for reporting a mistake just teaches everyone to stay quiet next time, which is worse for the business.

Does a staff member clicking a phishing link automatically mean we've had a reportable data breach?

Not automatically, it depends on what was actually accessed or exposed as a result. If credentials or data may have been compromised, that's worth assessing against your obligations under the Privacy Act's Notifiable Data Breaches scheme, and it's worth getting proper advice on that assessment rather than guessing.

We help Perth businesses implement security awareness training and simulated phishing programs as part of a complete cybersecurity posture.

Cybersecurity Services →

Get your team phishing-aware

Call 0433 087 091 - we'll set up simulated phishing campaigns and staff training to reduce your click rate and improve your human firewall.

Book a Security Consultation

For related reading, see our guides to How Often Should Staff Cyber Security Training Happen? and What an IT Security Audit Covers.

Share this article