Emergency SectorsCareers About us Blog Get in touch
NLNederlandsENEnglish
Employee looking at a suspicious email on a laptop screen

Phishing and the human layer

Almost every incident we are called into started with a login, not an exploit. That is not a training problem, it is a design problem: the system allowed one mistake to be enough.

Updated July 2026 3 min read Written by the ITproposal team
In short

Awareness training reduces clicks but never to zero, so a design that depends on nobody clicking will fail. Assume the click happens and make it survivable.

Three controls stop most credential attacks: phishing-resistant multi-factor authentication, conditional access that blocks sign-ins from unexpected places, and a payment procedure where no invoice change is accepted by email alone.

The first hour matters more than the training. Disable the account, revoke active sessions, check what the account touched, and tell people what happened without blaming the person who clicked.

Why training alone does not get you there

Awareness training works, in the sense that it lowers the click rate. It does not get the rate to zero, and it never will, because the messages are good and people are busy. A finance employee who receives forty supplier emails a day will eventually open the one that was designed to look like the other thirty-nine.

The mistake is treating that as the last line of defence. If one click is enough to lose an account, the problem is not the click. Training belongs in the plan, but as a way of shortening the time until someone reports it rather than as the control that prevents it.

The three controls that actually stop it

In order of effect per euro spent.
ControlWhat it stopsEffort
Phishing-resistant multi-factorA stolen password on its own is uselessLow, and mostly configuration
Conditional accessSign-ins from countries and devices that make no senseLow, needs a policy decision
Payment change procedureInvoice and bank detail fraud, which is where the money goesNone technically, it is a process

Note that the third one is not an IT measure at all. It is the one that prevents the most expensive category of loss, and it costs nothing but a rule.

Not all multi-factor is equal

Push notifications that ask you to approve a login are convenient and increasingly ineffective. Attackers send the request repeatedly until somebody taps approve to make it stop, usually at an inconvenient moment. That is known as MFA fatigue and it works often enough to be a standard technique.

Number matching, where you have to type a code shown on the screen you are logging in from, removes most of it. Hardware keys remove effectively all of it. For a mid-market organisation, number matching everywhere plus hardware keys for finance and administrators is a proportionate answer.

The attack that costs the most is not technical

Invoice fraud and bank detail changes cause more direct financial loss than encryption does. An attacker who reads a mailbox for two weeks learns your suppliers, your tone and your payment cycle, and then sends a plausible message about a changed account number at exactly the right moment.

The defence is a rule with no exception: a change of bank details is verified by calling a number you already had, never one from the email. Write it down, apply it to the director as well, and make it socially acceptable to insist on it. Most organisations have the rule and quietly waive it when the request comes from someone senior, which is precisely the case it was written for.

What to do in the first hour

  • Disable the account and revoke sessions. Changing the password is not enough; an active session survives it.
  • Check what changed. Mail forwarding rules, added devices, changed recovery details. Attackers set those up within minutes.
  • Check what was reachable. Which files and mailboxes the account could open, not just which it did.
  • Tell people. Others got the same message. Silence guarantees a second click.
  • Do not blame the person who reported it. The next report will take a day longer if you do, and that day is the whole difference.

Where this lands in an incident procedure is described under cybersecurity, and the reporting obligations under NIS2 in what you must be able to show.

Simulations are useful if you use them properly

A phishing simulation that produces a click percentage and a scolding email achieves very little. One that measures how quickly the first person reports it achieves a great deal, because reporting time is the number that determines how much damage an incident does.

Run them regularly, keep them realistic rather than absurdly easy, and publish the reporting time rather than the click rate. It changes what people optimise for.

Frequently asked

Questions we get about this

What organisations ask after a close call.

Does awareness training actually work?

It lowers the click rate but never to zero. Its real value is shortening the time until somebody reports a suspicious message, and reporting time is what determines how much damage an incident does. Treat it as a way to speed up detection, not as a way to prevent clicks.

Is multi-factor authentication enough on its own?

It is the single most effective control, but push-approval multi-factor can be defeated by sending repeated requests until somebody approves one. Number matching removes most of that risk and hardware keys remove effectively all of it.

What should we do first if somebody clicked?

Disable the account and revoke active sessions, because changing the password alone leaves an open session working. Then check for added forwarding rules and devices, work out what the account could reach, and warn everyone who received the same message.

How do we prevent invoice fraud?

One rule, applied without exception: bank detail changes are verified by phoning a number you already held, never one from the email. It costs nothing and it prevents the most expensive category of loss we see.

Related services

Where this lands in our work

Where this connects.

Want this looked at for your own sites?

Half an hour on a call is usually enough to tell you whether we are the right party for it, and we will say so if we are not.