Half an hour of training is worth more than most technical controls.
WHAT TO SHOW THEM
Real phishing messages, ideally ones your business has actually received How to read the true sender address rather than the display name How to hover over a link and read the destination
The pattern: urgency, threat, a link, a login page
THE SCENARIOS THAT COST MONEY
A supplier emailing new bank details A message appearing to be from a director asking for an urgent payment An invoice attachment asking to enable macros A shared document requiring sign-in
THE RULES TO DRILL
Verify any change of payment details by phone, using a number you already hold Never enter a password on a page reached from an email link If in doubt, ask a colleague before clicking
WHAT TO AVOID
Blame. If someone clicks and reports it immediately, that is a good outcome. A culture where people hide mistakes is how a small compromise becomes a large one.
REPEAT IT
Once a year, and whenever a new attack pattern appears.