Cyber Security

Security Awareness Training and Phishing in the UAE: What Actually Reduces the Risk

SKIMBOX Team

Training changes what people know. It does not reliably change what they do under a well-targeted lure, and the national security agencies say so. Here is the honest version, including why punitive phishing simulations backfire and which controls work whether or not somebody clicks.

Security Awareness Training and Phishing in the UAE: What Actually Reduces the Risk

Someone in accounts paid a fake invoice. The technical controls were bought, the antivirus was current, and the annual training was completed by everyone with a certificate to prove it.

This is the part of security that resists being solved by purchasing, and it is also the part where the advice is least trustworthy, because almost all of it is published by companies selling training platforms. What follows is drawn from the national security agencies instead, and their position is more sceptical than the sales material.

We cover the technical layer separately in our guides to small business cybersecurity and website security, and the delivery platform question in our corporate LMS guide.

Does awareness training work?

Partly, and less than you have been told. Research co-authored through NIST's human-centred cybersecurity programme found that the best predictor of phishing susceptibility was previously falling for a phishing email, and that repeat clickers did not respond to training interventions [3]. A second study it cites found a group whose failures came from interest in the subject matter and a lack of careful attention rather than a knowledge gap, and whose performance also did not improve after training [3].

The NCSC states the human side bluntly: blaming users for clicking on links does not work, because clicking stems from situational and personality factors rather than a simple knowledge gap, and asking users to examine every email in depth is unrealistic when responding to email is a core part of most jobs [1].

NIST's earlier modelling points the same way, treating the decision to comply with a phishing message as a function of context and personality rather than knowledge alone [4].

Read together, that is a more useful position than either "training is essential" or "training is useless". Training raises the floor and tells people how to report. It does not reliably stop a well-targeted message reaching a busy person at a bad moment. So the defence has to include controls that hold when the click happens anyway.

Why your click rate is not telling you what you think

NIST publishes a method called the Phish Scale precisely because organisations were drawing wrong conclusions from raw click rates. It rates how difficult an email actually was to detect, using the number and nature of cues in the message and something it calls premise alignment, meaning how closely the message matches the recipient's real role and current context [3].

The implication is uncomfortable for anyone reporting a click rate to a board. A well-targeted email aimed at a real work concern, with few detectable cues, is genuinely hard to spot regardless of training. A low click rate on an obvious lure proves nothing, and a high one on a sophisticated lure does not mean your people are careless.

NIST's guidance on building an awareness programme points at a better measure: behaviour change, specifically the percentage of participants who changed a behaviour such as reporting a suspected phishing email, and how those reports are made [2].

Report rate is the number worth putting in front of your board. It measures whether people will raise a hand, which is the thing that actually shortens an incident.

Phishing simulations, run so they do not backfire

Simulations are currently the best available source of data on real susceptibility. They are also capable of doing genuine damage, and the NCSC is unusually direct about it: they erode trust between employees and security, and employees who are afraid for their jobs will not report mistakes [1].

Two agencies arrived at the same rules independently, which is worth noting on a topic this crowded with vendors.

Do not punish individuals. The NCSC observes that punishing people for clicking on emails you sent them starts to resemble entrapment [1]. NIST states that these activities should not be punitive and that no employee should be called out for their response [2].

Do not publish names. The NCSC's point about measurement is the one to keep: metrics express an organisation's values, and if you appear to value the absence of reported problems, you incentivise people to keep quiet [1].

Tell people simulations happen. NIST's guidance is to say in advance, in general terms, that exercises run on a random ongoing basis and that results guide future learning [2].

Do not impersonate real organisations. NIST specifically flags avoiding real external brands in a lure, because it produces genuine confused contact with those third parties [2].

Baseline first, and judge difficulty honestly. NIST suggests establishing current click rates for a group or work role to see whether more targeted training is needed [2], and the Phish Scale exists to stop you comparing campaigns of different difficulty as though they were the same test.

The attack that actually takes the money

Business email compromise arrives as a credible email rather than as malware. There may be no attachment, no link, and nothing for a filter to catch. It asks for a payment to be made or for bank details to be changed, and it often follows a real conversation the attacker has been quietly reading.

CISA has documented the mechanism that makes the reading possible: attackers creating mailbox rules that move or delete messages so the legitimate account holder never sees the thread continuing without them [7]. That rule is frequently the only visible artefact sitting between the account compromise and the fraudulent invoice, which makes monitoring for new or unusual mailbox rules a genuinely high-value control.

The single most valuable thing in this article. Verify every change to payment details out of band, by calling a number you already hold, never one supplied in the message. Applied without exception, that defeats the whole category regardless of how convincing the email was or whose name was on it.

The reason it fails in practice is that it is written as advice rather than as process. If it is a guideline, somebody has to decide whether this particular message looks suspicious, and the whole point of a good lure is that it does not. Make it a mandatory step in the finance workflow, keep the contact numbers in your own system rather than in the email thread, and make it explicitly acceptable for a junior finance person to apply the rule to a director. That last part is cultural and it is the part that usually breaks.

The controls that work whether or not somebody clicks

Move off SMS codes. CISA publishes a clear hierarchy: hardware security keys using FIDO or WebAuthn are strongest, then an authenticator app with number matching, then an authenticator app with a one-time code, then biometrics, with SMS or email codes described as the weakest protection to be used only when stronger options are unavailable [5].

Understand what phishing-resistant means. CISA's position is that phishing-resistant methods such as FIDO, WebAuthn and certificate-based authentication resist phishing, and that push bombing, telecoms interception and SIM swap attacks do not apply to them [6]. That is a structural defence rather than a behavioural one, which is why it holds on the day training does not.

Know the local angle on SIM swap. SMS as a second factor depends on nobody taking over your number. The UAE has a relevant structural protection here, in that SIM registration is tied to Emirates ID and residents can check which numbers are registered in their name through the Hesabati service [11]. That makes an unnoticed swap harder than in some markets, and it is not a reason to keep using SMS.

Watch for MFA fatigue. An attacker who already has a password can simply trigger approval prompts repeatedly until somebody accepts one to make it stop, usually late at night. Number matching addresses it directly, and it is a configuration change rather than a training topic.

Name QR code phishing in training. A phishing link delivered as an image has no URL for a filter to read, and the victim scans it with a personal phone that often sits outside your protections entirely. Most people do not perceive a printed code as a link at all.

What to actually put in the training

Given all of the above, the useful content is narrower than a generic course and mostly concerns what to do rather than what to spot.

Teach the reporting route, not the warning signs. Spotting advice ages badly and does not survive a well-targeted lure. Knowing how to report, and that reporting is welcome, survives both. If people remember one thing, make it the button.

Teach the payment rule to the people it applies to. For finance, payroll and executive support, the content is a process: any change to bank details is verified by calling a stored number. That is a five-minute briefing repeated often, not an hour-long module.

Teach the shapes that filters miss. A QR code in an image, a message with no link at all asking for a favour, and a request that arrives inside a genuine ongoing conversation are the cases where technology will not help. Those are worth naming specifically because they do not look like the phishing examples people have seen.

Say out loud that clicking happens. Telling a room that some of them will click, that it is expected, and that the only wrong move is staying quiet does more for your incident response time than a module on hovering over links. It is also true, which the alternative framing is not.

Reporting is the control you are actually buying

One route, one click, no fear attached. A button in the mail client beats an address people must remember, and either beats a policy nobody has read. The NCSC runs a national reporting service on exactly this principle, noting that reporting is free and takes about a minute [8].

What happens after the first report determines your reporting rate for the next year. Thank people quickly and visibly. The NCSC's guidance is explicit about reassuring users that they will not get in trouble for reporting, including reporting after they have already clicked, and about supporting people who click and only later suspect something was wrong [1].

That last case matters more than it sounds. The hours between a click and a report are usually where the loss is decided, and how long they last is set entirely by how safe reporting feels.

A pattern we see. A UAE business runs a simulation, publishes the results by name in a management meeting, and congratulates itself on a falling click rate over the next two quarters. What actually fell was reporting. Three months later a real compromise runs for eleven days because the person who noticed the odd email assumed it was another test and did not want to be on the list again.

Reporting obligations, stated carefully

Check your own position rather than relying on a general article. The UAE data protection law requires notification, and our PDPL compliance guide sets out our position in detail, including what we could not confirm.

The UAE government publishes general cyber security guidance for businesses and residents [9], and the data protection law itself is summarised on the same official portal [10]. Neither establishes the specifics people usually want. We are deliberately not publishing a notification deadline in hours or a penalty figure here, because no executive regulation establishing either has been published, and a confident wrong number on this subject is worse than none. If you operate in a regulated sector, your regulator's requirements will be more specific than the general law, and they are the ones that will apply to you.

If you are pursuing certification, awareness sits inside what a management system covers and your auditor will expect evidence of a programme. Our ISO 27001 guide covers what the audit examines. Build the programme to change behaviour rather than to satisfy the audit, and the evidence falls out of it anyway.

Who to start with, and why headcount is the wrong unit

Attackers target roles, not people at random, so a programme organised by headcount spreads effort evenly across a risk that is not evenly distributed.

The roles that matter for this specific threat are the ones that can move money or change where it goes: finance, payroll, whoever supports the executives, and anyone with authority to approve a payment or amend a supplier record. A finance team of four is a larger exposure than a warehouse team of forty, and treating them identically is how the fourth-largest risk gets the same attention as the first.

Start there, and give that group the payment verification rule as a process step rather than as awareness content. Then extend to everyone else with something shorter and less frequent, because the goal for the wider organisation is the reporting habit rather than deep familiarity with attack patterns.

There is a second reason to start narrow. A small group is where you can afford to do the expensive part properly: sitting with the finance team, walking through how a supplier bank change actually reaches them today, and finding the step where nobody currently verifies anything. That conversation surfaces more real risk than any simulation, and it takes an afternoon.

What it costs

An awareness programme with simulations starts from around AED 3,000 a year for a small team with us. A review of your payment verification process, which is the control most likely to prevent an actual loss, starts from around AED 2,500. These are our own figures rather than a market survey, since no government body or standards organisation publishes rates for this work. Final pricing depends on headcount and how many roles need role-specific material.

For context against the rest of your security spend, a security assessment starts from around AED 5,000 and managed IT support from around AED 100 per user per month.

Our honest view on sequencing: if you have to choose, phishing-resistant authentication and a written out-of-band verification rule will do more for a typical UAE SME than another year of courses. Both are one-off pieces of work with permanent effect. Train alongside them, not instead of them.

What to do this month

  • Write the payment verification rule and make it a mandatory process step, not advice
  • Move any account that can approve payments off SMS codes
  • Turn on number matching wherever your authenticator supports it
  • Set up a one-click reporting button and thank the first person who uses it
  • Check for unexpected mailbox rules across your finance and executive accounts
  • Run a baseline simulation with no names published and no consequences attached
  • Report your report rate to your board, not your click rate

None of that requires a platform purchase, and the first two would have stopped most of the invoice fraud we have been asked to look at after the fact.

If you would like the payment process reviewed by someone who has seen how these actually succeed, contact us.

References

[1] National Cyber Security Centre, Phishing attacks: defending your organisation. ncsc.gov.uk

[2] NIST, SP 800-50 Rev. 1: Building a Cybersecurity and Privacy Learning Program. csrc.nist.gov

[3] NIST, Human-Centered Cybersecurity: phishing research and the Phish Scale. csrc.nist.gov

[4] NIST, IR 8194: Exploratory Lens Model of Decision-Making in a Potential Phishing Attack Scenario. csrc.nist.gov

[5] CISA, Require multifactor authentication. cisa.gov

[6] CISA, Implementing phishing-resistant MFA. cisa.gov

[7] CISA, Analysis Report AR21-013A: Strengthening Security Configurations to Defend Against Attackers Targeting Cloud Services. cisa.gov

[8] National Cyber Security Centre, Report a scam email. ncsc.gov.uk

[9] The Official Portal of the UAE Government, Cyber security. u.ae

[10] The Official Portal of the UAE Government, Data protection laws. u.ae

[11] The Official Portal of the UAE Government, Telecommunications: SIM registration and the Hesabati service. u.ae

Frequently asked questions

  • Does security awareness training actually work?

    Partly, and less than the companies selling it suggest. Research co-authored through NIST found that the best predictor of phishing susceptibility was previously falling for a phishing email, and that repeat clickers did not respond to training interventions. A second study found a group whose failures came from interest in the subject and lack of careful attention rather than a knowledge gap, and whose performance also did not improve with training.

  • So should we not bother training staff?

    Train, but do not treat it as your defence. Training raises the floor, gives people permission to be suspicious, and tells them how to report. What it does not do is reliably stop a well-targeted message reaching a busy person at the wrong moment. That is why official guidance pushes toward controls that work whether or not the click happens, rather than treating awareness as the primary control.

  • Why do people click even after training?

    Because clicking links is the job. The UK's National Cyber Security Centre puts it plainly, saying that blaming users for clicking links does not work, and that asking users to examine every email in depth is unrealistic when responding to email is a core part of most roles. Susceptibility also tracks context and personality rather than knowledge alone, which is why the same trained person can pass one month and fail the next.

  • What is the Phish Scale?

    It is a NIST method for judging how difficult a phishing email actually was to spot, based on the number and nature of cues in the message and how closely its premise matches the recipient's real work context. It exists because organisations were comparing raw click rates across campaigns of wildly different difficulty and drawing wrong conclusions. A low click rate on an obvious lure tells you nothing useful.

  • Is click rate a good measure of our programme?

    On its own, no. NIST's guidance on building an awareness programme points at behaviour change as the measure, specifically the percentage of participants who changed a behaviour such as reporting a suspected phishing email, and how those reports are made. Click rate moves with how well targeted that month's lure happened to be. Report rate tells you whether people will actually raise a hand.

  • Should we run phishing simulations?

    Yes, if you run them without punishment. Simulations are currently the best available source of data on real susceptibility, but the NCSC is blunt about the downside, warning that they erode trust between employees and security, and that employees afraid for their jobs will not report mistakes. A simulation programme run as a trap does measurable harm to the reporting culture you actually need.

  • Can we discipline people who fail simulations?

    We would strongly advise against it, and so do both national agencies. The NCSC notes that punishing people for clicking emails you sent them starts to resemble entrapment. NIST's guidance states that these activities should not be punitive and that no employee should be called out for their response. The practical cost of punishment is that your next real incident goes unreported until it is expensive.

  • Should we publish a leaderboard of who clicked?

    No. Naming individuals converts a security exercise into a shaming exercise, and the NCSC's point about metrics is the one to hold onto: metrics express an organisation's values, and if you appear to value the absence of reported problems, you incentivise people to keep quiet. A team-level trend is useful. A list of names is a way of finding out less next time.

  • Should we tell staff that simulations happen?

    Yes, in general terms. NIST's guidance is to tell staff in advance that phishing exercises take place on a random ongoing basis and that results will guide future learning rather than punish individuals. That framing keeps the data honest while removing the sense of ambush, and it makes the programme defensible internally when somebody senior fails a test and asks who authorised it.

  • Can we impersonate a real brand in a simulated phishing email?

    You should not. NIST specifically flags avoiding the impersonation of real external brands or organisations in a simulated lure, because it generates genuine confused calls and emails to those third parties. There is also a plain reputational risk in sending mail that imitates a bank or a government body. Build lures that are realistic in structure without borrowing somebody else's identity.

  • What is business email compromise?

    It is fraud that arrives as a credible email rather than as malware, usually asking for a payment to be made or for bank details to be changed. There may be no attachment, no link and nothing for a filter to catch, which is precisely why it works. It targets whoever can move money, and the message often follows a real conversation the attacker has been reading.

  • How do attackers read our email before the fraud?

    Commonly through a compromised mailbox plus a rule that hides their tracks. CISA has documented attackers creating mailbox rules that move or delete messages so the legitimate account holder does not notice the ongoing conversation. That is why monitoring for new or unusual mailbox rules is a control worth having: the rule is often the only visible artefact between the account compromise and the fraudulent invoice.

  • What is the single best control against invoice fraud?

    Verify bank detail changes out of band, using a phone number you already hold rather than one supplied in the message. That one rule, applied without exception, defeats the entire category regardless of how convincing the email was or who appeared to send it. Write it down, make it mandatory, and make it socially acceptable for a junior person to apply it to a director.

  • How do we make out-of-band verification actually happen?

    By removing the judgement call. If the rule is that any change to payment details requires a call to a stored number, nobody has to decide whether this particular message looks suspicious. Make it a process step in your finance workflow rather than a guideline, keep the contact numbers in your own system rather than in the email thread, and confirm that staff will not be criticised for slowing a payment down.

  • What is MFA fatigue?

    It is an attack where someone who already has your password triggers repeated approval prompts until the user accepts one, often late at night or during a busy period, simply to make them stop. It does not require any technical sophistication. It works because approving a prompt is easier than investigating one, which is a design problem rather than a training problem.

  • Which type of multi-factor authentication is strongest?

    CISA publishes a clear hierarchy. Hardware security keys using FIDO or WebAuthn are strongest, followed by an authenticator app with number matching, then an authenticator app with a one-time code, then biometrics, with codes sent by SMS or email described as the weakest protection to be used only when stronger options are unavailable. Moving up that list is usually cheaper than another year of training.

  • What does phishing-resistant mean?

    It means the factor cannot be handed over by a person who has been tricked. CISA's position is that phishing-resistant methods such as FIDO and WebAuthn or certificate-based authentication resist phishing, and that push bombing, telecoms interception and SIM swap attacks do not apply to them. That is a structural defence rather than a behavioural one, which is exactly why it holds when training does not.

  • What is a SIM swap and can it happen here?

    It is an attacker taking control of your phone number to intercept codes sent by SMS. It is a strong argument against SMS as your second factor anywhere. The UAE has a relevant structural protection, in that SIM registration is tied to Emirates ID and residents can check which numbers are registered in their name through the Hesabati service, which makes an unnoticed swap harder than in some markets.

  • What is QR code phishing?

    It is a phishing link delivered as a QR code, usually in an image, so that email filters scanning for malicious URLs have nothing to read. The victim then scans it with a personal phone, which frequently sits outside the organisation's protections entirely. It is worth naming in training specifically, because a printed or emailed code does not look like a link to most people.

  • What should our reporting route be?

    One route, one click, and no fear attached. A button in the mail client is better than an address people have to remember, and either is better than a policy nobody has read. The NCSC's own national reporting service exists precisely because low-friction reporting produces a usable security signal at scale, and it makes the point that reporting is free and takes about a minute.

  • What should happen when somebody reports a real phish?

    Thank them, quickly and visibly. The response to the first report sets the reporting rate for the next year. If the reply is slow, dismissive, or turns into questions about why they opened it, you have taught the organisation not to bother. NCSC guidance is explicit about reassuring people that they will not get in trouble for reporting, including after they have already clicked.

  • What if somebody clicked and only realised later?

    You want that report far more than you want the earlier one you did not get. NCSC's guidance is to support people who click and later suspect something was wrong, rather than treating the moment of realisation as an admission of guilt. The hours between a click and a report are usually where the loss is decided, and they are entirely determined by how safe reporting feels.

  • Do we have to report incidents to a UAE authority?

    Check your own obligations rather than relying on a general article. The UAE data protection law requires notification, and our PDPL guide sets out our position carefully, including what we could not confirm. We are not publishing a deadline in hours or a penalty figure, because no executive regulation establishing either has been published. If you are in a regulated sector, your regulator's rules will be more specific than the general law.

  • Does ISO 27001 require awareness training?

    Awareness is part of what a management system covers, and if you are pursuing certification your auditor will expect to see a programme with evidence. Our ISO 27001 guide covers the certification path and what the audit actually examines. Do not build your awareness programme to satisfy an auditor, though. Build it to change behaviour, and the evidence for the auditor falls out of it.

  • How often should training happen?

    Regularly and briefly, rather than annually and at length. A single long session once a year is the format that suits compliance records rather than memory. Short, frequent, role-relevant material works better, particularly for the small number of roles that actually get targeted: finance, payroll, executive assistants, and anyone who can change bank details or approve payments. Frequency matters more than duration, because the point is keeping the reporting habit alive rather than transferring knowledge once.

  • Who should we train first?

    The people who can move money or change where it goes. Attackers target roles, not headcount, so a finance team of four matters more than a warehouse team of forty for this specific risk. Start with finance, payroll and whoever supports the executives, give them the payment verification rule as a process rather than as advice, and expand from there.

  • Should we deliver this through an LMS?

    If you already have one, yes, and if you do not, that is a separate decision from whether to run a programme. Our corporate LMS guide covers platform choice, delivery and record keeping. The platform question is genuinely secondary here: a well-run programme delivered by email and a short monthly team session beats a badly designed course nobody finishes on expensive software.

  • What does a programme cost?

    An awareness programme with simulations starts from around AED 3,000 a year for a small team with us, and a review of your payment verification process starts from around AED 2,500. These are our own figures rather than a market survey, since no government body or standards organisation publishes rates for this work. Final pricing depends on headcount and how many roles need role-specific material.

  • Is training better value than technical controls?

    Usually not, if you have to choose. Moving from SMS codes to phishing-resistant multi-factor authentication and writing a mandatory out-of-band verification rule for payment changes will do more for most UAE SMEs than another year of courses, and both are one-off pieces of work with permanent effect rather than a recurring spend. Training is worth doing alongside those, because it is what builds the reporting culture the controls cannot create. It is a poor substitute for them.

  • What should we do first, this month?

    Write the payment verification rule and tell your finance team it is mandatory. Then check what your second factor actually is, and move the accounts that can approve payments off SMS. Then set up a one-click reporting route and thank the first person who uses it. Those three things cost very little and address the way the money actually leaves.

SKIMBOX Team

Tech Consultancy

Get fresh writing in your inbox

One email a fortnight. No filler.

By subscribing, you agree to our privacy policy.

Want us to build something?

We work with teams across MENA, UK, USA, and India to build products, run programs, and grow.

Get in touch

Continue reading