Someone in accounts paid a fake invoice. The technical controls were bought, the antivirus was current, and the annual training was completed by everyone with a certificate to prove it.
This is the part of security that resists being solved by purchasing, and it is also the part where the advice is least trustworthy, because almost all of it is published by companies selling training platforms. What follows is drawn from the national security agencies instead, and their position is more sceptical than the sales material.
We cover the technical layer separately in our guides to small business cybersecurity and website security, and the delivery platform question in our corporate LMS guide.
Does awareness training work?
Partly, and less than you have been told. Research co-authored through NIST's human-centred cybersecurity programme found that the best predictor of phishing susceptibility was previously falling for a phishing email, and that repeat clickers did not respond to training interventions [3]. A second study it cites found a group whose failures came from interest in the subject matter and a lack of careful attention rather than a knowledge gap, and whose performance also did not improve after training [3].
The NCSC states the human side bluntly: blaming users for clicking on links does not work, because clicking stems from situational and personality factors rather than a simple knowledge gap, and asking users to examine every email in depth is unrealistic when responding to email is a core part of most jobs [1].
NIST's earlier modelling points the same way, treating the decision to comply with a phishing message as a function of context and personality rather than knowledge alone [4].
Read together, that is a more useful position than either "training is essential" or "training is useless". Training raises the floor and tells people how to report. It does not reliably stop a well-targeted message reaching a busy person at a bad moment. So the defence has to include controls that hold when the click happens anyway.
Why your click rate is not telling you what you think
NIST publishes a method called the Phish Scale precisely because organisations were drawing wrong conclusions from raw click rates. It rates how difficult an email actually was to detect, using the number and nature of cues in the message and something it calls premise alignment, meaning how closely the message matches the recipient's real role and current context [3].
The implication is uncomfortable for anyone reporting a click rate to a board. A well-targeted email aimed at a real work concern, with few detectable cues, is genuinely hard to spot regardless of training. A low click rate on an obvious lure proves nothing, and a high one on a sophisticated lure does not mean your people are careless.
NIST's guidance on building an awareness programme points at a better measure: behaviour change, specifically the percentage of participants who changed a behaviour such as reporting a suspected phishing email, and how those reports are made [2].
Report rate is the number worth putting in front of your board. It measures whether people will raise a hand, which is the thing that actually shortens an incident.
Phishing simulations, run so they do not backfire
Simulations are currently the best available source of data on real susceptibility. They are also capable of doing genuine damage, and the NCSC is unusually direct about it: they erode trust between employees and security, and employees who are afraid for their jobs will not report mistakes [1].
Two agencies arrived at the same rules independently, which is worth noting on a topic this crowded with vendors.
Do not punish individuals. The NCSC observes that punishing people for clicking on emails you sent them starts to resemble entrapment [1]. NIST states that these activities should not be punitive and that no employee should be called out for their response [2].
Do not publish names. The NCSC's point about measurement is the one to keep: metrics express an organisation's values, and if you appear to value the absence of reported problems, you incentivise people to keep quiet [1].
Tell people simulations happen. NIST's guidance is to say in advance, in general terms, that exercises run on a random ongoing basis and that results guide future learning [2].
Do not impersonate real organisations. NIST specifically flags avoiding real external brands in a lure, because it produces genuine confused contact with those third parties [2].
Baseline first, and judge difficulty honestly. NIST suggests establishing current click rates for a group or work role to see whether more targeted training is needed [2], and the Phish Scale exists to stop you comparing campaigns of different difficulty as though they were the same test.
The attack that actually takes the money
Business email compromise arrives as a credible email rather than as malware. There may be no attachment, no link, and nothing for a filter to catch. It asks for a payment to be made or for bank details to be changed, and it often follows a real conversation the attacker has been quietly reading.
CISA has documented the mechanism that makes the reading possible: attackers creating mailbox rules that move or delete messages so the legitimate account holder never sees the thread continuing without them [7]. That rule is frequently the only visible artefact sitting between the account compromise and the fraudulent invoice, which makes monitoring for new or unusual mailbox rules a genuinely high-value control.
The single most valuable thing in this article. Verify every change to payment details out of band, by calling a number you already hold, never one supplied in the message. Applied without exception, that defeats the whole category regardless of how convincing the email was or whose name was on it.
The reason it fails in practice is that it is written as advice rather than as process. If it is a guideline, somebody has to decide whether this particular message looks suspicious, and the whole point of a good lure is that it does not. Make it a mandatory step in the finance workflow, keep the contact numbers in your own system rather than in the email thread, and make it explicitly acceptable for a junior finance person to apply the rule to a director. That last part is cultural and it is the part that usually breaks.
The controls that work whether or not somebody clicks
Move off SMS codes. CISA publishes a clear hierarchy: hardware security keys using FIDO or WebAuthn are strongest, then an authenticator app with number matching, then an authenticator app with a one-time code, then biometrics, with SMS or email codes described as the weakest protection to be used only when stronger options are unavailable [5].
Understand what phishing-resistant means. CISA's position is that phishing-resistant methods such as FIDO, WebAuthn and certificate-based authentication resist phishing, and that push bombing, telecoms interception and SIM swap attacks do not apply to them [6]. That is a structural defence rather than a behavioural one, which is why it holds on the day training does not.
Know the local angle on SIM swap. SMS as a second factor depends on nobody taking over your number. The UAE has a relevant structural protection here, in that SIM registration is tied to Emirates ID and residents can check which numbers are registered in their name through the Hesabati service [11]. That makes an unnoticed swap harder than in some markets, and it is not a reason to keep using SMS.
Watch for MFA fatigue. An attacker who already has a password can simply trigger approval prompts repeatedly until somebody accepts one to make it stop, usually late at night. Number matching addresses it directly, and it is a configuration change rather than a training topic.
Name QR code phishing in training. A phishing link delivered as an image has no URL for a filter to read, and the victim scans it with a personal phone that often sits outside your protections entirely. Most people do not perceive a printed code as a link at all.
What to actually put in the training
Given all of the above, the useful content is narrower than a generic course and mostly concerns what to do rather than what to spot.
Teach the reporting route, not the warning signs. Spotting advice ages badly and does not survive a well-targeted lure. Knowing how to report, and that reporting is welcome, survives both. If people remember one thing, make it the button.
Teach the payment rule to the people it applies to. For finance, payroll and executive support, the content is a process: any change to bank details is verified by calling a stored number. That is a five-minute briefing repeated often, not an hour-long module.
Teach the shapes that filters miss. A QR code in an image, a message with no link at all asking for a favour, and a request that arrives inside a genuine ongoing conversation are the cases where technology will not help. Those are worth naming specifically because they do not look like the phishing examples people have seen.
Say out loud that clicking happens. Telling a room that some of them will click, that it is expected, and that the only wrong move is staying quiet does more for your incident response time than a module on hovering over links. It is also true, which the alternative framing is not.
Reporting is the control you are actually buying
One route, one click, no fear attached. A button in the mail client beats an address people must remember, and either beats a policy nobody has read. The NCSC runs a national reporting service on exactly this principle, noting that reporting is free and takes about a minute [8].
What happens after the first report determines your reporting rate for the next year. Thank people quickly and visibly. The NCSC's guidance is explicit about reassuring users that they will not get in trouble for reporting, including reporting after they have already clicked, and about supporting people who click and only later suspect something was wrong [1].
That last case matters more than it sounds. The hours between a click and a report are usually where the loss is decided, and how long they last is set entirely by how safe reporting feels.
A pattern we see. A UAE business runs a simulation, publishes the results by name in a management meeting, and congratulates itself on a falling click rate over the next two quarters. What actually fell was reporting. Three months later a real compromise runs for eleven days because the person who noticed the odd email assumed it was another test and did not want to be on the list again.
Reporting obligations, stated carefully
Check your own position rather than relying on a general article. The UAE data protection law requires notification, and our PDPL compliance guide sets out our position in detail, including what we could not confirm.
The UAE government publishes general cyber security guidance for businesses and residents [9], and the data protection law itself is summarised on the same official portal [10]. Neither establishes the specifics people usually want. We are deliberately not publishing a notification deadline in hours or a penalty figure here, because no executive regulation establishing either has been published, and a confident wrong number on this subject is worse than none. If you operate in a regulated sector, your regulator's requirements will be more specific than the general law, and they are the ones that will apply to you.
If you are pursuing certification, awareness sits inside what a management system covers and your auditor will expect evidence of a programme. Our ISO 27001 guide covers what the audit examines. Build the programme to change behaviour rather than to satisfy the audit, and the evidence falls out of it anyway.
Who to start with, and why headcount is the wrong unit
Attackers target roles, not people at random, so a programme organised by headcount spreads effort evenly across a risk that is not evenly distributed.
The roles that matter for this specific threat are the ones that can move money or change where it goes: finance, payroll, whoever supports the executives, and anyone with authority to approve a payment or amend a supplier record. A finance team of four is a larger exposure than a warehouse team of forty, and treating them identically is how the fourth-largest risk gets the same attention as the first.
Start there, and give that group the payment verification rule as a process step rather than as awareness content. Then extend to everyone else with something shorter and less frequent, because the goal for the wider organisation is the reporting habit rather than deep familiarity with attack patterns.
There is a second reason to start narrow. A small group is where you can afford to do the expensive part properly: sitting with the finance team, walking through how a supplier bank change actually reaches them today, and finding the step where nobody currently verifies anything. That conversation surfaces more real risk than any simulation, and it takes an afternoon.
What it costs
An awareness programme with simulations starts from around AED 3,000 a year for a small team with us. A review of your payment verification process, which is the control most likely to prevent an actual loss, starts from around AED 2,500. These are our own figures rather than a market survey, since no government body or standards organisation publishes rates for this work. Final pricing depends on headcount and how many roles need role-specific material.
For context against the rest of your security spend, a security assessment starts from around AED 5,000 and managed IT support from around AED 100 per user per month.
Our honest view on sequencing: if you have to choose, phishing-resistant authentication and a written out-of-band verification rule will do more for a typical UAE SME than another year of courses. Both are one-off pieces of work with permanent effect. Train alongside them, not instead of them.
What to do this month
- Write the payment verification rule and make it a mandatory process step, not advice
- Move any account that can approve payments off SMS codes
- Turn on number matching wherever your authenticator supports it
- Set up a one-click reporting button and thank the first person who uses it
- Check for unexpected mailbox rules across your finance and executive accounts
- Run a baseline simulation with no names published and no consequences attached
- Report your report rate to your board, not your click rate
None of that requires a platform purchase, and the first two would have stopped most of the invoice fraud we have been asked to look at after the fact.
If you would like the payment process reviewed by someone who has seen how these actually succeed, contact us.
References
[1] National Cyber Security Centre, Phishing attacks: defending your organisation. ncsc.gov.uk
[2] NIST, SP 800-50 Rev. 1: Building a Cybersecurity and Privacy Learning Program. csrc.nist.gov
[3] NIST, Human-Centered Cybersecurity: phishing research and the Phish Scale. csrc.nist.gov
[4] NIST, IR 8194: Exploratory Lens Model of Decision-Making in a Potential Phishing Attack Scenario. csrc.nist.gov
[5] CISA, Require multifactor authentication. cisa.gov
[6] CISA, Implementing phishing-resistant MFA. cisa.gov
[7] CISA, Analysis Report AR21-013A: Strengthening Security Configurations to Defend Against Attackers Targeting Cloud Services. cisa.gov
[8] National Cyber Security Centre, Report a scam email. ncsc.gov.uk
[9] The Official Portal of the UAE Government, Cyber security. u.ae
[10] The Official Portal of the UAE Government, Data protection laws. u.ae
[11] The Official Portal of the UAE Government, Telecommunications: SIM registration and the Hesabati service. u.ae



