Most companies do security training once a year. A video, a quiz, a checkbox in a compliance folder. Then everybody goes back to work for 12 months while the people trying to get in keep iterating every week.

Three attempts landed on my company in the last 30 days. Every one of them looked like ordinary business.

The $74,000 invoice that went to the CEO first

Late July. An email came in with the subject line INV(81950234), a PDF attached, and a line referencing a request from our CEO by name. It arrived as a reply chain with previous correspondence quoted underneath, sent from a real person at a real company.

It went straight to the CEO. He read it as an invoice, because that is exactly what it looked like, and he forwarded it to our finance guy to handle. Normal Friday.

Finance opened the PDF. Then he saw the number. $74,000. That's what made him stop and ask whether the thing was real, and by then the file was already open.

His next question is the one I hear every single time:

“The invoice is a PDF, there's no link. Do you think it will still hack my email?”

That question is the actual problem. He knew enough to worry and not enough to know what to do.

One detail in that thread gave the whole thing away. The sending domain was one letter off from ours. One character. At 1pm on a Friday with a $74,000 invoice in front of you, nobody reads a domain letter by letter.

I saw the thread and called Omar, our Tech Specialist and Performance Leader in the Philippines. We picked the plan of action on that call and he ran it: reset the password, revoke every active session, delete the MFA registration so it had to be built again from scratch.

Under an hour from the click to contained. That hour existed because two people had to get on a call and decide. Written down in advance, it's ten minutes.

The subpoena that showed up on my calendar

August 21. A calendar invitation from a law office I'd never heard of. “Urgent: Subpoena and Court Hearing, Immediate Attention Required.” Google Meet link, dial-in number, PIN. It opened with “Dear Counsel.”

I'm not a lawyer, and I know a real subpoena doesn't show up in my email. It comes as a letter in the mail.

What got my attention was the delivery. Nobody emailed me anything. Somebody put an event on my personal calendar with a link inside it to review subpoena and hearing documents, and I never accepted the invitation. It was sitting there anyway.

That's where the creativity is going. Calendar invites. Shared documents. Meeting links. Channels your staff has never once been trained to distrust, because two years ago nobody was coming through them.

What a phishing simulation actually is

A phishing simulation is a fake attack you send your own people on purpose. Same fake urgency, same fake sender, same fake button as the real thing, except the click gets logged instead of exploited and the person who clicked gets training while it still stings.

We have one going out to 176 people this week.

The lure is an HR email. Employee Benefits Center. Back-to-school allowance, up to $250 per dependent for the school year, confirm your eligibility before the claim window closes Wednesday. Reference number at the bottom, and a polite line asking you not to forward it because allowances are issued per employee.

It works on the part of your brain that handles paperwork. The annual training video teaches people to be suspicious of threats and warnings. This one is a favor with a deadline on it.

We run ours through IRONSCALES, which is the platform we already use for email security. Any of the tools in that category will do the same job: send the simulation, log who clicked, put training in front of them the same day.

What you're actually buying

Owners fixate on the click percentage. Three things matter more than that number.

Reps against current tactics. Your staff can spot a Nigerian prince and a fake shipping notice in their sleep. A quoted reply chain from a real vendor is new. A court summons on the calendar is new. Every test you run adds one more pattern their gut recognizes at 4:45 on a Friday.

A response that's already been rehearsed. Somebody will click. The only open question is whether the next twenty minutes are already decided: password, sessions, MFA, and one named person who gets told. Ours took an hour because we built the plan live on a phone call. Yours takes ten minutes if it's written down.

People willing to raise their hand. Our finance guy said “I did” out loud, on a thread with four people watching. That's worth more than a clean click rate. When staff believe that admitting a mistake gets them written up, they sit on it, and a compromised mailbox goes from an hour of exposure to three weeks of it.

Which gives you the one rule you can't break. Never punish the person who clicks. The day testing becomes a performance review, you've paid for a tool that makes your company less safe.

If you run a 12-person agency

This works at any size, and it works with zero security staff.

Run a simulation monthly. Quarterly if monthly feels heavy. Rotate the lure so it isn't the same fake invoice every time, and put the owner and the producers on the list. Leadership gets targeted hardest, because leadership can move money.

Write your response steps on one page. Reset the password, kill the sessions, re-register MFA, tell one specific person. Tape it inside a drawer if that's what it takes.

Then add the two habits that catch the current wave. Read the sending domain letter by letter on anything involving money. Treat a calendar invite from a stranger the way you'd treat an attachment from one.

This sits alongside everything else in your tech stack, and it runs on the same clean data the rest of your systems depend on.

Your E&O carrier will start asking about this if it hasn't already. My reason is simpler. A $74,000 invoice landed in a thread that looked completely ordinary, and it cost us nothing because one person finally asked a question and another person knew what to do next.

Training once a year prepares your staff for the attacks of a year ago.

Questions I get about phishing simulations

How often should we run phishing tests?

Monthly is the target. Quarterly beats annually by a mile. The cadence matters more than the platform you use.

What's a good click rate?

The trend beats the number. A team going from 20% to 8% over six months is working. A team frozen at 4% is probably getting easy lures.

Should we tell employees we're testing them?

Tell them the program exists and why. Don't announce individual campaigns. A test everybody's expecting measures nothing.

Does this make sense for a 5-person agency?

Yes, and arguably more. Five people means the person who approves wire transfers is also the person answering the phone.

What do we do the moment someone clicks?

Reset the password, revoke active sessions, force MFA re-registration, and check sent mail and forwarding rules. Decide who owns those four steps before you need them.