Two years ago, it was enough to teach people to spot strange Portuguese and badly written email addresses. Today, the phishing email is well written, the phone call features the voice of the Chief Financial Officer and the urgent video call shows the face of the CEO asking for a transfer. Fraud technology has improved; most companies' training has stayed in 2019. This article explains what has changed and how to train a team realistically — without two-hour sessions that no one retains or rules that no one follows.
What changed: from the poorly written message to the perfect imitation
Three things. First, the text: fraudulent emails are now written in correct Portuguese, with the tone and signature of the person they are imitating. Second, the voice: with a few seconds of public audio (an interview, a LinkedIn video) it is possible to generate a call using a director's voice asking for “something urgent”. Third, the image: video calls with faces generated in real time have already been used to authorise transfers in European companies. The common denominator is not the technology — it is urgency and a authoritysomeone important needs something now, outside the normal procedure.
Rule zero: the procedure overrules the person
If training only teaches how to detect fraud, it will fail, because some fraud is undetectable. What works is a rule that doesn't depend on detecting anything: payment requests, changes to bank details or the sending of sensitive data are always confirmed via a second channel, using a previously known contact. Received an email from a supplier with a new IBAN? Call the number that is on the contract, not the one in the email. Did the CEO ask for a transfer via video call? Confirm by phone using his number. If the rule is absolute and management follows it too, the quality of the imitation no longer matters. This rule is at the heart of our analysis of the altered invoice fraud.
Training that works: short, frequent and with real-life examples
An annual two-hour session has almost zero retention after a month. What works is the opposite: 15 to 20-minute sessions every two or three months, each focused on a single topic (email, calls, video calls, social media, USB sticks and files). Always with real examples — ideally actual attempts that reached the company itself, anonymised. People remember “that email Ana received pretending to be from EDP”, not a generic slide.
Phishing simulations: yes, but without humiliating
Sending simulated phishing emails to the team is the most effective way to measure and improve. Two rules. First: whoever clicks receives a short, immediate explanation, never a public reprimand — the aim is for people to report without fear, and fear makes them hide. Second: you measure the rate of report, not just the click-through rate. A company where 5% clicks but 60% reports is safer than one where 2% clicks and nobody reports it. Start with one simulation per quarter and gradually increase the difficulty.
The report button
The team needs a way to report in two seconds: a button in Outlook or an internal address known to everyone. And it needs feedback: whoever reports must know, on the same day, whether it was fraud or not. Without feedback, people stop reporting after a month. With feedback, the team turns into the company's best security sensor — faster than any filter.
Training for deepfakes: what to tell people
- A call or video call can be fake even if the voice and face are the right ones. This is not paranoia; it is the current state of technology.
- Useful but insufficient signs: out-of-procedure request, haste, request for confidentiality (“don't tell anyone”), refusal to use the usual channel.
- The answer is always the same: “I'll confirm with you shortly via the usual channel” — and they hang up. No legitimate person takes offence at this. If management says this out loud in the training session, the team will start doing it without fear.
- Verbal passcode for financial requests between management and finance: simple, free and effective.
The targets that deserve extra training
Finance and accounting (transfers), human resources (personal data, salary account changes), reception and executive assistants (access to diaries and “on behalf of” requests), and management itself — which receives the most personalised attacks and attends training the least. In the embassies, clinics and hotels we work with, reception is frequently the first target, because it answers whoever calls.
The technical part that reduces what reaches people
Training is the last line, not the first. Before it: email filtering that flags external messages and blocks executable attachments, domain authentication (SPF, DKIM and DMARC) to make it harder for someone to send emails on behalf of the company, and multi-factor authentication to prevent a stolen password from getting through. In our contracts managed cybersecurity these layers are configured and team awareness is part of the service.
Frequently Asked Questions
How often should training be undertaken?
Short sessions every two or three months work better than one long session a year. A phishing simulation per quarter keeps the topic front of mind.
Don't the simulations create mistrust in the team?
They do, if they are used to punish. If every click is followed by a two-minute explanation and the focus is on celebrating those who report, the effect is the opposite: people start talking about the issue.
How do I know if a call with my boss's voice is fake?
You don't know for sure. That's why the answer isn't to detect, it's to confirm: hang up and call back on the known number. A previously agreed verbal password resolves most cases.
Is the training mandatory by law?
GDPR requires appropriate organisational measures and NIS2 explicitly mandates cybersecurity training for covered entities, including management bodies. Even outside of those obligations, it is the most cost-effective measure.
Would you like to start with your team?
We have prepared the initial session, the first simulation and the reporting button, and we have configured email filtering and MFA so that fewer frauds reach people. See our managed cybersecurity for businesses or call 211 459 950.





































