• Home
  • About Us
  • Courses
  • Membership
    • Registration
  • Events
  • Blog
  • Contact
  • Home
  • About Us
  • Courses
  • Membership
    • Registration
  • Events
  • Blog
  • Contact
RegisterLogin

Blog

  • Home
  • Blog
  • Blog

Day 9: Phishing Simulation and Awareness

  • Posted by IFIS TEAM
  • Date October 9, 2026
  • Comments 0 comment

The CFO arrived late, carrying the kind of silence that makes an executive committee stop checking phones. “We have lost money.”

Nobody spoke. The room went silent you could hear even a pin drop.

The first number was UGX 1.8 billion. By the time Internal Audit joined the meeting, the suspected exposure had climbed higher. Payments had left through legitimate banking channels. The approvals appeared genuine. The suppliers existed. The emails looked normal.

The attack had entered through email. I have sat in enough crisis rooms to know what happens next. Technology gets blamed first. The CIO is asked why all the investments in SOC, cybersecurity and all the firewalls failed. Cybersecurity investigates. Finance freezes payments. Someone asks whether insurance will cover the loss.

Then the facts become worse. Three weeks earlier, an accounts officer had received an email from a regular supplier. The supplier said its bank account had changed. The message used familiar language, referenced a real invoice and copied people who usually appeared in the thread. It had even been flagged by the internal system as coming from “someone outside the organisation.” But none of this helped.

Finance updated the account. Payment followed. The email was fake. Not badly written fake. Not the old “Dear Customer, click hear immediately” nonsense still used in awareness presentations. This was patient, contextual and believable. The attacker had researched the relationship, understood the payment cycle and entered the conversation at the right moment. Had used generative AI to craft a message that resonates with the kind written by the company.

Then EXCO learned something more disturbing.

Two employees had noticed the message looked unusual.

Neither reported it.

That is where most phishing programs fail.

We train employees to identify suspicious emails as though cybersecurity were an examination. We teach spelling mistakes, strange links, unknown senders and attachments. Then we run a simulation, count who clicked and congratulate ourselves when the percentage falls.

That model is obsolete today.

The objective is not to create employees who pass phishing tests. The objective is to build an organisation that is difficult to deceive.

What we are told to do is run annual awareness training, test employees and report the click rate.

What we actually must do is test the entire chain from deception to business loss.

In this company, the real failure was not one click. Someone trusted the email. Someone changed supplier details. Someone approved payment. Nobody verified the change through an independent channel. Nobody escalated the anomaly. The organisation failed as a system.

That is the first shift: start with the money, data or decision an attacker wants, then work backwards. If the crown jewel is cash, simulate supplier-bank-change fraud. If the crown jewel is privileged access, simulate a password reset request.

If executives hold sensitive acquisition information, simulate a board document. Phishing awareness should mirror the business model. The second shift is more controversial.

Stop treating click rate as the main measure of success.

A staff member can click a malicious link and report it thirty seconds later. Another may recognise the attack, delete the email and tell nobody. Which employee is more useful?

I want to know how fast employees report, how quickly security sees the alert, whether the same message can be removed from other inboxes, whether compromised credentials are disabled and whether finance can stop the transaction.

The third shift is cultural.

Phishing exploits hierarchy almost as effectively as technology.

The attacker says, “The CEO needs this urgently.”

A junior employee thinks, “Who am I to question the CEO?”

Now we have a cybersecurity weakness created by culture.

I once watched a senior executive become irritated when someone suggested employees should independently verify his unusual payment instructions. He thought it undermined authority.

It did the opposite.

A strong executive should want employees who challenge unusual instructions respectfully. A company where nobody questions the boss is a beautiful hunting ground for a fraudster.

Back in the EXCO room, the investigation revealed that the attackers had not defeated sophisticated technology.

They had defeated routine.

The supplier-change process relied too heavily on email. Reporting suspicious messages was cumbersome. Employees feared embarrassment if they raised a false alarm. The annual cyber course had been completed by nearly everyone.

Compliance looked excellent. Resilience was poor. So the company changed the question.

Instead of asking, “How many employees completed training?” management began asking, “If a convincing attack starts at 9:00 tomorrow morning, how many minutes before we know?”

Run realistic simulations. Train immediately after failure. Make reporting one click. Test finance, HR, procurement and executives differently. Verify sensitive transactions outside the original communication channel. Reward early reporting. Retest relentlessly.

The most dangerous phishing email your organisation receives may contain perfect grammar, the correct logo, the right names and information only insiders appear to know.

Your defence cannot depend on spotting ugly emails. It must depend on disciplined people, strong processes and fast detection.

That morning, EXCO thought it was investigating an email problem.

By lunchtime, the truth was unavoidable.The real vulnerability was the organisation itself. And that is exactly what a good phishing simulation should reveal before a criminal does.

Copyright Institute of Forensics & ICT Security, 2026. All rights reserved.

  • Share:
IFIS TEAM

Learn By Doing. We offer practical training to individuals and corporate entities who demand the very best.

Previous post

Day 8: Security Operations Centre (SOC) 101
October 9, 2026

You may also like

c3f7f91b3f133cd761e8a4d9a29a256b
Day 8: Security Operations Centre (SOC) 101
October 8, 2026
0b0242a0ee00c9041a154ad1f937cfa3
Day 7: AI in cybersecurity: threat detection and response
October 7, 2026
bc58441a6deab65d14e47cd02927e069
Day 5: Cybersecurity Awareness Month, 2026: championed by forensicsinstitute.org in Uganda.
October 5, 2026

Leave A Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Courses

Protected: Why IFRS 9 Matters for URA

Protected: Why IFRS 9 Matters for URA

Free
Internal Audit Core

Internal Audit Core

$1,120
Certified Fraud Forensic Professional

Certified Fraud Forensic Professional

$1,120

At IFIS, we live by our motto. Every course, certification, and training session emphasizes practical, hands-on skills that empower you to solve real-world challenges from day one. Learn by doing. Be empowered to transform your career and life.

Facebook X-twitter Youtube Instagram

Quick Links

  • Home
  • About Us
  • Courses
  • Membership
    • Registration
  • Events
  • Blog
  • Contact
  • Home
  • About Us
  • Courses
  • Membership
    • Registration
  • Events
  • Blog
  • Contact

Contact Us

  • admissions@forensicsinstitute.org
  • +256 783373637
  • +256 782 610333
  • Strategy Place, Trinity Building, Block 216, Plot 2475, Kayondo Road, off Ntinda–Kiwatule Road, Kalinabiri, Ntinda, P.O. Box. 40292, Kampala.
  • Privacy Policy
  • Terms & Conditions

© 2026 – Forensic Institue. All rights reserved.

Login with your site account

Lost your password?

Not a member yet? Register now

Register a new account

Are you a member? Login now