Phishing defence: why training alone is not enough
KINNEX Team5 min read
Phishing works because it targets people. Training is worth doing, but expecting everyone to spot every message is not a plan.
Stop it before it arrives
Use an email security gateway or built-in protection with link rewriting, attachment sandboxing and impersonation detection. Tune it for executives, finance and HR, who are targeted most.
Make your domain hard to spoof
Publish SPF, DKIM and DMARC for your domains and move DMARC towards enforcement. This protects customers and partners from spoofed mail that uses your name.
Reduce what a click can do
Multi-factor authentication limits the damage of a stolen password. Conditional access, least privilege and endpoint protection limit what an attacker can do next.
Make reporting easy
A one-click “report phishing” button turns users into sensors. Respond quickly and thank people. Fear of blame stops reporting.
Train usefully
Short, regular lessons based on real examples beat an annual lecture. Simulated phishing is useful for learning, not for punishing.
Prepare for the bad day
Know how to reset a compromised account, search and purge a malicious message from every mailbox, and review sign-in logs for the account.
Measure
Track the share of messages blocked, the report rate, and the time from first report to removal.