Cybersecurity

Phishing awareness for the staff of small businesses in Nice

Making a team phishing-aware comes down to three things: a simulated phishing campaign, calibrated on your line of work and strictly anonymous; a one-hour workshop that starts from the results of that campaign; and a written procedure, put up on the wall, saying who to report a suspicious message to and what to do in the ten minutes after a click. A second campaign three months later measures the real progress.

Why is phishing still the main way in?

Because it does not target the machine but the person in a hurry. A fake email from a supplier changing its bank details, a fake message from the director asking for an urgent transfer, a fake delivery notification: no anti-virus blocks a deliberate action taken by the user, with their own credentials, on a site that looks like the real one.

It is also the cheapest door to close. Where bringing an estate back up to standard needs a budget and a timetable, awareness produces a measurable effect within a few weeks — and it benefits every other protection, since it cuts the number of incidents to deal with.

How does a simulated phishing campaign work?

We send fake phishing emails calibrated on your line of work — a fake supplier invoice, a fake message from the director, a fake bank notification — and we measure who clicks, without ever naming anybody. What you receive is a rate, together with an analysis of the scenarios that worked and of those that fooled nobody.

The scenarios are matched to the sector: a fake transfer for an accountancy practice, a fake delivery for a shop, fake IT support for a manufacturing firm. A generic campaign measures nothing useful: it is the plausibility that gives the result its value.

The anonymity of the results is not a formality: a campaign experienced as a trap set by management destroys trust and makes the second exercise pointless.

What does the one-hour workshop cover?

It starts from the results of your own campaign, not from generic slides. One hour, on site in Nice or by video call, to learn to spot a forged sender address, to check a link before clicking, and to handle an urgent request for a transfer — the scenario that costs small businesses the most.

The workshop ends with the most useful rule of all: when in doubt, pick up the telephone and call the sender on a number you already know, never on the one given in the message.

  • Spotting a forged sender address and a misleading display name.
  • Checking a link before clicking, on a computer as well as on a mobile.
  • Handling an urgent request for a transfer or a change of bank details.
  • Reporting a suspicious message without fear of being blamed.

What should you do after an unfortunate click?

Follow a written procedure, put up on the wall and prepared in advance: who to report a suspicious email to, and what to do in the ten minutes after a click. Those ten minutes are often worth more than the rest of the arrangements put together: change the password concerned, tell the named contact, check the forwarding rules created in the mailbox, warn the accounts team if a transfer is in progress.

The procedure fits on one page. It names a person, not a department, and it states explicitly that reporting quickly will never be held against anybody. A firm where people dare not report finds out about its incidents weeks too late.

How much does awareness training cost, and when should you measure again?

The session is charged as a fixed fee. A second campaign three months later measures the real progress: it is that comparison, not the initial rate, that says whether the exercise was worth it. In the small businesses we support, the click rate falls sharply between the first and the second campaign.

It is the cheapest action in a security plan, and often the most profitable. Repeating it once or twice a year is worthwhile, particularly after new people join the team.

Frequently asked questions

Phishing awareness: what we get asked

Are the employees who click identified?

No, never. We measure an overall rate and the comparative effectiveness of the scenarios, not individuals. That is a condition of the exercise: a campaign experienced as a trap set by management destroys trust and makes the second one pointless. The report you receive contains no names.

How much time does it take?

One hour per group for the workshop, and nothing more for the campaign, which runs during normal work without anybody being warned. The reporting procedure fits on a single page on the wall. That lightness is deliberate: a heavy arrangement is never repeated the following year.

How often should it be repeated?

A second campaign three months after the first measures the real progress, after which once or twice a year is enough, particularly after new people join the team. What counts is the comparison between two campaigns, not the rate of a single isolated one.

Do you adapt the scenarios to our sector?

Yes, and that is what makes the result worth having. A fake transfer for an accountancy practice, a fake delivery for a shop, fake IT support for a manufacturing firm, a fake booking for a hotel. A generic scenario fools nobody and therefore measures nothing useful.

How many of your colleagues would click?

The free audit includes the scoping of a first campaign, on site in Nice, Sophia Antipolis, Cannes or Monaco.