Most successful attacks on Australian small businesses don't start with someone breaking through a firewall — they start with someone clicking a link. Phishing works because it targets people, not systems, which means your best defence is a team that can recognise a suspicious message and knows what to do next. That's a training problem, and it's very trainable.
Why phishing keeps working
A phishing email is a message designed to trick the reader into doing something harmful: entering their password on a fake login page, opening a malicious attachment, or paying an invoice to the wrong account. It succeeds because it borrows trust — it looks like it comes from your bank, the ATO, Microsoft, a supplier, or your own boss — and because it manufactures a reason to act quickly, before the reader stops to think. The more time-pressured and emotionally charged a message feels, the more suspicious it deserves to be.
The Australian Signals Directorate's Essential Eight lists mitigations like multi-factor authentication and application control precisely because human error is expected. Training doesn't replace those controls; it's the layer that catches what technology can't.
The red flags to teach
You don't need your team to become security experts. You need them to notice a handful of recurring tells and pause when they see one.
- The sender address doesn't match the display name. "ATO" in the name means nothing; the actual address after the @ is what counts. Teach people to expand and read it.
- Urgency and threats. "Your account will be suspended," "pay within the hour," "final notice." Legitimate organisations rarely operate this way.
- Links that don't go where they claim. Hovering over a link (without clicking) reveals the real destination. A mismatch between the visible text and the actual URL is a strong signal.
- Requests for credentials or payment. Any email asking someone to log in via a supplied link, or to change bank details for a payment, deserves independent verification.
- Unexpected attachments, especially ones that ask you to "enable content" or "enable macros".
- Slightly-off language, logos, or formatting, and greetings that are oddly generic for someone who supposedly knows you.
The one habit that matters most
If you teach your team a single behaviour, make it this: verify out of band before acting on any request for money, credentials, or a change to payment details. That means confirming through a channel other than the email itself — phoning the supplier on a number you already have, walking over to the colleague who supposedly sent the request, logging into a service by typing the address yourself rather than clicking a link.
This one habit neutralises the most expensive attack most SMEs face: business email compromise, where an attacker impersonates a supplier or an executive to redirect a legitimate payment. No red-flag spotting is perfect, but a standing rule that bank-detail changes are always verified by phone closes the gap.
Making the training stick
A single induction slide won't change behaviour. What works is little and often.
- Run short, regular refreshers rather than one annual session — a ten-minute team discussion of a real example lands better than an hour of slides.
- Use real examples your business has actually received. Nothing teaches faster than "here's the one that came to us last week."
- Make reporting easy and blameless. Give people one obvious way to report a suspect email and thank them when they do — even for false alarms. The moment reporting feels like admitting a mistake, people stop doing it.
- Consider a simulated phishing exercise once your basics are in place, so you can see where the gaps are without a real attacker finding them first.
Back the training with controls
Training reduces clicks; controls reduce the damage when a click happens anyway. The two work together. Multi-factor authentication means a stolen password alone often isn't enough. Keeping software patched closes the holes malicious attachments try to exploit. Restricting who can install applications limits what a compromised account can do. These map directly to the Essential Eight and are worth implementing alongside your awareness programme rather than instead of it. Our Operations hub covers how the technical side fits into a well-run back office.
Phishing awareness isn't a project you finish — it's a habit you maintain. This is general information; for guidance tailored to your environment, the ASD's cyber.gov.au resources and a trusted IT provider are good starting points.
About the author
Andrew Northcott
Founder & Chairman, Valont
Andrew is the founder and chairman of Valont and the parent group Wattlestone. He has spent two decades building and running Australian SMEs, and writes about the realities of ownership — cash, people, systems, and the decisions that compound.
LinkedIn →