
The best use of a small or mid-sized company’s limited security budget is a combined program: contextual phishing simulations rated for difficulty using the NIST Phish Scale, a one-click reporting workflow, and phishing-resistant MFA layered on top, following CISA guidance and frameworks like ArchiTECH MSP’s six-step model. This week, enable organization-wide MFA and publish a one-line reporting instruction: “See something suspicious? Forward it to security@yourcompany.com, no explanation needed.”
TL;DR:
- Implement role-specific phishing simulations rated with the NIST Phish Scale to reflect varying employee risks and improve realistic training outcomes.
- Enforce organization-wide phishing-resistant MFA, prioritizing FIDO-based authentication, and publish simple, clear reporting instructions to encourage employee participation.
- Roll out technical controls in phases, including SPF, DKIM, DMARC, and disabling legacy protocols, to reduce email-based attacks and prevent BEC schemes.
- Measure training effectiveness through contextual metrics such as report rates and time-to-first report, not just click rates, to accurately assess risk reduction.
- Pair technical controls with ongoing simulations and quick incident response procedures, focusing on continuous review and role-based targeting for maximum impact.
Building a Phishing Awareness Training Program That Fits Your Team
Most phishing awareness training fails for one reason: it treats every employee like they face the same risk. Your accounts payable clerk and your warehouse supervisor are not the same target, and your curriculum shouldn’t pretend otherwise.
Start with two or three measurable objectives, not five vague ones. Pick targets like reducing business email compromise exposure, raising your internal reporting rate, and shrinking time-to-report on suspicious messages. Those three map directly to what actually stops fraud: someone catching a bad email fast and telling IT before money moves.
Segmenting by role comes next. Finance and HR staff need lures that mirror wire-transfer requests and W-2 scams. Warehouse and field staff need texts and voicemail-style vishing scenarios. Executives need deepfake and impersonation content, a category CISA’s training catalog now treats as standard curriculum, not an edge case.

Here’s where the NIST Phish Scale earns its place. It rates simulated phishing emails on cues (grammar, urgency, sender mismatch) and premise alignment (how closely the lure matches someone’s actual job). A highly realistic invoice scam sent to accounts payable will produce a higher click rate than a sloppy prize-notification email sent company-wide, and that’s not a training failure. It’s the scale doing its job.
A workable cadence looks like this:
- Baseline simulation in month one, low to medium difficulty, to establish where you stand.
- Monthly micro-simulations after that, rotating difficulty and lure type.
- A quarterly “hard mode” test aimed at high-risk roles.
- An annual policy refresher tied to your compliance calendar.
Reporting has to be nearly effortless or nobody uses it:
- A one-click report button inside Outlook or Gmail.
- Automatic routing to the helpdesk queue for triage.
- A trigger that escalates to incident response the moment a real threat is confirmed.
Pro Tip: Never publish results by name. A leaderboard of who clicked what turns your best early-warning system, the reporting habit, into something people hide from. Praise reporters publicly; handle repeat clickers privately with coaching, not consequences.
Which Technical Controls Actually Reduce Phishing Risk?
Training reduces risk. Technical controls remove entire categories of it. Prioritize in this order.
Phishing-resistant MFA first. CISA identifies FIDO-based authentication as the only widely available method that blocks credential replay on a fake login page, because the cryptographic key never leaves the device and can’t be phished the way a text-message code can. FIDO is already built into most modern browsers and phones, so the barrier is usually policy, not hardware.
Email authentication second. SPF, DKIM, and DMARC together verify that mail claiming to be from your domain actually is. Add external sender banners so employees see a visible flag on outside mail, and pair that with a clear anti-phishing policy so people know what the banner means.
Admin hardening third. A few settings close the gaps attackers rely on most:
- Block automatic external forwarding rules, a favorite BEC persistence trick.
- Disable legacy authentication protocols like POP and IMAP that skip MFA entirely.
- Log and alert on mailbox rule changes and new forwarding setups.
That last point isn’t theoretical. IC3 traced more than $2.1 billion in losses between 2014 and 2019 to BEC schemes that exploited cloud email services, often using exactly these gaps: quiet forwarding rules and legacy protocols nobody had turned off.
An MSP typically rolls these out in phases rather than flipping every switch at once. Pilot MFA and DMARC enforcement with a high-risk department first, usually finance, watch the telemetry for a few weeks, then expand company-wide once you’ve confirmed nothing broke. It’s slower than a blanket rollout, but it avoids the helpdesk meltdown that comes from locking out half the company on a Monday morning.
How Do You Measure If Phishing Training Is Working?
Click rate is the metric everyone tracks and the one most likely to mislead you. A rising click rate on harder simulations isn’t decay. It might mean your program finally graduated from easy lures to realistic ones.
Track these instead of obsessing over one number:
- Click rate, but only alongside the simulation’s Phish Scale difficulty rating.
- Report rate, the share of employees who flagged the email instead of clicking or ignoring it.
- Time-to-first-report, how fast the first person alerted your team.
- Repeat clickers, a small group that needs targeted coaching rather than another company-wide module.
- Protective stewards, employees who consistently report before anyone clicks. Every organization has a handful; they’re worth identifying and thanking.
Contextualize everything through the NIST Phish Scale before you present numbers to leadership. A 30% click rate on a Phish Scale “high difficulty” lure aimed at finance is a very different story than the same number on an easy, generic simulation.
Temper your expectations honestly. A large-scale reproduction study covering more than 12,000 participants found little to no significant effect of individual training modules on click or report rates. The value showed up elsewhere: faster reporting and a broader organizational “inoculation” effect, where enough people know the drill that suspicious emails get flagged quickly even without perfect individual recall. Pair those human metrics with technical telemetry, blocked-email counts, quarantine logs, and failed-login attempts, for a picture that actually reflects your risk posture.
Your First 30, 60, and 90 Days
Days 1 through 30: Turn on organization-wide MFA, prioritizing FIDO-based methods where devices support it. Publish a one-line reporting instruction everyone can follow without training. Configure external sender banners. Run a low-difficulty baseline simulation to see where you stand.

Days 31 through 60: Scale simulations to monthly cadence with mixed difficulty. Apply DMARC enforcement (not just monitoring mode). Disable legacy authentication protocols. Train your helpdesk on triage steps so reported emails get assessed within hours, not days.
Days 61 through 90: Analyze click and report data against Phish Scale ratings, not raw numbers. Present a short report to leadership with difficulty-adjusted context. Schedule recurring quarterly refreshers so this doesn’t become a once-a-year fire drill.
- Assign an owner for each phase: IT for controls, HR for communications, leadership for sign-off on policy.
- Draft a sample pre-simulation notice at the policy level (never announcing specific test dates).
- Build a one-paragraph post-incident template for the helpdesk to use when a real phishing report comes in.
How ArchiTECH MSP Applies This Blueprint
Awareness training doesn’t sit alone in ArchiTECH’s approach. It’s one stage inside a six-step security framework that also covers risk assessment, technical hardening, monitoring, incident response, and ongoing review, built that way because training without the technical backstop just delays the inevitable click.
A phishing simulation that never gets paired with MFA enforcement and email authentication is a fire drill in a building with no sprinklers. It teaches people to notice smoke. It doesn’t put the fire out.
ArchiTECH’s clients get that pairing from day one: role-based simulations calibrated with Phish Scale style difficulty context, alongside MFA rollout, SPF/DKIM/DMARC configuration, and a reporting pipeline that routes straight into incident response. That structure is part of why the firm maintains a zero-major-incident track record across its client base.
Pro Tip: If your current provider only offers a training video with a quiz at the end, ask what happens after someone reports a real phishing email. If the answer is vague, the training piece is disconnected from your actual defense.
What I’d Prioritize If I Only Had Time for One Thing
Phishing-resistant MFA plus a friction-free reporting habit beats any standalone training module. Do that first. Expect click rates to look messy for months as your simulations get harder before leadership sees the payoff in faster reporting and fewer successful compromises. That tradeoff is the program working, not failing.
— Tyson
Get Phishing Defense and Awareness Training Set Up Right
ArchiTECH builds security in from the start instead of bolting it on after something goes wrong, which is the gap most SMBs discover the hard way. Our cybersecurity services include security awareness training, MFA rollout, dark web monitoring, and incident response, all organized around the same six-step framework referenced throughout this guide, so training, technical controls, and response actually talk to each other instead of living in separate vendor contracts.

Getting started doesn’t require ripping out your current setup. A free cybersecurity assessment shows you where your phishing exposure actually sits, from MFA gaps to email authentication holes, before you spend a dollar on a training platform. If you’d rather have one team own both the awareness side and the technical defense, our managed IT services fold co-managed IT and 24/7 monitoring into the same engagement. Request the assessment and you’ll get a prioritized punch list, not a sales script.
Where to Verify This Guidance Yourself
- CISA: Teach Employees to Avoid Phishing — no-cost training resources
- IC3 BEC Guidance — reporting and response steps
- Reproducibility study on training effectiveness
Sources
- Teach Employees to Avoid Phishing - CISA
- IC3 PSA — Business Email Compromise (BEC)
- Anti-Phishing Training (Still) Does Not Work: A Reproduction of Phishing Training Inefficacy…
FAQ
How Often Should We Run Phishing Simulations?
Monthly micro-simulations work best for most SMBs, with a baseline test in month one and a harder quarterly test for high-risk roles like finance. Frequency matters less than variety: rotating lure type and difficulty, guided by the NIST Phish Scale, keeps employees from just memorizing your test format.
Does Phishing Awareness Training Actually Work?
It works differently than most people expect. A large reproduction study found little measurable effect on individual click rates, but organizations still benefit through faster reporting and a broader “inoculation” effect where enough staff recognize red flags to catch threats early. Pairing training with technical controls like MFA closes the gap training alone leaves open.
What Should We Do Immediately After a BEC Incident?
Contact your financial institution immediately to attempt to halt or reverse any fraudulent transfer by following how to secure corporate banking: a step-by-step guide, then file a complaint with IC3. Internally, trigger your incident response process right away and check for unauthorized mailbox forwarding rules, a common sign of ongoing compromise.
Why Do Our Click Rates Go Up After We Improve Training?
A rising click rate often means your simulations got harder, not that your employees got worse. Rate each simulation against the NIST Phish Scale difficulty before comparing month to month, and track report rate and time-to-report alongside it for real context.
How Much Should a Small Business Budget for This?
Costs vary by company size and whether you handle training in house or through a managed provider; ArchiTECH’s security awareness training pricing is available on request after a free assessment of your current exposure. Budgeting typically covers simulation platform costs, MFA licensing, and staff time for review and remediation.