Phishing remains the most common initial vector in South African breach reports. Annual click-through training videos rarely change that — and the data on their effectiveness is unforgiving. Effective phishing training is a behaviour-change programme: measurable, simulation-led, personalised, and operated continuously rather than annually. This article sets out what actually moves the needle.
The short answer
Effective phishing training programmes combine quarterly phishing simulations, role-specific micro-learning, and AI-assisted personalisation through platforms such as KnowBe4. Outcomes are measured by click-through and reporting rates over time, not by completion percentages. The programme is continuous, not annual.
Phishing and business email compromise increasingly affect fraud exposure, payment integrity, operational continuity, and executive trust — not just mailbox security.
Why annual training fails
Annual training videos produce completion certificates and almost no behaviour change. The reasons are well documented: skill decay is fast, single exposure is insufficient, generic content underperforms role-specific framing, and the absence of practice means the first real phishing attempt is also the first practical test. Compliance teams that report training completion as a security metric are reporting attendance, not capability.
Mature programmes build a reporting culture, not fear. Staff should feel encouraged to report suspicious activity early, without fear that mistakes will automatically result in punitive action.
What measurable behaviour change looks like
Two metrics matter — click-through rate (how many recipients fall for the simulation) and reporting rate (how many recognise and report it). Mature programmes track both monthly, segmented by role and risk tier. Targets are reductive — high-risk roles (finance, executive support, IT) should achieve a low single-digit click-through rate and a high two-digit reporting rate within 12 months.
Simulation-led learning — practice as the curriculum
Phishing simulations are the practical training layer. Done well, they use varied template themes (executive impersonation, supplier invoice, HR notification, IT credential reset), realistic difficulty progression, and immediate feedback when a user clicks. Just-in-time training — short, specific lessons triggered by a click — outperforms scheduled training for retention.
Modern phishing programmes increasingly simulate SMS phishing, collaboration-platform impersonation, QR-code phishing, and messaging-app scams alongside traditional email attacks.
AI-assisted personalisation through the KnowBe4 platform
Modern awareness platforms apply behaviour analytics and AI-driven personalisation — training content adjusts to individual user risk profiles, with role-tailored content libraries and language-aware simulations. For South African organisations, platforms with mature local content libraries (executive impersonation in local accents, supplier scenarios from local sectors) outperform generic global content.
Beyond the inbox — the BEC layer
Phishing training reduces clicks. Business email compromise (BEC) exploits trust and process — supplier invoice redirection, executive impersonation, payroll diversion — and is rarely defeated by training alone. The defensive answer is procedural: out-of-band payment verification on changes, callback procedures on supplier banking detail updates, dual-approval thresholds, and mailbox-rule monitoring. Training supports these controls; it does not substitute for them.
Key Takeaways
- Annual training videos produce attendance metrics, not behaviour change.
- Click-through rate and reporting rate are the two metrics worth tracking — segmented by role and risk tier.
- Simulation-led learning with just-in-time feedback outperforms scheduled training for retention.
- AI-assisted personalisation (KnowBe4 and similar) tailors content to individual risk profiles.
- Phishing training reduces clicks; BEC defence requires procedural controls in addition.
How Cyber Resilience Can Help
Cyber Resilience helps organisations improve awareness culture, phishing resilience, and reporting behaviour through continuous simulation-led training programmes tailored to organisational risk profiles.
Speak with our team to arrange a discussion on a phishing-awareness programme.
