Podcast
The article takes the floor. A conversation generated by artificial intelligence.
Phishing consistently ranks among the cyber incidents Swiss companies report most often to the Federal Office for Cybersecurity: it has become the number one way in. Yet most current awareness programmes generate as much stress as actual protection. Your staff need vigilance, not paranoia.
Why your current training reinforces mistrust instead of vigilance
Many companies launch simulated phishing campaigns without preparation. The result is immediate. Employees who click on a trap link receive a guilt-inducing message, sometimes in front of colleagues.
This punitive approach creates mistrust towards IT, not vigilance towards threats.
65% of office workers bypass cybersecurity policies, according to CyberArk’s 2024 survey. This figure doesn’t reflect a lack of awareness, but a rejection of methods. When training becomes a fear-based ordeal, teams develop avoidance strategies.
They stop reporting suspicious emails. They avoid asking questions. They hide their mistakes instead of sharing them.
The perverse effects of poorly calibrated simulators
A phishing simulator can become counter-productive if not properly accompanied. Without context or debriefing, it reinforces the idea that IT is trying to trap rather than protect.
Staff end up considering every email a potential threat, including legitimate internal communications.
This generalised mistrust slows business processes. Teams hesitate before each click. They contact IT for unnecessary checks. The time lost far exceeds the benefit of initial vigilance.
When training becomes a source of anxiety
49% of European SMEs hold back their development out of fear of cyberattacks, according to a 2025 Mastercard study. This paralysis comes not only from the threats themselves, but also from how they are presented.
A catastrophist message generates stress without offering a concrete solution.
Staff exposed to anxiety-inducing training develop a form of cognitive fatigue. They don’t retain good practices. They only memorise the diffuse sense of danger.
This approach turns cybersecurity into a psychological obstacle rather than an operational reflex.
Build a reflex without creating fear
Effective training rests on clarity, not intimidation. Your teams must know what to do facing a suspicious email, not simply what to avoid. This distinction radically changes the impact of your initiatives.
Bet on realistic, progressive scenarios
Simulators work when they reproduce credible situations. A fake email from your CFO requesting an urgent transfer will have more impact than a generic banking message. Progression matters too.
Start with obvious attempts, then ramp up complexity over the weeks.
This ramp-up lets staff build vigilance step by step. They learn to spot weak signals without feeling overwhelmed. Each success strengthens their confidence in their ability to detect a threat.
Turn each test into a learning moment
The debriefing makes all the difference. After each simulation, explain why the email was suspicious. Show the concrete clues. Share the good reactions of certain staff without singling out those who clicked.
We systematically organise short sessions after each internal campaign. These moments turn an individual mistake into collective learning. Teams better understand phishing mechanics and develop a common vocabulary to discuss threats.
From simulators to real stories
Phishing has become the number one reported way into small businesses. Your staff need to understand the real consequences, not just the statistics. Concrete stories stick far more than figures.
Tell what happened in a company similar to yours after a click on a trap link. Describe the incident’s unfolding, the first warning signs, the IT team’s reaction. These narratives create an emotional connection that aids memory.
Use internal mistakes as case studies
When a staff member reports a phishing attempt or admits to clicking, turn that event into a teaching opportunity. Anonymise the case, present it in a meeting, explain what could have happened and what was avoided thanks to the quick report.
This approach values transparency. Teams understand a reported error beats a hidden one. They develop an information-sharing reflex that strengthens your real-time threat detection and monitoring capability.
Build an accessible library of real cases
Set up a shared space where your staff can consult recent examples of phishing attempts. Update this content regularly with annotated screenshots and short explanations.
This tool becomes a common reference. Teams come back to it when in doubt. They compare a suspicious email with documented examples. This autonomy reduces unnecessary requests and speeds decision-making.
Adapt your message to who is actually listening
Not all your staff react the same way to threats. A finance leader doesn’t have the same concerns as a maintenance technician. Your awareness work must reflect this diversity.
Segment your audiences by risk exposure
Identify the most-targeted profiles in your organisation. Those who handle payments, HR, or system access face more phishing attempts. Build specific modules for these groups.
An HR lead must recognise a booby-trapped fake CV. An accountant must spot a fake transfer request. These targeted scenarios increase training relevance and strengthen participant engagement.
We adapt our campaigns to business roles. This personalisation improves the reporting rate of real threats and reduces false alarms.
Measure what really matters
The percentage of clicks on a trap email isn’t enough to assess your progress. Track also the number of spontaneous reports, the average time to detect a real attempt, the participation rate in debrief sessions.
- Number of suspicious emails reported each month
- Average time between receipt and report
- Proportion of staff who completed training modules
- Click-rate evolution across successive campaigns
These indicators give a complete view of your teams' maturity. They allow you to adjust messages and value concrete improvements rather than sanction one-off mistakes.
Take action without waiting for the next attack
Phishing and credential theft are now the main way attackers get into SMEs. Your best defence remains a trained, vigilant team confident in its ability to detect threats.
We support you in building this security culture without generating unnecessary stress. Let’s discuss your current situation and the concrete actions to put in place quickly.
