Failing a phishing test can have dire consequences for you and your organisation – here’s why, and how to pass the test.
Phishing is more common than ever, and businesses are taking ever more extreme measures to protect themselves and their staff from it. You have an obligation to
protect yourself and your organisation by wising-up to phishing and phishing tests with this expert’s invaluable advice.
Here IT expert Michael Moore from Next Perimeter weighs in on how to recognise a phishing email and protect yourself and your colleagues.
Phishing attempts are seemingly on the rise, with statistics reporting a 28% increase in phishing emails sent during a three-month period in 2024 compared to the three months prior. These cyberattacks pose a major and increasing security threat to businesses.
To try to guard against phishing attacks, some companies run random ‘phishing tests’ to test employees’ awareness – or the disastrous lack of it. Failing these tests repeatedly can have serious results including termination in some cases.
“All it takes is one click on a link in an email that looks harmless, by an employee who isn’t vigilant enough,” says IT expert Michael Moore, Chief Information Officer of Next Perimeter. “It’s easy to do, but the consequences can be very serious for a business that then has to deal with a critical data breach or disaster recovery. That’s why some companies run random employee phishing tests.”
Below, Michael explains what phishing tests are and why companies conduct them.
What is a Phishing Email?
“Phishing emails seek to fly in under the radar of the receiver’s vigilance. They function on desire and, frankly, people’s curiosity and perhaps dissatisfaction. The effectiveness of phishing emails, and how easy it is to fall for the links in them, means cybercriminals use them often,” says Michael.
Cybercriminals use phishing so much because it’s a relatively low effort, potentially high-yield way to glean secure data and use it advantageously, to steal, or to corrupt. While only around 1.2% of all global email is considered suspicious, that’s a worldwide total of well over 3 billion phishing messages sent daily**- and rising.
“Typically you’ll get an email that looks legitimate and offers you something. Whether it’s your want, your curiosity, or habit that makes you click on the link in that email, by the time you’ve opened it, it’s too late. You have opened a portal to a protocol that sends sensitive and private data back up the pipe. Or you may be led to a fake website that steals your credentials when you create an account and log in.”
What is a Phishing Test?
A phishing test is a benign email sent internally (or from a white hat partner) to an employee that is made to look very subtly inauthentic. Like a real phishing email, the test email will contain a promising link to a thing the email recipient might be interested in. This thing might relate to the sector or industry the recipient is in, or more typically, it won’t. It might contain an offer, or product or service that induces desire. If the staffer clicks on the link, they have failed the phishing test.
What if You Fail a Phishing Test?
Failing a phishing test once shouldn’t earn you much more than a gentle reprimand, but it very much depends on the sector you are in. Unsurprisingly, sectors like finance and certain types of IT need to protect themselves more effectively from cybercriminals because of the type of data they handle.
Fail a phishing test in the covert intelligence community or the military and the consequences are likely to be much more serious. If multiple tests are failed, that may result in dismissal. Ultimately, multiple failures will likely get you fired whatever sector you are in.
How to Recognise a Phishing Email
“Phishing emails can be very hard to spot,” says Michael. “But a rule of thumb is: if you don’t recognise or know the sender, don’t open the email. If you do, there are red flags to watch out for, however.”
Phishing emails tend to contain links to products and services that are either seasonally relevant (Christmas gift deals, perhaps) or too good to be true. They may comprise requests relating to fake emergencies, and birthday greetings.
Others ways to recognise a phishing email:
- They may contain urgent calls to action or threat flag-ups
- Bad spelling or grammar – phishing emails are often poorly written
- Generic greetings – the greeting is nameless and non-specific
- Mismatched email domains – the email purports to be from a legitimate company, but the email domain is different or generic (Gmail etc)
- Outlook displays a message stating that it cannot identify the sender
- The email contains suspicious links or unexpected/unsolicited attachments
Michael Moore, CIO of Next Perimeter, commented: “The ethics of firing someone who fails phishing tests repeatedly are debatable, as is the utility of doing so. The replacement employee may be even more gullible than the first person, and by then the first person will have probably learnt their lesson anyway. Phishing tests are actually pretty effective anti-phishing tools though.
“Phishing and general cybercrime awareness are vital for both individual employees and businesses. Phishing tests can help to raise awareness – and protect critical data. You can avoid phishing emails by being vigilant, and suspicious in a good way. Good suspicion can be very useful. Ultimately, if you have any doubts about an email at all, don’t open it. Send it to spam immediately. It’s best to err on the side of caution because the consequences of not doing so are severe.”
What is Fraud? “Fraud” is any activity that relies on deception in order to achieve a gain. Fraud becomes a crime when it is a “knowing misrepresentation of the truth or concealment of a material fact to induce another to act to his or her detriment” (Black’s Law Dictionary). In other words, if you lie in order to deprive a person or organization of their money or property, you’re committing fraud.
