top of page

Phishing 101

Purpose of the course:

A cybersecurity awareness course designed to help employees recognise and respond to phishing attacks — covering the most common techniques used by malicious actors, the warning signs to look for in suspicious emails and messages, and the correct steps to take when a phishing attempt is identified. This course is provided to both new hires and existing employees worldwide, recurring on an annual basis. 

My approach:

Developed in Storyline 360 and Camtasia to allow use of extensive graphical and multimedia elements — allowing employees to complete the course on any device, which is particularly important for field-based and remote staff. Content is structured as a progressive journey from awareness through to action: learners first understand what phishing is and why it works, before moving into interactive email simulations where they must identify real versus fake messages.  Tone kept deliberately practical and non-alarmist, yet also serious — focused on empowering staff rather than creating anxiety around technology use.

Measuring success

Success is measured through a scored knowledge check at the end of the course, with a minimum pass mark aligned to the organisation's requirements. Longer-term effectiveness tracked through simulated phishing campaigns run by the IT security team — monitoring click rates on test phishing emails before and after training to provide a concrete behavioural measure of impact.

Screenshots from course:

1.png
2.png
3.png
bottom of page