1. Purpose
The Phishing Awareness Procedure defines how the organization identifies, communicates, trains, tests, monitors, and improves employee awareness against phishing and social-engineering attacks.
The procedure is designed to reduce the likelihood that personnel will:
- Click malicious links
- Open malicious attachments
- Disclose credentials
- Approve fraudulent authentication requests
- Transfer sensitive information to unauthorized parties
- Install malicious software
- Respond to fraudulent payment or business requests
- Bypass security controls
- Become victims of social-engineering attacks
Core Principle
Identify → Educate → Simulate → Report → Analyze → Reinforce → Improve
2. Scope
This procedure applies to:
- Employees
- Contractors
- Interns
- Temporary personnel
- Consultants
- Privileged users
- Remote workers
- Personnel handling customer information
- Personnel handling personal information
- Other users with organizational accounts
The organization may apply enhanced awareness activities to higher-risk roles.
3. Phishing Awareness Objectives
The organization should ensure personnel can:
☐ Recognize common phishing indicators
☐ Identify suspicious emails
☐ Identify suspicious links
☐ Identify malicious attachments
☐ Recognize credential-harvesting attempts
☐ Recognize MFA fatigue attacks
☐ Recognize business-email-compromise attempts
☐ Recognize social-engineering techniques
☐ Verify unusual requests
☐ Report suspected phishing
☐ Avoid interacting with suspicious content
☐ Respond appropriately after accidental interaction
4. Phishing Threat Categories
Awareness activities should cover relevant attack types.
Email Phishing
Fraudulent emails designed to trick users into clicking, opening, replying, or providing information.
Credential Phishing
Attempts to obtain:
- Passwords
- MFA codes
- Session tokens
- Authentication information
Spear Phishing
Highly targeted phishing directed at a specific employee, role, or organization.
Business Email Compromise
Fraudulent messages impersonating:
- Executives
- Customers
- Suppliers
- Finance personnel
- Business partners
MFA Fatigue
Repeated authentication requests intended to pressure users into approving an unauthorized login.
Smishing
Phishing through SMS or messaging applications.
Vishing
Social engineering through voice or telephone calls.
QR Phishing
Malicious QR codes directing users to fraudulent websites.
Attachment-Based Phishing
Malicious or unexpected files designed to compromise a system or obtain information.
AI-Assisted Phishing
Highly convincing messages generated or enhanced using AI.
5. Roles and Responsibilities
| Role | Responsibility |
|---|---|
| Senior Management | Support awareness program and provide resources |
| Information Security | Own phishing awareness program |
| HR | Support employee communication and onboarding |
| IT | Support technical controls and reporting mechanisms |
| Managers | Support completion and follow-up |
| Employees | Complete training, identify and report suspicious activity |
| Security Team | Analyze reported phishing and coordinate response |
| Incident Response Team | Handle confirmed security incidents |
| Training Owner | Maintain training content and records |
6. Phishing Awareness Program
The organization should maintain a risk-based phishing awareness program consisting of:
- Initial awareness training
- New-employee training
- Periodic refresher training
- Security communications
- Phishing simulations where appropriate
- Reporting mechanisms
- Incident-driven awareness
- Measurement and analysis
- Targeted reinforcement
- Continual improvement
7. New Employee Awareness
Phishing awareness should be included in security onboarding.
Before or shortly after receiving organizational access, personnel should understand:
☐ How to identify suspicious messages
☐ How to report phishing
☐ How to verify unusual requests
☐ How to handle attachments
☐ How to handle links
☐ MFA security
☐ Password protection
☐ Incident reporting
☐ Business-email-compromise risks
☐ Social-engineering risks
8. Periodic Awareness Training
Phishing awareness should be refreshed periodically based on risk.
Training may include:
- Email examples
- Real-world scenarios
- Short videos
- Interactive exercises
- Quizzes
- Simulations
- Security alerts
- Case studies
- Incident lessons learned
Training frequency should be determined based on organizational risk, threat exposure, incidents, regulatory/customer requirements, and previous training results.
9. Phishing Indicators
Employees should be trained to consider:
Sender
☐ Unexpected sender
☐ Similar-looking domain
☐ Unknown external sender
☐ Unexpected internal sender
☐ Display-name impersonation
Message
☐ Urgent request
☐ Threatening language
☐ Unexpected payment request
☐ Unexpected password-reset request
☐ Request for confidential information
☐ Unusual business request
☐ Suspicious grammar or formatting
Link
☐ Unexpected link
☐ Mismatched displayed URL
☐ Suspicious domain
☐ URL-shortening service used unexpectedly
☐ Unexpected login page
Attachment
☐ Unexpected attachment
☐ Unexpected document
☐ Executable file
☐ Macro-enabled document
☐ Password-protected archive from an unknown source
10. Verify Before Acting
Personnel should be trained to independently verify unusual or high-risk requests.
Examples:
“Please transfer this payment immediately.”
“Send me the customer database.”
“Reset my password.”
“Approve this MFA request.”
“Download this urgent document.”
“Share the security report.”
The employee should verify the request using an independent communication channel where appropriate.
11. Reporting Procedure
Personnel should have a simple mechanism for reporting suspected phishing.
Possible mechanisms:
- Phishing-report button
- Security email address
- Helpdesk
- Security ticket
- Incident-management platform
- Approved reporting channel
Employee Reporting Process
Stop → Do Not Interact Further → Report → Follow Instructions
Employees should not be discouraged from reporting because they believe they may have made a mistake.
12. What Employees Should Do
If a suspicious message is received:
If Not Opened
- Do not click links.
- Do not open attachments.
- Report the message.
- Follow the organization’s instructions.
- Delete or quarantine it when authorized.
If a Link Was Clicked
- Stop interacting with the website.
- Do not enter credentials.
- Close the browser if appropriate.
- Report the event immediately.
- Follow security-team instructions.
If Credentials Were Entered
- Report immediately.
- Do not attempt to hide the event.
- Follow password-reset instructions.
- Follow MFA/security instructions.
- Cooperate with the investigation.
If a Malicious Attachment Was Opened
- Stop interacting with the file.
- Disconnect from the network if instructed.
- Report immediately.
- Do not delete evidence unless instructed.
- Follow incident-response instructions.
13. Phishing Simulation Program
Where appropriate, the organization may conduct controlled phishing simulations.
The objective is to measure and improve awareness, not to punish employees.
Simulation Lifecycle
Plan → Approve → Configure → Send → Monitor → Analyze → Reinforce → Report → Improve
14. Simulation Planning
Before conducting a simulation:
☐ Objective defined
☐ Scope defined
☐ Target audience defined
☐ Simulation type defined
☐ Risk assessed
☐ Approval obtained
☐ Communication approach defined
☐ Privacy considerations assessed
☐ Emergency stop mechanism established
☐ Results handling defined
15. Simulation Rules
Simulations should be designed responsibly.
Avoid unnecessary:
- Personal humiliation
- Public naming and shaming
- Highly distressing content
- Excessive frequency
- Collection of real passwords
- Collection of unnecessary personal information
- Real malware
- Actual credential harvesting
Simulation systems should not collect real passwords.
16. Phishing Simulation Scenarios
Examples:
Scenario 1 — Password Expiry
A simulated message claims that the user’s password will expire.
Scenario 2 — Document Sharing
A simulated notification asks the user to review a document.
Scenario 3 — Executive Request
A simulated executive requests urgent action.
Scenario 4 — Supplier Invoice
A simulated supplier sends an invoice requiring review.
Scenario 5 — MFA Request
A simulated authentication notification attempts to create urgency.
Scenario 6 — Cloud Login
A simulated cloud-service notification asks the user to sign in.
17. Simulation Metrics
Track appropriate metrics.
Click Rate
Users who clicked ÷ Users tested × 100
Reporting Rate
Users who reported ÷ Users tested × 100
Credential Submission Rate
Where safely simulated without collecting real credentials:
Users who reached the simulated credential page ÷ Users tested × 100
Repeat Failure Rate
Users failing multiple simulations ÷ Users tested × 100
Metrics should be interpreted carefully rather than used as standalone measures of employee performance.
18. Phishing Simulation Register
| Simulation ID | Date | Audience | Users Tested | Clicked | Reported | Click Rate | Report Rate | Follow-Up |
|---|---|---|---|---|---|---|---|---|
19. Targeted Awareness
Additional awareness may be provided to higher-risk groups.
Examples:
Finance
Focus on:
- Payment fraud
- Invoice fraud
- Executive impersonation
- Supplier impersonation
HR
Focus on:
- Employee-data requests
- Resume attachments
- Identity fraud
- Payroll fraud
IT
Focus on:
- Credential theft
- Privileged access
- MFA attacks
- Technical impersonation
Developers
Focus on:
- Repository notifications
- Package/repository phishing
- Developer credential theft
- Secrets exposure
Executives
Focus on:
- Executive impersonation
- Business-email compromise
- Targeted spear phishing
20. Business Email Compromise Awareness
Personnel should be trained to recognize unusual requests involving:
- Payments
- Bank-account changes
- Supplier details
- Customer information
- Confidential information
- Urgent approvals
- Gift cards
- Password resets
- Executive requests
Verification Principle
Urgency does not replace verification.
High-risk financial or information requests should follow the organization’s approved authorization process.
21. MFA Awareness
Personnel should understand that MFA does not eliminate phishing risk.
Awareness should cover:
☐ Unexpected MFA requests
☐ MFA fatigue
☐ Authentication-code requests
☐ Push-notification abuse
☐ Fake authentication pages
☐ Never approving an unexpected login
Rule
Never approve an authentication request that you did not initiate.
22. AI-Enabled Phishing Awareness
Personnel should be aware that AI can make phishing messages:
- Grammatically correct
- Highly personalized
- Professionally formatted
- Contextually convincing
- Multilingual
Therefore, employees should not rely only on spelling mistakes or poor grammar to identify phishing.
Focus on:
- Unexpected requests
- Identity verification
- Link destination
- Context
- Urgency
- Authorization
- Independent verification
23. Phishing Reporting and Incident Escalation
A reported phishing message should be assessed.
Process
Report → Triage → Analyze → Determine Severity → Contain → Investigate → Recover → Learn
Potential outcomes:
☐ Spam
☐ Phishing attempt
☐ Credential theft attempt
☐ Malware attempt
☐ Business-email compromise
☐ Confirmed compromise
☐ Security incident
☐ False positive
24. Security Team Responsibilities
The security team should, where appropriate:
- Review reported messages
- Analyze sender information
- Analyze URLs
- Analyze attachments
- Check authentication logs
- Check endpoint alerts
- Search for similar messages
- Identify affected users
- Block malicious domains
- Block malicious indicators
- Reset compromised credentials
- Revoke sessions/tokens where necessary
- Escalate confirmed incidents
- Preserve evidence
- Update awareness content
25. Incident-Driven Awareness
When phishing results in a security incident, evaluate whether additional awareness is required.
Example
Phishing email → Employee clicks → Credentials compromised → Account secured → Root cause analysis → Targeted training → Simulation → Effectiveness review
The objective should be to address the underlying risk rather than simply blame the individual.
26. Security Controls Supporting Awareness
Phishing awareness should be supported by technical controls where appropriate.
Examples:
☐ Email filtering
☐ Anti-malware
☐ URL protection
☐ Attachment scanning
☐ SPF
☐ DKIM
☐ DMARC
☐ MFA
☐ Conditional access
☐ Endpoint protection
☐ DNS filtering
☐ Security monitoring
☐ Browser protection
Awareness training should not be treated as a substitute for appropriate technical controls.
27. Phishing Training Content
Training content should cover:
Basic Awareness
- What is phishing?
- Why phishing works
- Common attack types
- Warning signs
- Reporting
Authentication
- Password protection
- MFA
- MFA fatigue
- Credential phishing
Information Protection
- Customer information
- Personal data
- Confidential information
- Financial information
- Source code
Social Engineering
- Authority
- Urgency
- Fear
- Curiosity
- Trust
- Familiarity
Response
- Stop
- Report
- Verify
- Escalate
28. Awareness Communications
Security communications may be issued following:
☐ New phishing campaign
☐ Significant threat
☐ Security incident
☐ New attack technique
☐ Technology change
☐ Regulatory/customer requirement
☐ Repeated simulation failures
Communications should be concise and actionable.
29. Phishing Awareness Records
Maintain appropriate evidence such as:
- Training assignments
- Training completion
- Training materials
- Assessment results
- Phishing simulation records
- Campaign communications
- Reporting statistics
- Incident-driven training
- Management reports
- Corrective actions
- Improvement records
Avoid retaining unnecessary sensitive employee information.
30. Privacy and Employee Data
Phishing awareness activities should respect employee privacy.
The organization should:
☐ Collect only necessary information
☐ Restrict access to simulation results
☐ Define retention
☐ Protect employee records
☐ Avoid unnecessary public disclosure
☐ Apply applicable privacy requirements
☐ Define appropriate management reporting
31. Training Effectiveness
Effectiveness should be evaluated using multiple indicators.
Consider:
- Training completion
- Assessment results
- Phishing simulation results
- Reporting rate
- Click rate
- Repeat behavior
- Security incidents
- Near misses
- Employee feedback
- Audit findings
Effectiveness Principle
Completion demonstrates participation. Behavior demonstrates effectiveness.
32. Corrective Actions
Where weaknesses are identified:
| Finding | Cause | Action | Owner | Due Date | Evidence | Status |
|---|---|---|---|---|---|---|
Actions may include:
- Refresher training
- Targeted training
- Additional simulations
- Technical controls
- Process changes
- Access restrictions
- Management communication
- Incident-response improvements
33. Exceptions
Where a person cannot complete required training:
☐ Reason documented
☐ Risk assessed
☐ Alternative arrangement defined
☐ Compensating control considered
☐ Approval obtained
☐ Expiry date defined
☐ Follow-up scheduled
34. Management Reporting
Management reporting may include:
| Metric | Current | Previous | Target | Status |
|---|---|---|---|---|
| Training Completion | ||||
| Phishing Click Rate | ||||
| Phishing Reporting Rate | ||||
| Repeat Failure Rate | ||||
| Phishing Incidents | ||||
| Overdue Training |
Reports should emphasize security risk and trends rather than individual employee performance.
35. Review Frequency
The procedure should be reviewed:
☐ At least annually
☐ Following a significant phishing incident
☐ Following significant changes in threats
☐ Following major technology changes
☐ Following significant audit findings
☐ Following changes to applicable requirements
36. AWS SaaS Startup Example
Consider a SaaS startup with:
- AWS production environment
- GitHub
- Microsoft 365 or Google Workspace
- Remote employees
- Customer data
- Cloud administrators
- Developers
- Finance personnel
Awareness Program
All Employees
- Phishing awareness
- MFA
- Password security
- Incident reporting
Developers
- GitHub phishing
- Repository notifications
- Credential theft
- Secrets protection
Cloud Administrators
- AWS credential phishing
- Privileged access
- MFA fatigue
- Cloud-console impersonation
Finance
- Invoice fraud
- Executive impersonation
- Bank-account-change verification
Audit Trail
Threat → Awareness Requirement → Training → Simulation → Reporting → Measurement → Corrective Action → Improvement
37. Startup-Friendly Model
A small startup can implement an effective phishing program without a large security team.
Minimum Program
Monthly
- One short awareness message
Quarterly
- One focused phishing awareness activity
Periodically
- Controlled phishing simulation where appropriate
Annually
- Formal security-awareness training
After Incidents
- Targeted awareness and corrective action
Minimum Evidence
Maintain:
- Training register
- Simulation register
- Campaign records
- Assessment results
- Incident records
- Corrective actions
38. Common Mistakes
Avoid:
- Treating phishing awareness as a once-a-year presentation.
- Relying only on employees to stop phishing.
- Ignoring MFA-fatigue attacks.
- Focusing only on spelling mistakes.
- Failing to provide an easy reporting mechanism.
- Punishing employees for reporting mistakes.
- Collecting real passwords during simulations.
- Publicly shaming employees.
- Ignoring business-email compromise.
- Ignoring AI-assisted phishing.
- Failing to analyze repeat behavior.
- Not updating training after incidents.
- Measuring only training completion.
- Failing to integrate phishing reporting with incident response.
39. Relationship With Other ISMS Documents
| Document | Relationship |
|---|---|
| Information Security Awareness Policy | Defines awareness requirements |
| Security Awareness and Training Procedure | Defines the broader training process |
| Security Awareness Training Register | Records training completion |
| Role-Based Security Training Matrix | Defines role-specific training |
| Employee Security Training Checklist | Verifies individual training |
| Incident Response Procedure | Handles confirmed phishing incidents |
| Security Incident Reporting Procedure | Defines incident reporting |
| Incident Register | Records confirmed incidents |
| Corrective Action Tracker | Tracks corrective actions |
| Security Awareness Campaign Register | Records awareness campaigns |
| Phishing Simulation Register | Records phishing simulations |
| Access Management Procedure | Supports protection after credential compromise |
| MFA Standard | Supports authentication security |
40. ISO 27001 Connection
Phishing awareness supports the organization’s information-security awareness, competence, access-control, incident-management, and information-protection objectives.
The procedure should be aligned with:
- Information-security roles and responsibilities
- Awareness and training requirements
- Authentication controls
- Access management
- Incident management
- Malware protection
- Technical vulnerability management
- Information protection
- Security monitoring
- Business continuity where relevant
The Phishing Awareness Procedure is not itself a universally prescribed ISO 27001 document. The organization should determine its need, scope, frequency, and evidence based on its risk assessment, threat environment, ISMS scope, applicable controls, contractual requirements, and legal/regulatory obligations.
41. Final Audit Checklist
☐ Phishing awareness owner assigned
☐ Procedure approved
☐ Phishing threats identified
☐ New-employee awareness defined
☐ Annual awareness defined
☐ Role-based awareness defined
☐ Reporting mechanism established
☐ Employees trained
☐ Phishing simulations approved where applicable
☐ Simulation rules defined
☐ Real credentials not collected
☐ Simulation results protected
☐ Phishing metrics tracked
☐ Incident escalation defined
☐ Incident-driven training defined
☐ MFA phishing risks addressed
☐ Business-email compromise addressed
☐ AI-enabled phishing addressed
☐ Technical controls considered
☐ Corrective actions tracked
☐ Training effectiveness measured
☐ Management reporting performed
☐ Procedure reviewed periodically
42. Final Audit Trail
For a phishing-awareness program, the organization should be able to demonstrate:
What phishing threats affect us?
Who is at risk?
What awareness is required?
Who received training?
How was understanding assessed?
How can employees report phishing?
Are simulations performed where appropriate?
What do the results show?
What happens when someone reports a suspicious message?
How are confirmed incidents handled?
What additional training follows an incident?
How is effectiveness measured?
How does the program improve over time?
Final Principle
Phishing awareness is not simply about teaching employees to recognize suspicious emails. It is a continuous security process that combines awareness, reporting, technical protection, incident response, measurement, and continual improvement.
Phishing Awareness Lifecycle:
Identify Threat → Educate → Simulate → Report → Analyze → Respond → Reinforce → Measure → Improve
