Most businesses don’t find out their team needs phishing training until after an incident.
By then, the cost has already landed: a wire transfer gone to the wrong account, a password reused across systems, or a client’s data exposed because someone clicked the wrong link.
The good news is the warning signs usually show up long before an attack succeeds.
Here are five to watch for, and what to do about each one.
1. Employees Forward Suspicious Emails to Each Other Instead of IT
What it looks like:
“Hey, does this look weird to you?” sent to a colleague instead of reported.
Why it matters:
If your team’s instinct is to ask a peer rather than flag it properly, two things are true: they don’t fully trust their own judgment, and they don’t have a clear, easy reporting path. Both are training gaps, not people problems.
What to do:
Give employees one obvious button or address to report suspicious emails to, and make sure it’s faster than asking a colleague. If reporting is easy, people do it. If it’s a five-step process, they won’t.
2. Your Business Has No Idea How Many Phishing Emails Actually Land in Inboxes
What it looks like:
IT has visibility into what got blocked, but no one has visibility into what got through.
Why it matters:
Every email filter has a miss rate. Attackers know this and design specifically to slip past standard filters. If you only see what was blocked, you have no picture of your real exposure.
What to do:
Run a phishing simulation. Not to catch people out, but to get an honest baseline: what percentage of your team would click, and on what kind of message.
This number is usually higher than leadership expects, and that’s the point of measuring it.
3. Password Reuse Is Common (Even If No One Says So Out Loud)
What it looks like:
The same password pattern shows up across work and personal accounts. No one talks about it, but it’s happening.
Why it matters:
Phishing rarely stops at one stolen password. Attackers test reused credentials against other systems immediately. One compromised personal account can become a route into your business systems.
What to do:
Training on password hygiene works far better paired with practical tools, like a password manager rollout, than as a standalone lecture.
Give people an easier good habit, not just a warning about a bad one.

4. Urgent Requests Get Actioned Before They Get Verified
What it looks like:
An email from “the CEO” asking for an urgent payment or gift card purchase gets actioned same day, no phone call, no second check.
Why it matters:
This is the single most common pattern in successful business email compromise.
Attackers exploit urgency and hierarchy on purpose, because it works. AI-written impersonation emails have made this harder to catch by tone alone.
What to do:
Set a simple rule: any unusual financial request gets verified through a second channel, no exceptions, regardless of who it appears to be from.
This one policy prevents a large share of real-world losses.
5. Your Last Training Session Was a Slide Deck, Once, a Year Ago
What it looks like:
Phishing awareness lives in an onboarding PDF nobody has opened since their first week.
Why it matters:
Attack patterns evolve constantly. A static training session from a year ago doesn’t reflect what phishing looks like today, especially with AI making lures more convincing and harder to spot on sight.
What to do:
Treat awareness as an ongoing habit, not a one-time event. Short, regular refreshers paired with real (simulated) examples build instinct in a way an annual slide deck never will.
Awareness Alone Isn’t Enough
Training builds instinct, but instinct still misses things, especially now that AI-generated phishing emails read as fluently as a real colleague would write.
That’s where detection tools like PhishNet come in: not to replace employee awareness, but to catch what even a well-trained eye can miss, by spotting the underlying behavioural and technical patterns of an attack rather than relying on obvious tells.
The businesses with the strongest defence pair both: people who know to pause and verify, and systems that catch what people can’t see.
If more than one of these five signs sounds familiar, that’s not a reason to panic.
It’s a reason to start.


