Phishing is not a new threat, and that is exactly the problem. Because it feels familiar, many organisations assume they have it covered — a spam filter here, an annual awareness slide deck there. Yet across our engagements in East Africa, a convincing email remains the single most reliable way an attacker gets their first foothold. It is still the front door, and it is still unlocked more often than it should be.
Why phishing still works
Attackers have simply kept pace with how we work. Cloud email, mobile-first staff, and busy finance teams create the perfect conditions for a well-timed message. The technical barrier keeps dropping too: phishing kits are cheap, and generative AI now writes fluent, localised messages that no longer carry the tell-tale spelling mistakes people were trained to spot.
The result is that the old advice — “look for bad grammar” — is close to useless. Modern phishing succeeds because it looks like ordinary work.
The mistakes we see most often
When we run phishing simulations for clients, the same gaps come up again and again:
- Treating awareness as a once-a-year event. A single training session in January does little for the employee facing a clever message in September.
- Relying on the filter alone. Email security gateways stop the obvious volume, but targeted messages to a named finance officer are designed to slip through.
- No easy way to report. If reporting a suspicious email takes five steps, staff simply delete it — and the security team never learns an attack is underway.
- Punishing the people who click. A blame culture guarantees that the next person who clicks stays quiet, which is the opposite of what you want.
What actually moves the needle
Effective phishing defence is less about a single product and more about a habit. The organisations that resist these attacks best tend to do a few unglamorous things well:
Make reporting effortless
A one-click “report phishing” button turns every employee into a sensor. When one person reports a campaign, your team can pull the same message from everyone else’s inbox before it does damage.
Simulate realistically, then coach
Run simulations that mirror the lures your staff actually receive — a fake invoice, an M-Pesa notification, an HR memo. When someone clicks, use it as a teachable moment, not a disciplinary one.
Protect the accounts that matter
Multi-factor authentication on email and finance systems dramatically reduces what a stolen password is worth. It is the highest-return control most SMEs can turn on this week.
The bottom line: phishing defence is a programme, not a poster. Small, consistent habits — easy reporting, realistic practice, and MFA — beat a once-a-year lecture every time.
Where to start
If you are not sure how exposed your team is, a baseline phishing simulation is a low-risk way to find out. It gives you a clear, honest number to improve on — and it usually surfaces a few quick wins in the process. If you would like to see how your organisation would fare, start a conversation with us.
