Cybersecurity
Phishing Prevention & Training
Hard to fake. Easy to report.
Phishing prevention combines two things: technical controls that keep convincing fake emails out and stop your own domain being forged, and training that makes reporting a suspicious message the easy, normal thing to do. happier IT sets up both for Canadian organizations of roughly 15 to 200 people, and runs simulations that are never used to embarrass anybody.
Who it's for
Four conversations that start this work.
Three are about money moving. One is about a domain being used by somebody else, which is a configuration problem with a specific fix.
Someone in accounts nearly paid the wrong bank account. A real supplier, a real invoice number, one line changed. Filters do not catch these, because there is nothing technically wrong with the message, it is a business process question wearing an email.
Clients are receiving mail that appears to come from you. Your domain is being used as a return address by people with no connection to you. This has a known fix, and it takes days rather than months.
Staff forward suspicious messages to each other. Which means the one person who could act never sees it, and the same email sits in twelve inboxes attracting twelve opinions.
Your last simulation went badly. A high click rate, an all-staff email about it, and now nobody reports anything. Recoverable, and slower to undo than it was to cause.
Why shaming backfires
A person who expects to be embarrassed for clicking will not tell you that they clicked. The silence is the costly part: a reported mistake is a twenty-minute password reset, an unreported one is a quiet fortnight.
We never publish names, never run leaderboards, and never hand results to a manager as a performance item.
What's included
The technical half and the human half.
Do the domain records first. They are the only item here that protects your clients and suppliers as much as it protects you.
-
Email authentication: SPF, DKIM and DMARC
Three records published in your domain settings that let receiving mail servers check a message claiming to be from you. SPF lists who may send as you, DKIM signs each message, and DMARC says what to do when a check fails, and reports back. Reaching DMARC enforcement is the best day of work on this page.
-
Filtering tuned rather than defaulted
Attachment and link handling, impersonation rules protecting the names most likely to be forged, and an external-sender banner worded to be noticed, a warning that appears on every message quickly becomes wallpaper.
-
A one-click report button
A Report button in Outlook that sends the message to us with its full headers, quarantines it for that person, and lets us pull the same message out of every other mailbox it reached. Reporting has to take one second to become a habit.
-
A written payment-change rule
Any change to bank details is confirmed by phoning a number you already held, never the number in the email, by someone other than the person who received it. This is a process control rather than a product, and it prevents more loss than anything else here.
-
Non-punitive simulations
Realistic test messages on a sensible cadence, with an immediate, friendly explanation for anyone who clicks. Results are reported as an organizational figure. Individual names stay with the platform and go no further.
-
A shorter, sharper track for finance and executives
The people who move money and the people whose names get forged need a different conversation from everyone else: approval thresholds, supplier bank changes, payroll requests, and what to do when the request appears to come from the boss on a phone.
-
A reply to every report
Whoever reports a message hears back with what it turned out to be and a thank you. That reply is the entire reason a second report ever happens.
-
The other channels, covered
Text messages, phone calls, Teams chats and QR codes printed on invoices carry the same requests. Training that only mentions email teaches people to relax everywhere else.
How it works
Domain first, button second, simulations last.
Running simulations before people have a way to report is how a programme starts on the wrong foot.
-
Fix the domain records
SPF, DKIM and DMARC published, then moved to enforcement carefully, with the reports monitored for a few weeks so a legitimate newsletter, payroll system or booking platform does not silently stop being delivered.
-
Give people a button and a promise
The report button goes into Outlook, and the promise goes with it: report anything at all, nobody will be made to feel silly, and you will hear back. Then we start measuring how often it gets used.
-
Simulate, explain, repeat
Simulations begin only once reporting exists. A click leads to a short explanation, not an escalation. Every quarter we look at the reporting rate first and the click rate second, and change the content rather than the people.
What it costs
Included in managed IT. The domain work stands alone.
If you buy nothing else on this page, publish the email authentication records. They are cheap, they are permanent, and they help people you will never meet.
Filtering configuration, the domain records, the report button and the simulation programme are all inside happier IT’s managed IT
Standalone, it is priced per mailbox, per month, and is usually bought together with security awareness training
It is worth doing on its own merits even if we never speak again.
What DMARC is actually worth
Enforced DMARC mostly stops other people sending mail that appears to come from your domain. That protects your clients and suppliers more than it protects your own inbox, which is precisely why it gets postponed.
Whether a provider has done it is a decent measure of whether they are thinking past your own inbox.
Why us for this
No filter catches everything, so the process has to hold.
Any provider can turn on a filter. The honest position is that a well-written message from a compromised supplier account, with the right invoice number attached, will land in somebody’s inbox, there is nothing technically wrong with it. That is why the phone-call rule and the report button are controls rather than training material.
When a message is reported, happier IT’s security operations centre in Canada can search every mailbox in your tenancy for the same message and remove it, then check whether anyone had already signed in somewhere they should not have. Staffed hours: 24/7, with the Surrey office on Monday to Friday, 8:00 am to 5:00 pm Pacific.
What we will not do is publish a click-rate improvement figure. We do not have a sourced one, and the number that matters is the reporting rate anyway.
Go deeper
- What is phishing? A plain definition and the common shapes.
- Security awareness training The wider curriculum around this.
- Microsoft 365 security Where most of the filtering settings live.
Questions
What people ask before they sign anything.
What are SPF, DKIM and DMARC?
They are three settings published in your domain’s DNS records, the public entries that tell the internet where your mail and website live, and together they prove an email really came from you. SPF, sender policy framework, lists the servers allowed to send as your domain. DKIM adds a cryptographic signature to each message. DMARC ties the two together, tells receiving servers what to do when the checks fail, and sends you reports about who is sending mail using your name. Publishing all three and enforcing DMARC is a short project with a lasting effect.
Do phishing simulations actually work?
They reliably improve reporting, which is the thing that matters, and they do not drive click rates to zero, nothing does. Treat the click rate as a thermometer rather than a target: it tells you how convincing that particular message was, and it moves for reasons that have nothing to do with your staff, such as a busy month-end. The reporting rate and the time between the first click and the first report are the numbers worth watching.
Should we tell staff we are running simulations?
Yes. Announce that the programme exists, explain why, and be clear that results are never attached to names or performance reviews. Do not announce the individual sends. Secret programmes create the exact atmosphere that stops people reporting real messages, and in a unionised or works-council environment an unannounced programme can create a genuine labour-relations problem as well.
Someone clicked a link and entered their password. What now?
Change the password and, more importantly, revoke the active sessions, a password change alone does not sign out a session already established. Then check for new mailbox rules and forwarding, check whether a second-factor method was added, and look at recent sign-in locations. Tell your provider immediately. If we run your security, that whole sequence is ours to do and it starts the moment you tell us.
Is Microsoft 365 filtering enough on its own?
It is genuinely good, and in most tenancies it is under-configured. Impersonation protection, Safe Links and Safe Attachments are often left off or left at defaults that do not know who your executives and finance staff are. Before buying a third-party filter to sit in front of it, it is worth having someone configure what you already pay for, see Microsoft 365 security.
What does phishing prevention cost?
The domain authentication project is separately priced because it is worth buying on its own.
Related
Where to go next.
Related services
Worth reading
Want to know what this would look like for you?
A 30-minute call. No slides, no audit fee, no obligation. We ask what is breaking and tell you honestly whether we are the right fit.