Treat awareness training as a core control, not a one-time exercise. Teach staff to verify unexpected requests through a separate channel, pause before downloading software, and recognise pressure tactics that create urgency. Good training also covers common social engineering patterns, because legitimate tools can be abused when users are persuaded to install them for an attacker.
Why Phone and Email Fraud Training Needs to Be Continuous
When employees are targeted by phone and email fraud, the real objective is usually to get them to bypass normal checks under pressure. Training should therefore focus on recognition and verification, not just policy memory. The most useful messages are simple: slow the interaction down, verify through a separate route, and treat urgency as a warning sign rather than a reason to comply.
Security awareness works best when it is built around the decisions staff actually face, such as whether to trust a caller, whether to click a link, or whether to install software after a message or voicemail. That makes the training practical, repeatable and easier to reinforce across phishing, vishing and broader social engineering attempts.
A good program also needs repetition because fraud tactics evolve and employees forget one-off guidance quickly. The goal is not perfect suspicion, but reliable pause-and-check behaviour when a request is unusual, time-sensitive, or involves credentials, software or payments.
What Effective Awareness Training Should Teach Staff to Do
Effective training should teach a short decision pattern that employees can use under pressure. If a request arrives by phone or email and asks for action outside the normal workflow, staff should stop, confirm the request using a known contact method, and escalate anything that feels time-critical, financial, or technically unusual. That is more reliable than trying to detect every scam format individually.
It should also cover common social engineering techniques: impersonation, authority pressure, urgency, secrecy, spoofed domains, and attempts to move the conversation off the normal channel. The point is to help staff recognise manipulation, not just malicious content.
One important detail is software delivery. Employees should be trained not to install remote access tools, browser add-ons, or “helpful” utilities at the request of an unexpected caller or sender unless the request has been separately validated. Legitimate tools can still become the attack path when the user is persuaded to install them for an attacker.
Training is strongest when it tells people exactly what a safe verification step looks like in their environment, such as calling the listed help desk number, using an internal ticket, or confirming with a manager through a different channel. Vague advice to “be careful” is much less useful than a clearly defined process for challenged requests.
How to Measure Whether the Training Is Actually Working
The best measure is behavioural, not attendance-based. Organisations should look for whether employees pause, verify, and report suspicious requests before harm occurs. Completion of a module proves exposure to the material, but it does not prove that staff will use it correctly when they are rushed or pressured.
Useful signals include how often suspicious emails are reported, how often phone-based attempts are escalated, and whether employees follow the separate-channel rule when a request appears unusual. If the reporting rate rises while successful fraud attempts fall, the training is probably changing behaviour in the right direction.
It also helps to test the control with realistic simulations that reflect current fraud patterns. The value is not in tricking staff, but in checking whether the organisation’s verification habits hold up when the request looks routine, urgent, or comes from a familiar-looking identity.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while CIS Controls v8, NIST CSF 2.0, NIST SP 800-53 Rev 5 and OWASP ASVS set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-14 — Security Awareness and Skills Training | Training staff to spot social engineering and verify requests is a core awareness control. |
| Recommendation — Deliver recurring fraud-awareness training and test it with realistic simulations. | ||
| NIST CSF 2.0 | PR.AT-01 — All Users Are Informed and Trained | The subject is user training against email and phone fraud, which fits CSF awareness. |
| DE.CM-01 — Networks and Systems Are Monitored to Detect Potential Cybersecurity Events | Reported fraud attempts and suspicious activity need monitoring to validate awareness. | |
| Recommendation — Provide role-appropriate awareness training on social engineering and verification habits. Monitor for suspicious requests and use user reports as part of detection. | ||
| NIST SP 800-53 Rev 5 | AT-2 — Awareness Training | The question is fundamentally about teaching users to resist fraud and manipulate attempts. |
| AT-3 — Role-Based Training | Employees face different fraud scenarios by role, especially finance and support staff. | |
| SI-4 — System Monitoring | Awareness is strengthened by monitoring reports and suspicious activity triggered by fraud. | |
| Recommendation — Maintain recurring awareness training that addresses phishing, vishing, and fraud cues. Tailor training to role-specific fraud paths and escalation steps. Correlate user reports with alerting to spot fraud attempts early. | ||
| OWASP ASVS | V16 — Security Logging and Error Handling | User-reportable fraud attempts depend on logging and traceability when requests are abused. |
| Recommendation — Log suspicious authentication and support-request activity for investigation. | ||
| MITRE ATT&CK | T1566 — Phishing | Phone and email fraud often rely on phishing-style social engineering to obtain action or access. |
| Recommendation — Map training scenarios to phishing and related social-engineering techniques. | ||
Practitioner Guidance
What to prioritise: Put the strongest emphasis on verification behaviour, because that is where fraud campaigns usually succeed or fail. If a request would cause a payment, credential action, software install, or data transfer, staff should know the exact confirmation step before they act.
What to verify: Make sure the training matches the channels attackers actually use in your organisation, especially phone, email, and remote-support style requests. A generic phishing module is not enough if employees are also receiving voice-based impersonation or installer-prompt scams.
Common mistake: Treating awareness as a periodic compliance exercise instead of a decision-making control. Fraud resilience improves when staff learn a small number of repeatable checks and are encouraged to use them every time pressure appears.
Practitioner takeaway: The most effective training does not try to make employees suspicious of everything, it makes them consistent about one habit: pause, verify independently, and refuse to let urgency replace process.
Related resources from NHI Mgmt Group
- What do organisations get wrong about email security awareness training?
- When should organisations prioritise targeted coaching over broad security awareness training?
- When should organisations prioritize blocking malicious email before relying on security awareness training?
- What happens when organisations treat awareness training and email security as separate programmes?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org