Phishing Training That Sticks
Last verified: August 2026
Phishing is THE 2026 small-business threat — AI-written email, voice-cloned bosses, QR-code "quishing," MFA-bombing, the wire-transfer trap. Here's the honest comparison of training platforms, the monthly cadence that actually changes behavior, the non-shame conversation when somebody clicks, and the first-60-minutes playbook every owner should have memorized.
Phishing is THE small-business threat in 2026
Most small-business owners I meet still picture cybercrime as a hooded teenager in a basement. It isn't. In 2026, the bulk of small-business cyber losses start with an email — often a very good email — that fools one person on the team into clicking a link, opening an attachment, or wiring money. I service small businesses across Portage County — salons in Kent, landscapers in Ravenna, two HVAC shops in Aurora, an accountant in Streetsboro — and I've seen phishing hit every one of them at least once in the last two years. The shops that had training got lucky. The shops that didn't have training paid for it.
Three things changed in 2024-2025 that made phishing much harder to spot: AI tools that write grammatically perfect English, voice-cloning that needs only 3 seconds of audio to clone the boss, and QR-code phishing that bypasses every email filter your IT person set up. The old advice ("look for spelling mistakes") doesn't work anymore. Modern training has to match modern bait.
The story that paid for itself in one phone call
A Streetsboro accountant called me last spring. Her bookkeeper got an email that looked exactly like one of their clients, asking to change the bank account for the next wire. The bookkeeper called the client (by the phone number she already had, not the one in the email) and the client said "I didn't send that." That phone call saved them $38,000. The whole reason it worked: the accountant had a written rule that wire-account changes get verified by phone, no matter what. One sticky note on a monitor. $38,000 saved.
What's in the 27-page PDF
- Why phishing is the #1 small-business threat now — the three numbers that ought to scare you.
- What modern phishing looks like in 2026 — AI-written email, voice-cloned bosses ("vishing"), QR-code phishing ("quishing"), MFA-bombing.
- The eight bait patterns Bill sees this year: invoice attachment, M365 password expiry, DocuSign request, payroll change, gift-card request from "the boss," calendar invite with malicious link, QR code, MFA-bombing.
- Honest comparison of KnowBe4, Hoxhunt, Curricula / Huntress, and free CISA — features, fit, approximate pricing (verify current).
- Bill's pick (KnowBe4 for most, Hoxhunt for engagement, free CISA when budget is zero) and the tradeoffs.
- The free path — running a credible $0 phishing program using CISA, FTC, and FBI IC3 resources.
- Why monthly cadence beats annual — the memory-decay argument and the graduated-difficulty principle.
- What a good simulation looks like — the difficulty progression, never-blame culture, the metric that matters.
- The "you clicked it" non-shame conversation — manager script, with the lines you should never say.
- MFA-bombing defense — number matching in M365 and Google, hardware keys for the owner.
- Business Email Compromise (BEC) and the wire-transfer trap — three rules written down.
- Vendor Email Compromise (VEC) — when the attacker is inside your vendor's email, not yours.
- The verify-by-calling SOP — the single rule that stops the most expensive scams.
- Setting up the Phish Alert button in M365 and Google, plus the phish@ shared inbox.
- The team reporting workflow — what happens between the click and threat containment.
- The first 60 minutes if somebody fell for one — minute-by-minute incident playbook.
- The 15-minute new-hire phishing intro — day-1 conversation script.
- The quarterly tabletop exercise — four scenarios you rotate through.
- The 90-day rollout checklist and the monthly/quarterly maintenance.
- The ten common mistakes Bill sees weekly.
Why I wrote this
Most small-business phishing advice is written by Fortune 500 security consultants for IT departments. That's not us. A 4-person plumbing crew doesn't have an IT department; they have a busy owner and a Google Workspace account they're not sure how to lock down. This guide is for that owner — the steps that work for 2-20 people, the tools that don't take a sysadmin to operate, the playbook that survives after the consultant leaves. — Bill
Want me to roll it out for you?
$99 flat per-visit — no tiers, no surprises. I pick the platform, deploy the Phish Alert button, turn on MFA number-matching, write your wire-transfer SOP, run the first simulation, and walk you through the first quarterly tabletop. 30-day come-back-free guarantee. Optional $39 Monthly Support Plan for unlimited phone & text help.
Would you rather I just do this for you?
No shame in it — plenty of folks would rather hand it off, and that's what I'm here for. I'll come to your home, set it up right, and make sure it's working before I leave. Flat $99 per visit — no jargon, no upsell, and every visit is 30-day come-back-free.
Not a hardware job? I can often fix it remotely for $49 — a secure screen-share, up to 2 hours, that you watch the whole time and can end whenever (included free for $39/mo Support Plan members, and it counts toward the $99 if it turns out I need to come out).