A falling click rate is the wrong thing to be proud of.
Most organisations can show a training certificate and a simulated-phishing click rate that went down this year. Neither says much about whether a real attack would succeed. A phishing awareness programme in Nigeria that runs once a year and counts only who clicked is a record of training, not a control. The people running business email compromise against finance teams are not slowed down by a module somebody watched in January.
The goal is narrow. A targeted employee notices something is off and reports it. And when someone does get fooled, one mistake does not become a payment to the wrong account. Both are behaviours, and both can be measured.
This piece covers the human programme. The technical baseline under it, from mail filtering to SPF, DKIM and DMARC, is set out in our cybersecurity essentials for Nigerian SMEs. Do that first. Training people to spot forged mail from your own domain is wasted effort if anyone in the world can still send it.
Why click rate is the wrong scoreboard
Click rate is easy to measure, which is why it dominates. It is also easy to move without changing anything. Make the simulations easier and it falls. Run the same templates every quarter and staff learn the templates, not the attack. Worst of all, people who quietly delete anything suspicious score perfectly, and your security team learns nothing about the live campaign landing in other inboxes.
Click rate also casts the employee as the failure. Opening attachments is the job. HR opens CVs. Accounts opens invoices. A programme built to shame clickers teaches people to hide mistakes, and a hidden mistake is the expensive kind. Change the question from "who clicked" to "how fast did we find out, and what happened next".
A programme that runs all year
Behaviour fades. A skill practised once a year is not a skill. The programme has to run continuously, and it does not need a large team to do it. It needs an owner with a calendar, and the discipline to act on what the numbers say.
Simulate on a steady cadence. Monthly or every other month suits most organisations. Rotate the theme and the difficulty so staff learn the cues, not your templates. Build the lures from the fraud that actually reaches Nigerian inboxes: a supplier announcing new bank details, an urgent instruction that appears to come from a director, a fake LPO chasing payment, a login page asking for a mailbox password. When someone falls for a simulation, show a short page at once explaining the cues they missed, with no penalty. That correction, at the moment of the mistake, does more than any annual course.
Weight the effort by role. Not everyone carries the same risk.
- Finance and accounts payable are the main target for invoice fraud and changed bank details. They need payment-themed simulations more often than anyone else, and a fixed rule described below.
- Executives and their assistants are impersonated in authority fraud and are often left out of training out of deference. That exemption is the gap. The fraud works because the assistant believes the instruction came from the principal.
- HR and procurement staff open unsolicited files as part of the job, so their simulations should look like their real inbox.
- IT and anyone with admin rights hold the credentials that unlock the most. They get the hardest simulations and no exceptions to multi-factor authentication.
The rule that matters more than training
The most reliable defence against changed-bank-detail fraud is not awareness. It is a procedure no single person can skip under pressure. Any change to a supplier's bank details, and any unusual payment instruction, is confirmed by a phone call to a number already on file. Never a number in the email. Never a reply to the email. A second person approves the change before the next payment goes out.
Write it down and tell suppliers it exists. Awareness lowers the odds of a mistake. The procedure makes sure one mistake cannot release money on its own. You need both, but if you can only do one this month, do the procedure.
Make reporting the behaviour you reward
A reported phishing email is an early warning. It lets someone pull the same message from every other inbox before a second person acts on it. A deleted one protects one person and leaves everyone else exposed.
The organisations that improve are the ones where reporting a suspicious email takes one click and is quietly expected. The security team then hears about a live campaign within minutes, not after the money has left.
Make it effortless. A report button in the mail client beats an address nobody remembers, and Microsoft 365 and Google Workspace can both provide one. Thank every report, including the false alarms, because punishing a wrong guess teaches people to stop reporting. And when a report stops a real campaign, tell the organisation, without naming anyone. People repeat behaviour they can see matters.
Measure what predicts a contained incident
Replace the single click-rate number with a few measures that track the behaviour you want.
- Report rate. The share of simulated and real phishing that gets reported. This is the headline. If it rises, the programme is working.
- Time to first report. How long until the first person flags a given campaign. The shorter it is, the fewer people the campaign reaches.
- Repeat susceptibility. People who fall for several simulations in a row. This small group is where coaching and tighter technical controls should go.
- Results by role. The same measures for each high-risk role on its own, so an average does not hide the groups that matter most.
- Real outcomes. Payment fraud attempts stopped before money moved, and how long any compromised account stayed in an attacker's hands.
Report these to leadership in plain language. Section 39 of the Nigeria Data Protection Act 2023 requires organisations that handle personal data to put appropriate technical and organisational measures in place to secure it. A trend line showing reporting rising in finance and the executive office is evidence that one of those measures is operating, which a completion certificate is not.
What the local setting changes
Most organisations spread across Abuja, Lagos and Port Harcourt cannot gather everyone in one room, so the programme runs and reports centrally. Some staff work on shared machines or mainly on phones over mobile data, so keep the material short and readable on a phone, not an hour of video. Contract staff and new joiners should be enrolled in the simulations on their first week, automatically. And when imported security licences are priced in dollars, a well-run programme and a firm payment procedure are some of the cheapest protection you can buy.
Where we fit, and where we do not
Phishing simulation is not one of our service lines. The programme above is yours to run, or to buy from a specialist. What we set up is the layer underneath it: multi-factor authentication enforced for everyone, legacy sign-in blocked, mail authentication on your domain, and managed devices. That is the work described in our Entra ID and Intune write-up for a law practice, and it is part of our deployment and implementation work for small and mid-sized firms. If ransomware is the worry behind the phishing question, our ransomware readiness guide covers recovery.
Frequently asked questions
How often should we run phishing simulations?
Often enough that recognition stays sharp, not so often that people tune out. Monthly or every other month suits most organisations, with the theme and difficulty rotated and payment lures included. Steady, varied practice builds the habit of stopping and reporting. A single annual exercise has faded long before the next one.
Is click rate a useful measure of a phishing awareness programme in Nigeria?
On its own, no. It is easy to move without changing real risk, and a programme built around it tends to shame staff into silence. Make report rate and time to first report the headline measures, broken down for finance and executives, and tie them to real outcomes such as fraud attempts stopped before money moved.
Should senior executives be included in simulations?
Yes. They and their assistants are the people attackers impersonate and target in authority fraud. Leaving them out creates the exact gap the fraud uses. Include them, and back it with the call-back rule for any payment or bank-detail request.
Does the NDPA require phishing training?
The Act does not name phishing training. Section 39 requires appropriate technical and organisational measures to keep personal data secure, and staff awareness is a normal part of that. A programme that produces trend data gives you better evidence of an operating measure than a one-off training record.
Where to start
This week, write the payment call-back rule and get the finance lead and one director to sign it. Next month, add a report button to your mail client and run one payment-themed simulation on the finance team. If the controls underneath are not in place yet, send us what you run on through our contact page and we will tell you which of them you are missing.



