You might think cybersecurity is strictly a “moat and castle” problem. The logic goes that you dig the moat deep enough with firewalls and build the walls high enough with encryption to keep your business safe.
But the modern threat landscape has shifted. The path of least resistance for a criminal is no longer hacking a complex server. It is hacking a busy human being.
The Human Firewall
This is where Security Awareness Training shifts from a compliance requirement to a critical strategy.
Technology filters data. Humans filter context.
A firewall cannot detect that an “urgent wire transfer request” from the CEO feels slightly out of character. An email filter cannot sense the social pressure applied by a fake IT support agent on the phone. Only a well-trained human can recognise the emotional manipulation that defines modern social engineering.
Why It Matters Now
In 2026, the gap between a secure company and a breached one usually comes down to a single moment of trust. Attackers are aggressively targeting the “human operating system” by using curiosity and helpfulness against your employees.
Whether they are scanning a QR code or answering a suspicious call. Upgrading the software in our employees’ minds is the only way to keep the software on their computers relevant.
The “Invisible” Threats
I want to highlight two specific threats that standard training often misses.
First is Quishing, or QR Code phishing. We train people to hover over links to check for danger. You cannot hover over a QR code. A malicious email can land in an inbox containing nothing but a legitimate-looking image of a QR code. It might ask you to scan to update MFA settings or validate parking. Scanning that code takes the user off the protected corporate network and onto a personal device where visual tricks are harder to spot.
The second tactic is Hybrid Vishing. This attack begins with a deceptive email regarding a fake invoice for a high-cost subscription. Because the email contains no malicious links, it often bypasses standard filters. The trap is a “support” phone number. When the employee calls to dispute the charge, they believe they are in control. In reality, they are speaking directly to a bad actor. This inbound nature of the call lowers the employee’s guard and increases their susceptibility to social engineering.
Looking at Our Own Data
At Phase Pacific, we realised that we had to protect ourselves before we could protect our clients. We looked at the data to see if training actually worked for us.
We used the KnowBe4 platform to test our own team. The results were clear.
After running consistent simulations on these advanced threats, we saw our Phish-Prone Percentage drop from 27.3% down to just 1.9%. This represents a total reduction in risk of 25.4%, meaning our team is significantly better equipped to identify and neutralise scams than they were six months ago.
Our internal data showing the reduction in risk over the last 6 months.
Even better, we saw our Reporting Rate climb from 5.5% to 28.8%, a massive 23.3% increase in proactive flagging. Our team has transitioned from simply ignoring suspicious messages to actively reporting them, creating a human firewall that protects the entire organisation.
The Takeaway
Technology alone cannot catch everything. When an attack bypasses the filter or moves offline, your last line of defense is your people.
Our internal numbers prove that security awareness reduces risk. As a KnowBe4 partner, we can help you benchmark your current risk and implement the strategy that secured our own operations.
Let’s Talk About Your Strategy
You have seen our numbers, and now we’d love to help you improve yours.
You don’t have to navigate these new threats alone. We can review your current security awareness strategy and show you exactly how we configured the KnowBe4 platform to get these results.
KnowBe4 Security Awareness Training Brochure | Contact us
Sign up for our newsletter | KnowBe4




