Microsoft published something on September 9 that should change how you think about security training.
Attackers are calling employees on the phone, claiming to be IT, and saying their passkey or multi-factor setup needs an urgent update. Then they text a link to a fake Microsoft sign-in page. Once the employee signs in, the attacker registers their own device as the second factor and starts quietly reading mail and pulling files out of SharePoint and OneDrive.
Notice what's missing. No typos. No sketchy attachment. Nothing your team was trained to look for.
At a wealth management firm, the person who takes that call is usually your ops manager or a client service associate — helpful by reflex, handling statements all day. That's not a weak link. That's a job description an attacker read.
Training that works is short, frequent, and looks like the attack you'd actually get. If you're on Microsoft 365 E5 or Defender for Office 365 Plan 2, the simulator is already sitting in your Defender portal — you can run a campaign and assign follow-up training in an afternoon. There's a 90-day trial if you're not.
And one rule beats any training module: nobody from IT will ever call and ask you to re-enroll your sign-in. Say that out loud at your next staff meeting.
Worth sorting out before your next cyber renewal.
Want the next one in your inbox?
One practical Microsoft 365, Copilot, Azure, or security move per week — plain English, no pitch.
Subscribe via email