AI
Run a 30-Minute AI Phishing Drill With Your Team
October is Cyber Security Awareness Month, and the federal Get Cyber Safe campaign picked a theme for 2026 that fits small teams well: "Your best defence is you." Its kickoff page says it plainly: "In a world powered by artificial intelligence (AI), cyber threats can look more real than ever" (Get Cyber Safe, Cyber Security Awareness Month).
You don't need a security vendor or a full day off the tools to act on that. You need 30 minutes, a meeting room, and a printer. Here's a drill we'd suggest to any Burnaby or New Westminster owner with a team of five to fifty people, plus an honest look at what the research says it can and can't do.
Why AI changes the old phishing advice
For years the easy tell was bad spelling. That tell is fading. Get Cyber Safe, writing with the Canadian Bankers Association, notes that "AI can now create messages that seem more legitimate" and that it can scan social media profiles to mention specific details like a person's job or family (Get Cyber Safe, How cyber criminals are using AI). The same post warns that AI voice cloning is making phone scams, or vishing, more convincing, because it can "mimic the voices of real people."
The business data backs up why this matters. In Statistics Canada's survey of 2023, about 16% of Canadian businesses were impacted by cyber security incidents, and among those, scams and fraud were the most common method at 50% (Statistics Canada, The Daily, 2024). Identity theft jumped 11 percentage points to 31% of impacted businesses. Total recovery spending doubled to about $1.2 billion.
And here's the gap. Only 22% of businesses gave formal cyber security training to non IT staff in 2023, and just 26% had written cyber security policies, according to the same release. Most small teams have never practised this together.
The 30-minute AI phishing drill
Run it as a tabletop exercise, not a trick. Everyone knows it's a drill. Nobody gets named and shamed.
Before the meeting (about 20 minutes of your time)
Use any AI chat assistant your business already approves to help you draft six short sample messages. Three should look like routine mail your team really gets, such as a supplier invoice or a booking confirmation. Three should be fakes built on the patterns scammers use: a "new banking details" request from a vendor, a shared document login prompt, and an urgent note that seems to come from you.
Two rules here. Don't paste real customer names, invoices or account numbers into the AI tool; use made up details. And if the assistant declines to write something, that's fine; write the fakes yourself from the red flags below. Print each message on its own page.
Minutes 0 to 5: set the scene
Explain the theme and the one point that matters: with AI, a clean, well written email proves nothing. Tell people the goal is to slow down, not to be perfect.
Minutes 5 to 15: sort the pile
Hand out the six pages in pairs. Each pair marks every message "real" or "fake" and circles what tipped them off. Use the federal checklist, the 7 red flags of phishing:
- Urgent or threatening language
- Requests for sensitive information, including login pages
- Anything too good to be true
- Unexpected emails, like receipts for things you didn't buy
- Information mismatches, such as a sender address that's close but wrong
- Suspicious attachments with odd names or file types
- Unprofessional design, like blurry logos
Then reveal the answers. Pay attention to which fakes fooled people. If you want a way to judge how hard your fakes were, the NIST Phish Scale User Guide was built for exactly that: rating how difficult an email is for a human to detect, so click and report results have context.
Minutes 15 to 22: the voice call
Read this aloud: "It's Friday at 4:40. Your manager calls. It sounds exactly like them. They need a supplier paid today and the bank details have changed." Ask the room what they'd do.
The answer you want is a rule, not a feeling. Get Cyber Safe's advice is to verify identity "by contacting them through another method" when anyone calls with urgent demands for money or information. Agree on yours right now. For example: any change to payment details gets confirmed by calling the number already on file, never the number in the message.
Minutes 22 to 27: the reporting path
Decide, out loud, where suspicious messages go. Who do people tell? Do they forward it, screenshot it, or use a report button? Make sure no one feels silly for reporting a false alarm.
Then cover the outside channels. The Canadian Anti-Fraud Centre takes reports from victims and witnesses at reportcyberandfraud.canada.ca, and it recommends victims also contact local police. Get Cyber Safe's Cyber Month page also points people to forwarding spam texts to 7726.
Minutes 27 to 30: write down one change
End with a single process change, written down and posted. The payment verification rule is a strong candidate. Put a reminder on the calendar to rerun the drill in six months with new examples.
What the research says about training, honestly
We'd be doing you a disservice if we told you a drill makes your team phish proof. The evidence is mixed at best.
A 2025 study by Rozema and Davis at Purdue tested training on 12,511 employees at a US fintech firm. Lecture training and interactive training both showed no significant effect on clicks (p = 0.450) or reporting (p = 0.417) (Rozema and Davis, arXiv, 2025). Click rates averaged 10.4% overall and rose from 7.0% on easy lures to 15.0% on hard ones. The authors conclude the results support "defense-in-depth" and "changes to processes and technology to reduce reliance on humans."
That's why this drill spends most of its time on rules and reporting rather than spotting tricks. A callback rule for payment changes still works when someone is tired and the email is perfect. Spotting skills alone often don't.
Where this doesn't apply
- It's not a security program. One meeting won't replace multi factor authentication, a password manager, backups or email filtering. Get Cyber Safe's Week 2 material covers those basics.
- Live phishing tests need care. Sending surprise fake emails to staff is a bigger step. Microsoft's documentation, last updated July 2026, says its Attack simulation training requires a Microsoft Defender for Office 365 Plan 2 licence, with only a limited trial subset for E3 customers (Microsoft Learn). Talk to your team about it first, and check licensing before you plan around it.
- The Canadian stats skip the smallest shops. The Statistics Canada survey covered enterprises with 10 or more employees, and it only counted incidents businesses felt impacted them. A three person firm should read those numbers as context, not a forecast.
- If you're mid incident, don't run a drill. If money has already moved or an account is compromised, call your bank, your IT provider, your insurer and the police first.
- Regulated work has its own rules. Clinics, law offices and financial firms may have training or breach obligations a 30 minute session doesn't meet.
A quick illustrative example
Picture a 12 person renovation company in Metro Vancouver. *(Illustrative only; not a real client.)* In the drill, four of six pairs flag the fake login page, but only one pair questions the "new banking details" email, because it uses the supplier's real name and an invoice amount that looks normal. The fix that comes out of the meeting isn't more training. It's a sticky note on the bookkeeper's monitor: "Bank details changed? Call the number on file." That's the kind of outcome to aim for.
Sources
- Communications Security Establishment Canada, Get Cyber Safe. "October is Cyber Security Awareness Month in Canada." 2026. https://www.getcybersafe.gc.ca/en/cyber-security-awareness-month
- Communications Security Establishment Canada, Get Cyber Safe. "The 7 red flags of phishing." 2024. https://www.getcybersafe.gc.ca/en/resources/7-red-flags-phishing
- Communications Security Establishment Canada, Get Cyber Safe, with the Canadian Bankers Association. "How cyber criminals are using artificial intelligence (AI) for online threats." 2024. https://www.getcybersafe.gc.ca/en/blogs/cyber-criminals-are-using-artificial-intelligence-ai-online-threats
- Statistics Canada. "The Daily: Impact of cybercrime on Canadian businesses, 2023." 2024. https://www150.statcan.gc.ca/n1/daily-quotidien/241021/dq241021a-eng.htm
- National Institute of Standards and Technology. "The NIST Phish Scale User Guide is Now Available!" 2023. https://www.nist.gov/news-events/news/2023/11/nist-phish-scale-user-guide-now-available
- Rozema, A. T. and Davis, J. C. "Anti-Phishing Training Does Not Work: A Large-Scale Empirical Assessment of Multi-Modal Training Grounded in the NIST Phish Scale." arXiv:2506.19899, 2025. https://arxiv.org/html/2506.19899v1
- Royal Canadian Mounted Police, Canadian Anti-Fraud Centre. "Report fraud and cybercrime." 2025. https://antifraudcentre-centreantifraude.ca/report-signalez-eng.htm
- Microsoft. "Get started using Attack simulation training." Microsoft Learn, 2026. https://learn.microsoft.com/en-us/defender-office-365/attack-simulation-training-get-started
Want help turning the rules from your drill into something that sticks, like an AI assistant that flags payment change requests for a callback before anyone pays? Book a free call with Autana and we'll look at where AI can lower your risk, and where it shouldn't be trusted yet.
Want an AI employee for your business?
We install a 24/7 AI worker for businesses in Vancouver, Burnaby, and beyond. Book a free Discovery Call.
Book a call →

