The practical handbook for IT & Security Managers

Take your phishing click rate from 60% to under 5%. Sustainably.

Another awareness campaign won't do it. Get Phishing Under Control is the experience- and evidence-based playbook that combines hard technical controls with real behavioural science — written by a security veteran who went back to university to understand why people click, and then proved the answer at scale.

Available on Amazon in Kindle and paperback editions.

60%
click rate after the full programme
0
programme phases, from diagnostic to governance
0
years of security experience behind it
Book cover of Get Phishing Under Control by Emmanuel Nicaise — the practical handbook for IT and Security Managers

What the programme actually delivers

In one organisation tracked from its very first simulation, the click rate fell from 60% to under 5% — not with fear or blame, but with layered technical controls, realistic exercises, and interventions grounded in cognitive psychology.

60% 40% 20% 0% Baseline · 60% Technical controls · 38% Detection aids · 24% Exercises · 15% Behaviour change · 9% Sustained <5%

Illustrative trajectory of the organisation tracked in the book, from first simulation to a sustained sub-5% click rate.

  • Exercises alone plateau above 10%. Without behavioural training and technical controls, click rates stall — the book shows how to break through.
  • Reporting is the metric that matters. A team that clicks but reports fast beats a team that stays silent. You'll measure both, properly.
  • Statistics you can defend. Confidence intervals and the Siadati parallel model separate real change from noise before you report it to the board.

Technology and psychology, together

Most phishing programmes fight on one front and lose on the other. This handbook runs both.

The technical front

Reduce the attack surface before a single human is tested: SPF, DKIM and DMARC done right, web filtering, sandboxing, warning banners, the report button, and the belt-and-suspenders controls that limit the damage of the click that will eventually happen anyway.

The psychosocial front

Change behaviour without fear or blame: dual-process theory, habits versus heuristics, nudges, personas, and the teachable moment — the science of why smart people click on a busy Tuesday, and what actually stops them from doing it again.

Seven phases to get there

Every action is tagged MUST, SHOULD or ADVANCED, so a small team knows exactly where to start — and a mature programme knows what to optimise next.

0

Diagnostic

Score your current posture on a 100-point assessment and let the result route you to the phase where your energy pays off most.

1

Technical Controls

Stop phishing emails from reaching users: SPF, DKIM, DMARC, web filtering, reputation filters, sandboxing — and the controls that contain the inevitable click.

2

Visibility

Help people detect what gets through: polymorphic warning banners, full sender addresses, homoglyph defences, and the one-click phishing report button.

3

Exercises

Run realistic simulations ethically: communication plans, platform selection, safelisting, an annual exercise plan and a code of ethics your works council will sign off.

4

Behaviour Change

Move beyond "awareness": evidence-based interventions built on dual-process theory, habits, nudges and user personas — spices to be dosed, not dumped.

5

Metrics

Measure what matters with the Siadati parallel model and confidence intervals — and stop reporting noise as improvement.

6

Governance

Make it stick: a human-risk register, a policy framework based on nulla poena sine lege, empathy, and results communication that builds trust.

Depth where you need it

Eight masterclasses take you deeper — from SMTP spoofing mechanics to sampling error and the psychology of goal-oriented action. Six annexes hand you the paperwork ready-made.

01

Quick-Start Minimum

The three controls to deploy first — SPF/DKIM/DMARC, external banners, a report button — then exercises every three weeks. No waiting for perfect.

02

Masterclasses

In-envelope spoofing, SPF & SenderID, metrics and ratios, sampling error, attitude and behaviour, habits and heuristics, communication and education.

03

Ethics by design

A publishable code of ethics, an advisory board that approves every scenario, and GDPR-grade data handling — the programme your DPO will actually endorse.

04

Platform selection

58 criteria across usability, authentication, tracking, integration, data protection and licensing — with the traps vendors won't mention.

05

Ready-made communications

Seven battle-tested messages, from the CEO announcement to the teachable-moment page — every word chosen to build trust, not fear.

06

Defensible metrics

Binary behaviour coding, false positives and negatives, the parallel model, confidence intervals — and the vanity metrics to refuse.

Run the programme, don't retype it

Every template from the book's annexes, ready to adapt: Word documents for the communications and governance, Excel calculators for the statistics, and HTML you can paste into Exchange Online today. Free to download, no email required.

WORD

Sample Communications Pack

All seven programme communications: CEO announcement, works-council notification, manager briefing, teachable-moment page, reporter thank-you, results note, scenario approval.

Download .docx ↓
WORD

Code of Ethics Template

The publishable code that proves your programme has boundaries: objectives, prohibitions, treatment of participants, transparency and governance.

Download .docx ↓
WORD

Data Handling & Privacy Notice

What you collect, why, who sees it, when it disappears — the document your DPO and works council will ask for first, pre-written.

Download .docx ↓
WORD

Advisory Board — Terms of Reference

A deliberately lightweight board: composition, veto rules, quorum and email-approval flow that still works three years in.

Download .docx ↓
WORD

Awareness & Culture Policy Outline

The behaviour-change policy that situates exercises in a larger strategy: lifecycle, channels, target groups, responsibilities.

Download .docx ↓
EXCEL

Phishing Metrics Calculator

Confidence intervals at 95/99%, a two-proportion significance test, and a full Siadati parallel-model tracker — know noise from real change.

Download .xlsx ↓
EXCEL

Platform Selection Matrix

All 58 selection criteria from Annex A with priorities, weighted scoring for two vendors, and automatic red-flag detection on Essential gaps.

Download .xlsx ↓
HTML

Code Snippets Pack

Five rotating external-warning banners for Exchange Online (gaze cue included), a styled teachable-moment landing page, and a reporter thank-you email.

Download .zip ↓

Templates are provided as-is under the terms described in the book. Replace every <PLACEHOLDER> and have your DPO, legal counsel and employee representatives review before first use.

If you only do three things this quarter

The book's quick-start minimum — deploy these first, in this order, then start exercising at least every three weeks. Don't wait until everything is perfect.

Authenticate your email

Configure SPF, DKIM and DMARC on all your email domains, so attackers can't trivially impersonate you.

Flag external mail

Enable an external email warning banner in your email platform — and rotate variants to beat habituation.

Deploy a report button

One click to report. It's the single most valuable security behaviour your organisation can build.

Emmanuel Nicaise

Emmanuel Nicaise has spent more than thirty years in information security — long enough, he admits, to qualify as something of a dinosaur. He started out configuring Novell networks and SCO Unix servers, then moved into security when the Internet was still a novelty, and later into risk management, eventually serving as a CISO. Along the way, he wondered why so many security problems kept coming back to the same place: people.

So he went back to university and earned a master's degree in clinical psychology, followed by doctoral research at the Université libre de Bruxelles on epistemic vigilance — the mental processes we use to decide whom and what to trust — and how it shapes our ability to detect phishing.

That research found a practical testing ground when a large international financial institution asked him to build its human-security programme. Rather than running yet another awareness campaign, he used the scientific evidence available to design an evidence-based — and evidence-collecting — behaviour change programme. The lessons learned there, and with the organisations he has helped since through his consultancy, Apalala, became the foundation of Get Phishing Under Control.

Emmanuel holds the CISSP, CISA and CISM certifications, co-founded and chaired the (ISC)² Belux Chapter, and speaks regularly at security conferences such as BruCON and Hack.lu. He lives in Belgium, where he remains happily curious about the human side of technology — including what AI reveals about our own cognition.

Ready to get phishing under control?

Join the security leaders who stopped blaming users and started changing the odds. Technical depth, behavioural science, and every template you need — in one handbook.

Get the book

Kindle & paperback editions on Amazon.