Ten Employees Clicked the Fake Invoice: Phishing Simulation at a Singapore Trading Company
A composite scenario from Singapore: a 70-person trading company runs its first phishing simulation almost as an afterthought, and ten people click a fake supplier invoice in a single afternoon. How to read a first click-rate, why zero reports is a worse signal than ten clicks, and why the programme — not the platform licence — is the thing that changes outcomes.
The short answer: A first phishing simulation is a measurement, not a fix. When a Singapore trading company finally ran one, ten people clicked a fake supplier invoice in a single afternoon — not because training had never happened, but because nobody had ever measured who would actually fall for it. What changes outcomes is a recurring, managed programme, not a licence.
The company in this article is a composite. It is not a named client, and the numbers in the scenario are illustrative. The commercial detail — what a managed phishing simulation programme includes, how it is priced, and what it does and does not cover — is real and taken from what Brocent actually sells today.
Why Singapore trading companies are an unusually good phishing target
Singapore's trading and commodity houses run on email. A mid-sized firm moving goods between Southeast Asian suppliers and buyers in North Asia or Europe will process supplier invoices, shipping documents, letters of credit, payment instructions and freight bookings almost entirely through a shared inbox and a handful of individual ones. The workflow is high-volume, deadline-driven and routine. Somebody in finance opens forty PDF attachments a day and thinks nothing of it.
That is exactly the workflow business email compromise is designed to exploit. An attacker does not need to break anything technical. They need one person, on a busy afternoon, to treat a fraudulent invoice as the forty-first ordinary one. The pattern is so well-established in this sector that it has a shape: a supplier the company genuinely uses, an invoice for an amount that is plausible but not alarming, and a note that banking details have changed.
Two things make Singapore firms in this sector particularly exposed. The first is structural: a trading company with fifty to eighty staff usually has a finance team of four or five people with real payment authority and no dedicated security function sitting behind them. The second is linguistic. Staff work across English, Mandarin and Bahasa with counterparties in half a dozen countries, so an email written in slightly odd English from an unfamiliar address is not automatically suspicious — it is Tuesday.
The result is a company where the technical controls are usually fine and the human layer has never been tested. Spam filtering catches the obvious volume. Multi-factor authentication is switched on. Nobody, however, can answer the question that actually matters: if a convincing fraudulent invoice arrived tomorrow, how many of our people would act on it?
The scenario: one video, years ago, and an assumption
The composite company here employs about seventy people across an office in the CBD and a small operations team near the port. It has run managed IT for a few years. Endpoint protection is in place, patching is current, and the finance team uses multi-factor authentication on everything that touches banking.
Security awareness, such as it is, consists of a video that new joiners watch during onboarding. It covers passwords, suspicious links and a slide about not plugging in unknown USB drives. It was recorded some years ago. Nobody has watched it since their first week, and nobody has ever been asked to demonstrate that any of it stuck.
The operations director's mental model is common and reasonable-sounding: our people handle supplier documents all day, so they know what a real invoice looks like better than any training module could teach them. That belief is the thing the first simulation tests.
The simulation itself is run almost as an afterthought — an add-on discussed during a plan review, agreed to because it seemed like a sensible box to tick before a client's vendor questionnaire came round again. A single campaign is scheduled. The template is a supplier invoice notification with a link to view an attached statement. It goes out on a Wednesday afternoon.
By the end of the day, ten people have clicked. Two of them entered credentials on the landing page. One forwarded the email to a colleague in finance with the note "can you check this one". Nobody reported it to IT.
Ten out of seventy is not an unusual first-campaign result. That is the part that surprises people most. The operations director had privately expected one or two, and had half-planned a quiet word with whoever they turned out to be. Instead the number described the whole company rather than a couple of careless individuals — and no quiet word was going to fix it.
What that number actually tells you, and what it does not
A first-campaign click rate is a diagnostic. Read correctly, it tells you three things and misleads you about a fourth.
It tells you the scale of exposure. Ten clicks means the probability that a real campaign lands successfully is close to one. It tells you where the exposure sits — in this scenario, disproportionately in operations and logistics rather than finance, which is the opposite of what everyone assumed. And it tells you something about reporting culture: zero reports is a worse signal than ten clicks, because it means even the people who spotted it did nothing, and a real attack would run unopposed for as long as the attacker wanted.
What it does not tell you is whether your people are careless. A single campaign has no baseline and no trend. It captures one template, sent at one moment, to a company that had no particular reason to be alert. Treating that number as a verdict on individuals is the most common way a first simulation does more harm than good — it produces a round of blame, a defensive workforce, and a strong internal argument against ever running another one.
This is the point where most companies of this size get stuck. They have a number. They do not have a programme. And the market they turn to for help is not organised to give them one.
The problem with how this is sold in Singapore
Search for phishing simulation in Singapore and the results are dominated by comparison listicles — ten providers, twelve platforms, a table of features — and by platform licences priced per seat per year. A seventy-person company can easily end up looking at several thousand dollars a year for software.
The licences are capable. That is not the issue. The issue is that a platform licence is a tool, and a tool needs an operator. Buying one means somebody inside the company now owns: choosing templates plausible for a Singapore trading business rather than a US healthcare provider; scheduling campaigns so they do not all land in the same week as month-end; interpreting results without turning them into a disciplinary process; assigning follow-up training to the people who actually need it; and producing a report that a director or an insurer will accept.
In a company with no security function, that person is the office manager or the finance lead, on top of their real job. What happens in practice is predictable: the first campaign runs, the second is delayed, the third never happens, and eighteen months later the licence renews on a subscription nobody has opened since.
The listicle format makes this worse, because it compares platforms on features and price and never on who does the work. Two providers can look nearly identical on a comparison table while differing completely on the only question that determines whether the programme still exists next year.
The detail most companies skip: two people entered credentials
In the scenario, ten clicks got all the attention. The two credential entries mattered more.
A click on a link is exposure. Typing a password into a page that looks like your mail provider is a compromised account, and in a real incident the clock starts there. What follows is well documented: the attacker signs in, sets an inbox rule that quietly moves supplier correspondence to an archive folder, watches an invoice thread for a few weeks, and then joins it with banking details of their own. The finance team never sees a suspicious email, because the fraudulent message arrives inside a conversation they were already having.
This is the reason multi-factor authentication earns its place, and also the reason it is not a complete answer — attackers increasingly harvest session tokens or fatigue users into approving prompts. It is also why a simulation programme should be paired with the ability to detect and act on the thing it demonstrates is possible: mailbox rule creation, impossible-travel sign-ins, unusual forwarding. A simulation tells you the door can be opened. Monitoring tells you when it has been.
For the composite company, the practical follow-up after the first campaign was not a lecture. It was resetting the two affected accounts, checking the tenant for forwarding and inbox rules created in the preceding weeks, and confirming that a change of supplier bank details had a verification step that did not depend on email. None of that is training. All of it is the work a first simulation should trigger.
Brocent's perspective: the programme is the product, not the platform
Brocent has been running IT operations for companies across Asia since 2007, with a Hong Kong office since 2016 and headquarters in Singapore since 2021. Our view on awareness training is shaped by watching which programmes survive contact with a busy operating business.
The ones that survive are the ones the company does not have to run.
That is the deliberate design of Security Awareness Training as we sell it. Global platforms sell you the software and leave you to build campaigns, chase click rates and write the report. We run the whole programme: a named engineer selects the templates, sends the campaign, and delivers a per-department results report. You review and approve. We do the operating.
Three practical consequences follow from that model.
Templates are chosen for your business, not pulled from a global library. For a Singapore trading company that means supplier invoice and shipping document lures, in the languages your staff actually work in, timed against your calendar rather than a vendor's default schedule.
Cadence is a service commitment rather than an intention. Quarterly is the effective baseline for most SMEs; higher-risk groups — finance, HR, executives — benefit from monthly campaigns. Both run whether or not anyone internally remembers to start them.
Reporting is per-department and trend-aware. A single click rate is noise. Four campaigns across a year, broken out by department, is a picture: whether operations improved after targeted training, whether reporting rates rose, whether the finance team's exposure narrowed.
There is one thing we are firm about, and it runs against how this is usually marketed. A simulation programme is not a standalone security purchase. It closes one specific gap in a baseline that also needs current patching, endpoint protection, email filtering, credential management and monitoring. Sold on its own, to a company without those things, it measures a problem you cannot yet fix. That is why we treat it as part of managed IT support rather than as a product to be shopped against a comparison table.
What a managed programme looks like in practice
For a company the size of the one in this scenario, the shape is straightforward.
A baseline campaign, read as data. The first simulation establishes where you are. It is explicitly framed to staff and management as a measurement exercise rather than a test with consequences — which is what makes the second one honest.
A scheduled cadence with varied templates. Quarterly at minimum. Templates rotate across invoice fraud, credential harvesting, internal impersonation and delivery notification patterns, so the programme measures judgement rather than familiarity with one email.
Training triggered by behaviour, not by the calendar. Someone who clicks gets a short, specific module within days, while the moment is live. Someone who reports gets acknowledgement. Everyone else does not sit through a generic annual course they do not need — which is the single biggest reason awareness programmes generate resentment.
Per-department results, with individuals protected. Management sees department-level trend. The programme does not become an HR instrument, because the moment it does, staff stop reporting and start quietly deleting.
A report that goes outward. Vendor security questionnaires, client due-diligence packs and cyber-insurance applications increasingly ask whether simulated phishing runs and at what cadence. A dated report answering that is worth having before somebody asks for it.
Escalating cadence for the people who need it. Repeated failures are a coaching problem, handled with more frequent and shorter exposure for that group, not a disciplinary one. The expanded training library at the monthly cadence covers deepfake and voice-phishing patterns, which are increasingly what actually arrives.
Pricing is per user per month with a ten-seat minimum, and there is a one-time option if you want to run a single campaign and see the results before committing to a cadence. The published managed rate starts from US$2.50 per user per month — in practice at or below what a comparable self-serve platform licence costs, with the operating work included rather than handed back to you. Current figures are on the pricing page.
Three ways a Singapore company handles phishing simulation
A one-off annual test
- What you get: A number, once a year, and a box ticked on a questionnaire.
- What it costs: Low, and mostly in internal time.
- Where it breaks: No baseline, no trend, no way to tell whether anything improved. A single data point cannot distinguish a company that got better from one that got a gentler template. Follow-up training, if it happens at all, is generic and late.
- Who it suits: A company that genuinely only needs the questionnaire answered, and is honest with itself about that.
A self-serve subscription licence
- What you get: A capable platform, a large template library, dashboards, and full control over campaign design.
- What it costs: Typically per seat per year, often on a multi-year term. Global platform list prices run roughly US$1.50–3.75 per seat per month as of July 2026.
- Where it breaks: It requires an internal operator with time and judgement. In a company with no security function, cadence decays, templates go stale, results go uninterpreted, and the renewal arrives before the second campaign does.
- Who it suits: A company with an in-house security or IT lead who has both the capacity and the mandate to run it properly.
A managed phishing simulation programme
- What you get: A named engineer who selects templates, runs campaigns on an agreed cadence, delivers per-department results, and assigns targeted follow-up training. Trend reporting across campaigns. Reports suitable for management, clients and insurers.
- What it costs: Per user per month from US$2.50, ten-seat minimum, with quarterly and monthly cadences and a one-time single-campaign option.
- Where it breaks: It is not a substitute for the rest of a security baseline, and we will say so during scoping rather than after.
- Who it suits: A company of roughly 30–150 staff with no dedicated security function that wants the programme to still be running in two years.
Frequently asked questions
What is a normal click rate for a first phishing simulation?
There is no single benchmark worth quoting, and any provider offering one precisely is selling certainty they do not have. What matters more than the absolute number is the direction over subsequent campaigns and the reporting rate alongside it. A company whose click rate falls modestly but whose reporting rate climbs sharply is in materially better shape than the raw click figure suggests, because reporting is what actually shortens an attacker's window.
How often should phishing simulations run?
Quarterly is the effective baseline for most SMEs. Higher-risk groups — finance, HR and executives, who are targeted more precisely and hold more authority to move money — benefit from monthly campaigns. Both cadences are available as managed programmes, so the schedule is a commitment we keep rather than a reminder in somebody's calendar.
How is this priced compared with a per-seat platform subscription?
The managed programme is priced per user per month from US$2.50, with a ten-seat minimum and per-seat cost decreasing at higher tiers. Comparable self-serve platform licences sit in a similar per-seat band, but the licence price does not include anyone to operate it. The honest comparison is not licence versus licence; it is licence plus internal time versus a programme somebody else runs. Current figures are on the pricing page.
Does this include training, or only testing?
Both. Simulation without follow-up training measures a problem without addressing it. The programme includes core awareness modules, with an expanded library at the monthly cadence covering deepfake and voice-phishing patterns, and training is assigned to the people whose behaviour indicates they need it rather than pushed to everyone annually.
Can the results be reported to management or to an insurer?
Yes, and this is increasingly why companies start. Results are delivered per department, with trend across campaigns at the higher cadences and executive or board-ready reporting at the enterprise tier. Cyber-insurance applications and client due-diligence questionnaires commonly ask whether simulated phishing runs and how often; a dated report answers that directly.
Is this worthwhile for a company of seventy people?
Yes — arguably more than for a larger one. A seventy-person company has real payment authority distributed across a handful of people and no security function standing behind them. The minimum is ten seats, so the programme scales down cleanly, and at this size a single avoided fraudulent payment covers years of programme cost.
What happens to employees who fail repeatedly?
They receive more frequent, shorter, more targeted exposure — not disciplinary action. We report at department level specifically so the programme does not become an HR instrument. The moment staff believe a simulation can be used against them, reporting collapses, and reporting is the behaviour with the most defensive value.
Do we need anything else in place first?
A baseline: current patching, endpoint protection, email filtering, multi-factor authentication and credential management. If those are missing, a simulation will accurately measure a risk you are not yet positioned to reduce. If you are unsure what you have, that is a reasonable thing to establish before the first campaign rather than after.
Where this fits: one part of an ongoing plan
The useful lesson from the composite company in this article is not that ten people clicked. It is that nobody knew they would, and that a single afternoon's measurement changed the conversation from "we assume our people are careful" to "here is where we are, and here is the trend we are managing".
That shift only holds if the programme keeps running. A simulation is a diagnostic; a managed cadence is treatment. For most companies of this size the practical route is to fold it into the plan that already maintains the rest of the baseline — patching, endpoint protection, monitoring and credential hygiene — rather than to buy a separate licence that needs an operator you do not have. Our managed IT security services cover that baseline, and managed IT support is where the awareness programme sits alongside it.
If you want to see where you actually stand, the sensible first step is a single baseline campaign and an honest read of the result. Talk to us about scoping one for your team.
Share:
Ready to take action?
Turn these insights into a roadmap for your business.
Book a 15-minute no-obligation consultation with our APAC IT experts. We'll review your current setup and provide a tailored IT roadmap within 24 hours.
Free Checklist
10 Critical Checks Before Expanding IT to Greater China
PIPL compliance, network segmentation, bilingual helpdesk setup, and more — everything your IT team needs before Day 1 in China.
Request the checklist →📬 Monthly Asia IT Insights
China compliance updates, cybersecurity alerts, and IT tips for APAC teams — once a month.
No spam. Unsubscribe anytime.