B BROCENT

The Invoice That Almost Went Through

A composite scenario from Hong Kong: a small marketing agency nearly pays a fraudulent supplier invoice, caught only because a staff member happens to phone to confirm. Why the one cybersecurity video every new hire watches once isn't training, and what a managed, measured awareness programme changes instead.

A focused office worker on the phone at her desk, looking at a printed invoice while checking her computer screen, representing the moment a small business confirms a supplier's payment details before processing a payment
TL;DR: A Hong Kong small business almost pays a fraudulent supplier invoice sent by email. It's caught only because a staff member happens to phone the supplier to confirm the new bank details — not because anyone was trained to catch it. The founder realises the cybersecurity video every new hire watches once, on day one, isn't training. It's a formality. What replaces it is a managed, recurring awareness programme that's actually measured.

Hong Kong's small businesses don't have a security team — they have staff

Most of Hong Kong's small businesses run lean by necessity. A 10-to-25-person operation — a design studio, a trading office, a professional-services practice — doesn't have a dedicated IT hire, let alone a security one. IT is usually a part-time responsibility bolted onto someone's real job, or it's fully outsourced and thought about only when something breaks. Cybersecurity, in that structure, is whatever the outsourced provider ships by default, plus whatever the owner half-remembers from a LinkedIn post about ransomware.

That gap doesn't leave the business undefended, exactly — it leaves it defended by people instead of systems. Every email that reaches an inbox has already passed whatever spam filtering and email security the business has in place. What decides whether a fraudulent invoice, a fake password reset, or a convincing impersonation attempt actually causes damage is not a firewall. It's whether the person reading that email recognises something is wrong before they act on it. In a company this size, the staff are the perimeter, whether anyone designed it that way or not.

That's a real problem, because "the staff are the perimeter" is a statement most small-business owners would agree with in the abstract and have done almost nothing about in practice. Somewhere in the onboarding folder is a cybersecurity awareness video — fifteen minutes, generic, probably purchased as part of a compliance bundle years ago — that every new hire clicks through once, in their first week, and never sees again. That single watch is the entire security-awareness programme most small businesses in Hong Kong actually have.

The scenario: one video, watched once, three years ago

Picture a Hong Kong marketing and branding agency, sixteen people — designers, a small digital team, two account managers, and an office manager who also handles the books. It's the kind of business that pays a rotating cast of external vendors regularly: a printing house for large-format work, a production company for shoots, a handful of freelance contractors. Invoices arrive by email constantly, and paying them is a routine part of the office manager's week, not a moment anyone treats as high-risk.

One Tuesday, an invoice arrives from the agency's long-standing printing supplier — correct company name, correct invoice format, referencing a real recent job — with a note that the supplier has switched banks and attaching updated payment details. Nothing about the email looks wrong. The account manager who normally handles that vendor is out for the day, so the office manager, wanting to get the payment out before a deadline, is on the verge of processing it against the new account.

What stops it isn't a security control. It's a habit: before moving a five-figure payment on updated bank details received only by email, she calls the supplier's usual contact to confirm — not because a policy told her to, but because it felt like the responsible thing to do with that much money. The supplier has never heard of any bank change. The email address, on a second look, is one character off from the real one. The invoice was a convincing forgery, built from publicly available information about a real, recent job, timed for a day when the usual approver was away.

Nobody clicked a malicious link. No malware was involved. The entire attack lived inside a well-crafted email and a moment of routine trust, and it was stopped by luck as much as by judgement — the account manager happening to be out, the office manager happening to have the instinct to call first. The founder, hearing the story afterward, asks the obvious question: if she hadn't called, would anyone here have caught it? The honest answer is that nobody could say, because nobody had ever been tested.

What a single onboarding video actually produces

The near-miss forces a harder look at what "we do security training" has actually meant at this business, and the answer is uncomfortable once it's examined directly.

Everyone can recite the rules, and it doesn't stop them clicking. Ask any employee at this agency whether they should click links from unknown senders or verify unusual payment requests, and they'll say the right thing immediately — the video covered exactly that. Reciting a rule under no pressure and recognising a live, well-disguised attempt in the middle of a busy Tuesday are different skills, and only one of them gets tested by a video watched once at onboarding.

There is no data on who is actually high-risk. The founder has no idea which of the sixteen people at this business would spot a fraudulent invoice and which would process it without a second thought. That's not a hypothetical gap — it's the exact information a real attacker is counting on the business not having, because the same attacker will simply keep trying different people and different pretexts until one works.

Training only gets "tested" by a real attack. A one-time video has no mechanism for finding out whether it worked. The only test this business has ever run was the real supplier-fraud attempt itself — which is, by definition, the worst possible time to discover that the training didn't take. A programme that only reveals its failures after a real incident isn't really a programme; it's a hope.

New hires get it once, and everyone else never gets it again. The video lives in the onboarding checklist, which means someone who joined five years ago has had zero refreshers since, while attack techniques — invoice fraud, executive impersonation, AI-assisted phishing — have moved on considerably in that time. A control that only fires once, on day one, ages out of relevance for the entire tenure of every employee after their first week.

Brocent's perspective: awareness only works as a recurring, measured programme

The uncomfortable truth about a fifteen-minute onboarding video is that it was never actually training a person to recognise a live attempt. It was training a person to answer a quiz about attacks in the abstract. Those are not the same skill, and only one of them was tested in the incident above.

Real awareness training has three properties a single video structurally cannot have. It has to be recurring — run on a schedule, not once — because a skill that isn't reinforced decays, and because attack techniques keep changing in ways a static video from three years ago never reflects. It has to be realistic — simulated attempts that look like what actually arrives in this business's inbox, not generic examples from a stock training library, because the whole point is testing whether people catch the real thing, not whether they remember a slide. And it has to be measured — someone has to know, at the level of individual employees and departments, who clicks and who doesn't, because "we think everyone would be fine" is exactly the assumption this agency was one missed phone call away from being wrong about.

None of that is a criticism of any individual employee, including the office manager whose instinct happened to save the business this time. It's a structural point: a business this size has never had the tooling or the spare capacity to build and run that kind of programme itself. Someone has to select realistic phishing templates, schedule and send simulated campaigns, track who clicks and who reports, and turn that into something a founder can actually act on — and at a sixteen-person agency, there is no one whose job that is. Which is exactly why running it isn't something most small businesses should be doing themselves in the first place — it's something they need run for them.

What a managed awareness programme looks like in practice

This is the part a self-serve platform licence and a genuinely managed programme diverge on hardest, and it's worth being specific about what "managed" actually includes.

A managed phishing simulation runs on a fixed cadence — quarterly is a reasonable baseline for most small businesses, stepping up to monthly for higher-risk staff like finance and anyone who approves payments — with realistic, current templates selected by someone whose job is to know what invoice-fraud and impersonation attempts currently look like, not a generic library nobody has updated recently. Short, recurring training modules sit alongside the simulations, so the twenty minutes of onboarding video from three years ago becomes ten minutes a quarter, indefinitely, rather than a single event that never repeats.

The part that actually changes the founder's exposure is the reporting. A managed programme tracks click rates and report rates by individual and by department, so instead of a vague sense that "everyone's probably fine," there's an actual answer to "who would fall for this, and does that risk concentrate anywhere" — finance staff who approve payments, for instance, or anyone whose role makes them a public-facing point of contact. That answer is the thing this agency's founder didn't have and, until the near-miss, didn't know was missing.

Crucially, none of this requires the business to hire anyone or build anything. A named engineer handles template selection, sends the campaigns, and delivers the per-department results — the office manager reviews a report, she doesn't run a platform. That distinction is the entire difference between a self-serve licence, which hands over software and expects a business to operate its own security programme, and a managed Security Awareness Training service, which runs the programme and hands over the results.

Three ways Hong Kong small businesses handle security awareness

A one-time onboarding video

  • What it is: A generic cybersecurity video, watched once by every new hire during their first week, and never revisited.
  • What it actually produces: A box ticked for compliance purposes and zero ongoing measurement. Nobody at the business can say who would recognise a live attempt, because nobody has ever been tested against one — until a real attacker does the testing.
  • Who it suits: Nobody who's actually trying to reduce the odds of a successful phishing or invoice-fraud attempt. It satisfies "we did some training" and nothing else.

A self-serve licence like KnowBe4

  • What it is: A capable platform for building phishing simulations and training campaigns, sold as software — the business selects templates, schedules sends, and reviews results itself.
  • What it actually produces: Real capability, if someone at the business has the time and expertise to run it properly and keeps running it quarter after quarter. In practice, at a sixteen-person agency with no dedicated security role, that upkeep is the first thing that slips when the team gets busy, and an unused licence produces exactly the same protection as no licence at all.
  • Who it suits: A business with someone whose actual job includes running a security-awareness programme — which is uncommon at the small end of the Hong Kong SME market this article is describing.

A managed awareness programme, run for you

  • What it is: A named engineer selects realistic templates, schedules and sends simulated phishing campaigns on a fixed cadence, delivers short recurring training modules, and reports click and report rates by employee and department.
  • What it actually produces: A programme that keeps running whether or not anyone internally has spare capacity that quarter, because running it was never the business's job in the first place — reviewing the results is.
  • Who it suits: Exactly the profile in this article: a lean team with no dedicated security hire, where the honest answer to "who would catch a real attempt" needs to be a known number, not a guess.

Frequently asked questions

How is a managed awareness programme different from a KnowBe4 licence?

A KnowBe4 licence — like most self-serve platforms — sells you the software and leaves the campaign-building, sending, tracking and reporting to your own team. A managed programme includes that platform capability but a named engineer actually runs it: selecting templates, scheduling the simulations, and delivering a results report, so nothing depends on someone internally finding the time each quarter. For a business without a dedicated security role, that's usually the entire difference between a programme that keeps running and a licence that quietly stops being used.

What's a realistic click-rate improvement to expect?

It varies by starting point and industry, but the pattern that shows up consistently across a recurring, measured programme is a steady decline in click rates over the first several campaigns, followed by a flatter, lower baseline once staff have been through a few realistic simulations. The value isn't just the trend line, though — it's finally having a number at all, and knowing which individuals or departments sit above that baseline, which a one-time video never produces.

How often should simulations run?

Quarterly is the effective baseline for most small businesses, and it's enough to keep awareness from decaying between exposures without becoming a distraction. Higher-risk staff — anyone who approves payments, handles finance, or represents the business externally — benefit from stepping up to monthly, since they're disproportionately likely to be the specific target of an invoice-fraud or impersonation attempt like the one in this scenario.

Is this suitable for a 10-person business?

Yes — a managed programme is priced per user with a minimum seat count, specifically because the smallest businesses are the ones least likely to have anyone able to build and run a programme themselves, not the ones who need it least. A ten-person team paying real invoices to real suppliers has exactly the same exposure as a much larger one; it just has far less spare capacity to defend itself.

What happens if an employee keeps failing simulations?

That's the information the programme exists to surface. Rather than a punitive response, a well-run programme flags repeat clickers for more targeted follow-up training, and gives the business the option to add extra controls — a second-approval step on payment changes, for instance — around the specific people or roles that show up as consistently higher-risk, based on actual data rather than a guess about who's careful.

Does this satisfy a cyber-insurance requirement?

Increasingly, yes, in part — a growing number of cyber-insurance renewals ask whether a business runs any form of ongoing security awareness training, not just whether staff have "had training" at some point historically. A documented, recurring, measured programme with click-rate reporting is generally the kind of evidence an insurer or a renewal questionnaire is looking for; a one-time onboarding video from years ago typically is not. It's also worth being direct about what this doesn't do: awareness training reduces the odds that a fraud attempt succeeds, but it isn't a substitute for whatever payment-approval controls a renewal questionnaire separately asks about — the two usually sit on the same checklist as related but distinct lines, and an insurer evaluating this business's risk will want to see both addressed rather than one standing in for the other.

Do the simulated phishing emails ever get too realistic and cause real problems?

A well-run programme calibrates realism deliberately rather than chasing it for its own sake — the templates are built to resemble genuine current attack patterns closely enough to be a fair test, without spoofing anything that would cause operational confusion, like a fake internal system outage or an impersonation of a specific real employee's exact writing style without disclosure. The goal is an honest measurement of whether someone would catch a real attempt, not a stunt that erodes trust in the exercise itself; results are used to target training, not to single anyone out.

How much does it cost per user?

Brocent's managed Security Awareness Training starts from US$2.50 per user per month, with a minimum of 10 seats, for a quarterly cadence — stepping up to a monthly cadence for higher-risk teams. For comparison, self-serve platforms in the same category list at roughly US$1.63–3.75 per seat per month for KnowBe4 (typically on a 3-year minimum term) and comparable ranges for Proofpoint Essentials and similar tools — broadly similar sticker prices, but those figures buy a platform license, not a managed, run-for-you programme. The fuller pricing detail, including how the quarterly and monthly tiers compare, is on the Security Awareness Training pricing page.

Where awareness training fits: one part of an ongoing plan, not a standalone licence

It would be easy to read this article as an argument for buying security awareness training as its own, standalone purchase — swap a KnowBe4 licence for a Brocent one, and move on. That's not quite the right conclusion. The reason a managed awareness programme works for a business like the sixteen-person agency in this scenario is the same reason a managed IT plan works generally: someone else carries the operational load of keeping a control running continuously, instead of it depending on spare capacity nobody at a lean team actually has.

That's why awareness training sits inside Brocent's managed IT support plans as one of the security capabilities included or available as an add-on, alongside the endpoint protection, patching and managed IT security services that already need to run continuously for a business this size — not as a separate product a founder has to evaluate and manage on its own timeline. The value isn't the training platform in isolation; it's having one plan and one point of contact responsible for the whole security picture, of which awareness is one recurring piece, rather than a stack of individually-licensed tools each waiting for someone internal to find time to run them.

If the near-miss in this article sounds familiar — a convincing email is usually the way this kind of fraud attempt actually arrives, and the filtering and email-security side of that same problem is covered in a related case from a Hong Kong wholesaler's own supplier invoice fraud near-miss — the honest starting point isn't a decision to buy a training licence today. It's a conversation about what a managed IT plan actually covers for a business your size, and what that looks like on current pricing. Get in touch, and we'll walk through what's actually protecting your team right now, and what isn't.

Share:

Ready to take action?

Turn these insights into a roadmap for your business.

Book a 15-minute no-obligation consultation with our APAC IT experts. We'll review your current setup and provide a tailored IT roadmap within 24 hours.

📋

Free Checklist

10 Critical Checks Before Expanding IT to Greater China

PIPL compliance, network segmentation, bilingual helpdesk setup, and more — everything your IT team needs before Day 1 in China.

Request the checklist →

📬 Monthly Asia IT Insights

China compliance updates, cybersecurity alerts, and IT tips for APAC teams — once a month.

No spam. Unsubscribe anytime.