Anti-phishing software is the set of tools that catch phishing before it reaches your inbox and, increasingly, the tools that catch people after it does. This guide explains how the two halves work, where the gaps are and what a small Australian business actually needs in 2026.
TL;DR
- Anti-phishing software has two halves: technical filtering that stops known threats, and human-layer training that stops the ones designed to slip past the filter.
- Verizon's 2025 Data Breach Investigations Report analysed 22,052 incidents and 12,195 confirmed breaches and again found a human element in roughly 60% of them (full report PDF) — that human element is the half filters cannot reach.
- The technical half works through email authentication, link rewriting, attachment detonation and impersonation detection; the human half works through awareness training, phishing simulations and one-click reporting.
- ASD received more than 84,700 cybercrime reports in FY2024-25, one every six minutes, with an average self-reported cost of $56,600 for small businesses (ASD Annual Cyber Threat Report 2024-25).
- You need both halves. A filter with no training lets the crafted lure through; training with no filter buries staff in noise.
What anti-phishing software actually does
The name covers two categories that get sold together and behave differently:
- Email security tools sit between the internet and your mailbox. They inspect every message, block or quarantine the dangerous ones and rewrite links so a click can be checked in real time.
- Human-layer tools — awareness training platforms, phishing simulation engines and report buttons — measure and strengthen the decision your staff make when something suspicious reaches the inbox anyway.
Both are anti-phishing software. Buying only the first half solves the threat that was popular in 2015; buying only the second leaves staff exposed to industrial-scale commodity spam.
How the technical half works
Modern email security layers several checks on every message:
- Sender authentication. SPF, DKIM and DMARC verify the mail really came from the domain it claims. This kills a large share of naive spoofing.
- Reputation and pattern scoring. Sending IP reputation, message similarity to known campaigns and header analysis assign a risk score before delivery.
- Link rewriting and detonation. URLs are wrapped so that the click goes through a security gateway, which checks the destination at click time — not just when the mail arrived.
- Attachment detonation. Files are opened in a sandbox; anything that drops a payload or phones home is quarantined.
- Impersonation detection. Look-alike domains, display-name spoofing of your executives and replies to threads the attacker never joined are flagged.
These controls are effective against bulk campaigns. They are weakest exactly where attackers invest most: personalised, low-volume lures aimed at finance staff and executives, sent from legitimately registered domains.
How the human half works
When a crafted lure passes the filter, the last control is a person. Human-layer software strengthens that control with three mechanisms:
- Awareness training. Short monthly lessons that teach what real lures look like — invoice fraud, payment redirection, credential harvesting — instead of a once-a-year compliance video.
- Phishing simulations. Safe fake attacks that measure clicks and reports per person and trigger instant coaching, so the reflex is practised, not described.
- One-click reporting. A report button in Outlook or Gmail that logs the message and, ideally, pulls it from every other mailbox before a second person clicks.
Cyber Aware's awareness training and phishing simulations cover this half, with clickers auto-enrolled into a follow-up lesson the same day and results rolled into a per-learner score.
Where each half fails
| Failure | Which half it belongs to | What covers the gap |
|---|---|---|
| Bulk credential-harvest campaign | Technical | Filtering, reputation scoring |
| Personalised invoice fraud from a real domain | Technical (weakly) | Human: finance training + verification habits |
| Staff click a link in a personal chat app | Both | Human: channel awareness training |
| A report that nobody acts on | Process | Human: reporting workflow and response |
| Malicious attachment inside a PDF | Technical | Detonation, sandboxing |
The pattern is clear: the technical half handles volume, the human half handles intent. Attackers choose the gap with the least resistance, which is why the human element still appears in roughly 60% of breaches.
What it costs
Email security typically prices per mailbox per month and often ships inside Microsoft 365 Defender or Google Workspace already — check what you own before buying. Human-layer platforms price per user per year; for a 50-person business the realistic band is a few hundred to a couple of thousand dollars annually, and a comparison of platforms shows where vendors differ on automation and reporting rather than on headline features.
The money case holds at any size: IBM's 2025 Cost of a Data Breach Report put the global average breach at USD 4.44 million (IBM's report summary), and even the ASD's small-business average of $56,600 dwarfs a year of both halves combined.
How to choose for an Australian small business
Ask four questions before you buy:
- What do we already own? Defender and Workspace filtering may already cover the technical half — verify, then spend the budget where the gap is.
- Is the human half automated? Directory-sync enrolment, scheduled simulation campaigns and auto-remediation. A programme run by hand stops running.
- Is the content local? Fake tax office, bank and delivery notices beat generic templates for Australian staff.
- Can we show evidence? Exportable per-learner reports for insurers, auditors and enterprise clients.
If you are unsure whether your exposure is mostly technical or mostly human, a security gap assessment tells you which control deserves the next dollar.
FAQ
What is anti-phishing software? Tools that block phishing before delivery (email security: authentication, link rewriting, detonation) plus tools that strengthen the human decision after delivery (training, simulations, report buttons).
Do I need both? Yes. The technical half stops bulk campaigns; the human half stops the crafted lures built to defeat the filter. Each covers the other's blind spot.
Does Microsoft 365 include anti-phishing? It includes solid baseline filtering through Defender for Office 365, but no meaningful training or simulation layer — the human half still needs a platform.
How much does it cost? Technical filtering is often bundled with your email platform; human-layer training commonly runs a few dollars per user per month. Verify what you already pay for before adding spend.
Will it stop business email compromise? Not entirely. BEC frequently uses legitimate infrastructure and real threads, which filters cannot safely block. Verification habits and payment controls trained into finance staff are the control that catches it.
One last thing
Before you buy any anti-phishing product, run one baseline phishing simulation. The number you get back tells you whether your spend belongs in the filter or in the people — and most teams are surprised which it is.