Executive assistants control an executive's inbox, calendar, travel and often payment instructions — which makes them the single most targeted role in an average office for fraud attempts. This guide covers what executive assistant security awareness training should include in 2026, how often to run it, and how to prove it worked.
Why attackers target executive assistants
A business email compromise attempt works best when it reaches someone who can move money or share information without asking questions. That is the executive assistant's job description. Fraudsters who impersonate a CEO, CFO or senior partner do not need to fool the executive — they need to fool the person who acts on the executive's behalf.
The financial stakes are documented. The FBI's Internet Crime Complaint Center received 21,442 business email compromise complaints in 2024 with $2.77 billion in reported losses, making it the second-costliest cybercrime category the FBI tracks. In Australia, the average self-reported cost of a cybercrime incident for a small business reached $56,600 in FY2024-25, up 14% year on year. A single convincing wire-transfer email can erase that amount in an afternoon.
Assistants are also structurally exposed:
- They approve and route payments — invoices, vendor changes, travel bookings and reimbursements flow through them.
- They know the executive's schedule — attackers use calendar details to time urgent-sounding requests when the boss is unreachable, on a flight or in a board meeting.
- They handle sensitive information — contracts, HR matters, personal contact details and travel documents.
- They are expected to act fast — an assistant culture built on anticipation and responsiveness is exactly what a fraudulent urgent request exploits.
The attacks executive assistants actually face
Generic phishing modules cover the basics, but assistants need training against the specific plays used against them:
- Executive impersonation (CEO fraud). An email or message that appears to come from the executive asks for an urgent payment, a gift-card purchase or a change of banking details. Timing is chosen to make verification hard.
- Vendor email compromise. A genuine supplier's mailbox is taken over and a real-looking invoice arrives with new bank details. Everything about the email is authentic except the account number.
- Travel and booking scams. Fake itinerary changes, hotel confirmations and e-ticket attachments timed around known trips, sometimes delivered by SMS while the executive is in the air.
- Calendar and file-share lures. Malicious links disguised as meeting invitations, shared documents or e-signature requests — the tools assistants live in all day.
- Recruitment and HR-themed lures. Fake CVs and job applications carrying malicious attachments, aimed at whoever manages the executive's hiring pipeline.
What security training for executive assistants should cover
A role-specific curriculum for assistants in 2026 should include:
- Verification out-of-band — how to confirm a payment or banking change by phone using a number already on file, never one supplied in the request.
- Executive impersonation red flags — unusual urgency, secrecy ('don't mention this to anyone'), pressure to bypass normal process, and subtle display-name or domain spoofing.
- Vendor and invoice fraud — treating any change to payment details as a fraud attempt until verified.
- Safe handling of calendars, travel docs and attachments — recognising lookalike file-share and e-signature links.
- SMS and messaging attacks — the travel-day smishing plays that arrive when email is not the channel being watched.
- How and where to report — a fast, blame-free reporting path, so a suspicious email costs two minutes instead of two weeks of incident response.
How to train an assistant without pulling them off the calendar
Executive assistants are the least likely people in a company to have a free afternoon for a two-hour course. Training that works for this role is short, frequent and anchored to real scenarios:
- Short story-driven lessons on a steady cadence — security awareness training built around real incidents teaches the pattern of an attack, not just a checklist, and fits into the gaps of a working day.
- Role-relevant phishing simulations — send the executive-impersonation and invoice-fraud templates this cohort actually receives. Phishing simulations that auto-enrol anyone who clicks into a short follow-up lesson turn each mistake into private coaching rather than public shaming.
- Individual risk visibility — a human risk score built from training completions, failed quizzes and simulation outcomes shows whether this high-risk role is actually improving month over month.
Two or three minutes a week, every week, beats an annual seminar the assistant attends between phone calls. The point is not course hours logged — it is that the assistant who sees an 'urgent — approve attached invoice before the board meeting' email at 4:55pm on a Friday pauses, verifies by phone and reports it.
Proving the training worked
Executives and insurers increasingly ask for evidence, not attendance sheets. Keep a timestamped record of completions, quiz results and simulation outcomes for the roles with payment authority. A quarterly review should be able to answer three questions in one page: did the executive assistants complete their training, how did they perform against payment-fraud simulations, and is the trend improving. If the wider organisation needs a baseline, a security gap assessment shows where role-specific training fits among the other controls.
FAQ
Do executive assistants need different security training from other staff?
Yes. They face payment-fraud and impersonation attacks most employees never see, and they hold the authority attackers want. A generic annual course leaves exactly the gaps that matter for this role.
How often should executive assistants be trained?
Short lessons on a monthly or bi-weekly cadence, with phishing simulations running at least monthly. The role carries too much payment authority for an annual-only refresh.
Isn't a verification phone call enough on its own?
Verification is the control that stops the loss, but it only happens reliably when training has made pause-and-verify a habit — and when the assistant knows reporting a near-miss is welcomed rather than punished.
What should we do after an assistant clicks a simulated phishing email?
Enrol them in a short follow-up lesson immediately, review what made the email convincing, and adjust future simulations. The click is data, not a disciplinary event.
Who else should receive executive-impersonation training?
Everyone with payment authority: finance staff, office managers and the executives themselves. Attackers pick whichever person is easiest to reach, not the job title.
One last thing
The most convincing fraudulent email your executive assistant will ever receive will look exactly like your executive on a bad day: short, urgent, slightly out of character, and asking for something only they would normally handle. Train for that email by name.
Sources
- FBI Releases Annual Internet Crime Report — 2024 BEC losses of $2.77 billion across 21,442 complaints
- ASD Annual Cyber Threat Report 2024-25 — small business average cybercrime cost of $56,600
- Proofpoint: Email Attacks Drive Record Cybercrime Losses in 2024 — analysis of the FBI IC3 2024 findings