I. Introduction
Phishing emails are both a scam and a business. If an attacker manages to have his/her phishing email hook a key person in an organization, s/he can gain access to a myriad of sensitive services and data. Such an event is not unlikely since there is evidence showing that employees in Human Resources or Accounting and Finance are no better than other colleagues in recognising phishing emails [1]. Further, the likelihood of clicking on a poisoned link is higher when an individual spends more time on the Internet, independently of his/her technical literacy [2], [3].