Service
Security awareness training
The widest attack surface in any business is the people, and it is also the cheapest one to improve. What works is short, frequent and slightly uncomfortable. What does not work is a forty minute video once a year that everyone skips to the quiz.
The metric that matters
Report rate
not click rate
A message reported in four minutes can be pulled from every other inbox before it is opened.
How the programme runs
Continuous rather than annual, and deliberately low friction. Ten minutes a month sustained for a year beats a half day workshop comprehensively.
| Component | Cadence |
|---|---|
| Baseline simulationAn unannounced phishing test before any training, to establish a real starting point | Month 1 |
| Short modulesFive to ten minutes, one topic, delivered in the flow of work | Monthly |
| Ongoing simulationVaried difficulty and pretext, not the same template repeated | Monthly |
| Reporting reinforcementA one click report button, and thanks rather than silence when it is used | Continuous |
| Targeted follow upExtra support for repeat clickers, delivered privately | As needed |
| Management reportingClick rate, report rate and time to first report, trended | Quarterly |
Measure the right thing
Most programmes report click rate and stop, which is measuring failure and ignoring success.
- Report rate, meaning the percentage of people who flag a suspicious message. This is the metric that matters most and the one most programmes ignore
- Time to first report, because a message reported in four minutes can be pulled from every other inbox before it is opened
- Click rate, useful as a trend rather than as an absolute number
- Repeat clicker count, which identifies who needs support rather than who needs punishment
A business where 4 percent click but 60 percent report is in considerably better shape than one where 2 percent click and nobody says anything, because in the second case a real message sits undetected in fifty inboxes.
The one topic worth extra time
Business email compromise causes more direct financial loss at this scale than ransomware does, and it usually involves no malware at all. A convincing message from a supplier, a director or a conveyancer, asking for a payment or a change of bank details.
No technical control reliably stops a well written request from a legitimate but compromised mailbox. What stops it is a process: any change to payment details is verified by voice on a number already on file, never on a number in the message, without exception and regardless of who appears to be asking.
That single rule, trained and enforced, prevents more loss than most of the security stack combined.
Common questions
Answered before you ask.
Does security training actually change anything?
Short and frequent training does. An annual video does not, and the research on this is not particularly ambiguous. The mechanism that matters is not knowledge, it is habit: people learn to pause on an unexpected request involving money or credentials, and they learn that reporting something is welcomed rather than embarrassing. That behaviour is built by repetition over months, which is why a once yearly compliance exercise has so little effect.
Will staff resent being tested?
They resent being humiliated, which is a different thing and entirely avoidable. Results are reported to management in aggregate, follow up with someone who clicked happens privately and supportively, and nobody is named on a leaderboard. Where programmes generate resentment it is almost always because someone treated a click as a disciplinary matter rather than as evidence that the simulation worked as intended.
What about people who keep clicking?
A small number of people click repeatedly, and the productive response is support rather than sanction. Additional short training, a conversation about what makes a request suspicious, and in some roles a technical control such as tighter attachment handling. It is worth remembering that a purchasing or accounts role receives genuinely urgent payment requests all day, so the job itself makes the judgement harder.
Is this required for compliance or insurance?
Increasingly both. Cyber insurance questionnaires commonly ask whether security awareness training is delivered and whether completion is recorded, and several compliance frameworks including HIPAA require workforce training with documented completion. Recorded completion is the operative phrase, so a programme that cannot produce a record per person per period will not satisfy either.
Related
What sits alongside this.
Cybersecurity services
Endpoint detection, email security, monitoring and user training.
Managed detection and response
24 by 7 human review of security alerts, with authority to contain.
Microsoft 365 management
Tenant hardening, device management, licensing and the backup gap.
Healthcare
HIPAA, EHR uptime, device segmentation
IT compliance and risk
HIPAA, CMMC, PCI DSS and cyber insurance requirements.
Start with an unannounced baseline.
A simulation run before any training gives you an honest starting number. It is usually higher than management expects and lower than staff fear.