Skip to content

Service

Security awareness training

The widest attack surface in any business is the people, and it is also the cheapest one to improve. What works is short, frequent and slightly uncomfortable. What does not work is a forty minute video once a year that everyone skips to the quiz.

The metric that matters

Report rate

not click rate

A message reported in four minutes can be pulled from every other inbox before it is opened.

How the programme runs

Continuous rather than annual, and deliberately low friction. Ten minutes a month sustained for a year beats a half day workshop comprehensively.

Security awareness programme components and cadence
ComponentCadence
Baseline simulationAn unannounced phishing test before any training, to establish a real starting pointMonth 1
Short modulesFive to ten minutes, one topic, delivered in the flow of workMonthly
Ongoing simulationVaried difficulty and pretext, not the same template repeatedMonthly
Reporting reinforcementA one click report button, and thanks rather than silence when it is usedContinuous
Targeted follow upExtra support for repeat clickers, delivered privatelyAs needed
Management reportingClick rate, report rate and time to first report, trendedQuarterly

Measure the right thing

Most programmes report click rate and stop, which is measuring failure and ignoring success.

  • Report rate, meaning the percentage of people who flag a suspicious message. This is the metric that matters most and the one most programmes ignore
  • Time to first report, because a message reported in four minutes can be pulled from every other inbox before it is opened
  • Click rate, useful as a trend rather than as an absolute number
  • Repeat clicker count, which identifies who needs support rather than who needs punishment

A business where 4 percent click but 60 percent report is in considerably better shape than one where 2 percent click and nobody says anything, because in the second case a real message sits undetected in fifty inboxes.

The one topic worth extra time

Business email compromise causes more direct financial loss at this scale than ransomware does, and it usually involves no malware at all. A convincing message from a supplier, a director or a conveyancer, asking for a payment or a change of bank details.

No technical control reliably stops a well written request from a legitimate but compromised mailbox. What stops it is a process: any change to payment details is verified by voice on a number already on file, never on a number in the message, without exception and regardless of who appears to be asking.

That single rule, trained and enforced, prevents more loss than most of the security stack combined.

Common questions

Answered before you ask.

Does security training actually change anything?

Short and frequent training does. An annual video does not, and the research on this is not particularly ambiguous. The mechanism that matters is not knowledge, it is habit: people learn to pause on an unexpected request involving money or credentials, and they learn that reporting something is welcomed rather than embarrassing. That behaviour is built by repetition over months, which is why a once yearly compliance exercise has so little effect.

Will staff resent being tested?

They resent being humiliated, which is a different thing and entirely avoidable. Results are reported to management in aggregate, follow up with someone who clicked happens privately and supportively, and nobody is named on a leaderboard. Where programmes generate resentment it is almost always because someone treated a click as a disciplinary matter rather than as evidence that the simulation worked as intended.

What about people who keep clicking?

A small number of people click repeatedly, and the productive response is support rather than sanction. Additional short training, a conversation about what makes a request suspicious, and in some roles a technical control such as tighter attachment handling. It is worth remembering that a purchasing or accounts role receives genuinely urgent payment requests all day, so the job itself makes the judgement harder.

Is this required for compliance or insurance?

Increasingly both. Cyber insurance questionnaires commonly ask whether security awareness training is delivered and whether completion is recorded, and several compliance frameworks including HIPAA require workforce training with documented completion. Recorded completion is the operative phrase, so a programme that cannot produce a record per person per period will not satisfy either.

Start with an unannounced baseline.

A simulation run before any training gives you an honest starting number. It is usually higher than management expects and lower than staff fear.

CallFree assessment