Security awareness training that works

A practical programme to cut phishing risk

Security awareness training that works

The evidence base for security awareness training is weaker than the market for it suggests. A large-scale study published in 2025, run across a real workforce rather than a test group, found no significant effect from training interventions on either click rates or reporting rates. The variable that predicted behaviour was the quality of the lure, with click rates of around 7% for obvious fakes and 15% for convincing ones, largely independent of what training the recipient had completed.

The conclusion to draw is about format rather than principle. Annual e-learning satisfies a compliance requirement without addressing the conditions under which incidents occur, which is a person working under time pressure on a request that – to them – resembles something routine.

The Cyber Security Breaches Survey 2025/2026, published on 30 April 2026, found that 43% of UK businesses identified a breach or attack in the previous twelve months, with phishing the most prevalent type at 38% of businesses and named the most disruptive incident by 69% of those affected. The same survey has consistently found that only around one in five businesses ran any staff training or awareness activity, and that roughly four in ten have no agreed process for staff to follow when they encounter a fraudulent email.

This piece covers what a programme needs to do differently, how simulation fits into it, and how to measure whether it is working.

Why the annual module underperforms

Retention from a single long course completed once a year is poor, and this is not a controversial finding. Behaviour change depends on repetition and on proximity to the decision being made. Someone approving a change to payment details needs the prompt at the point of approval rather than in the abstract several months earlier. The annual module is structured around the audit calendar rather than the working day, which explains why it satisfies the former and has limited effect on the latter.

There is a second structural problem. The NCSC has argued for some years that expecting users to reliably identify malicious links is an unrealistic requirement, because competently constructed phishing is designed to be indistinguishable from legitimate mail. A programme resting entirely on individual judgement is dependent on the weakest control available.

That changes the objective. The aim is not to eliminate clicks, which is not achievable, but to shorten the time between something going wrong and somebody reporting it, and to make reporting straightforward and free of consequence.

What to cover

The baseline for all staff covers what business email compromise looks like in practice, the process for handling something suspicious, and the reasoning behind MFA. MFA fatigue attacks depend on a user approving a prompt they did not initiate, so staff need to understand that an unexpected prompt indicates their password is already compromised rather than that the system is malfunctioning.

Above the baseline, content should follow role:

  • Finance and accounts payable require substantive coverage of invoice fraud and payment redirection.
  • Staff handling customer records require more on data protection obligations.
  • Operational teams with limited system access require neither in depth.
  • Role-based content costs marginally more to produce than generic content and is more credible to the people receiving it.

The best place to start is using internal examples. Reference your own reporting process and attacks your business or sector has actually seen rather than generic scenarios.

Training that never refers to how the organisation operates is easily dismissed as irrelevant.

And remember, onboarding is a critical time in the process. New starters should complete this before system access is granted rather than several weeks into the role.

Running simulations without losing staff cooperation

Simulation measures behaviour under realistic conditions, which is why it is more informative than an assessment. Knowledge of phishing indicators and behaviour when presented with a convincing email are only loosely correlated.

Design decisions matter more than platform selection. A click should be treated as a coaching trigger and never as a disciplinary one. A short, plainly written follow-up delivered immediately, showing the recipient what the indicators were, is more effective than any punitive process. Punitive handling produces concealment of mistakes, which extends the window in which an incident can develop.

It’s important to vary difficulty deliberately rather than repeating the same template.

Ways you can do this include: rotating credential harvesting, fraudulent invoices, delivery notifications and simulated MFA prompt bombing. Since difficult lures produce roughly double the click rate of easy ones, a programme built on easy tests generates a favourable number rather than a useful one.

A very low click rate should be read as a comment on test difficulty rather than on staff capability. A simulation that nobody fails provides no learning, and the recognition that follows a click is the element that produces behaviour change. It is preferable for that to happen during a controlled test.

Measuring it properly

Completion rate records that people opened and closed a module. It is not predictive of behaviour during a live attack.

Metric What it actually tells you
Click rate Meaningful only alongside lure difficulty. In isolation it rewards easy tests.
Report rate Whether staff are using the process rather than deleting and continuing
Time to report How quickly a real attack would reach IT, which determines containment
Repeat clicks Whether particular individuals or teams need targeted support

Report rate is the primary metric here. A declining click rate combined with a flat report rate generally indicates that staff have learned to ignore unfamiliar email, which discards legitimate correspondence and provides no protection against an attack designed to resemble normal business. Both metrics moving together indicates a programme that is functioning.

Time to report receives a lot less attention than it warrants. In a live incident, the interval between the first click and the first report defines the attacker’s working window, and reducing that interval from hours to minutes has a larger effect on outcomes than a marginal improvement in click rate.

The highest-value single change

For most SMEs, the first change to make is adding a one-click report button to the email client.

Reporting friction is the most common reason an otherwise adequate programme produces no data. Where reporting requires several steps and an email to a shared mailbox while deleting requires one action, most users will delete. Removing that asymmetry usually produces a substantial increase in reporting volume.

Reports then need responses.

A member of staff who reports something and receives no acknowledgement has been taught that the process achieves nothing, and reporting rates fall accordingly.

Beyond email

Telephone and messaging channels are used routinely and are absent from most training programmes. A caller presenting as IT support, or a message claiming to come from a senior manager requesting an urgent payment, exploits the same pressure as phishing through a channel no email filter covers.

The control is a verified callback procedure that is documented, known and never penalised in use. Any request to change bank details or authorise an urgent payment is confirmed on a number already held on file rather than a number supplied within the request.

This depends on visible leadership support. Staff are reluctant to challenge requests that appear to originate from senior figures, and a written policy does not resolve that on its own. Directors need to state explicitly that they expect to be verified and will not treat it as an inconvenience.

Passwords

Instructions to use strong passwords change little, and a large proportion of password training consists of exactly that.

What is effective is explaining why length and uniqueness matter more than complexity, then removing the manual burden entirely through a properly deployed password manager with a supported setup session. Adoption without that session is minimal, which makes a brief reference in a slide deck an ineffective use of the time.

Address the specific behaviours rather than assuming they are understood to be problems. Reuse of credentials between work and personal accounts, shared logins between colleagues, and passwords stored in spreadsheets are the patterns most commonly found in SME environments.

Making the programme sustainable

Run a baseline simulation before making any changes, so subsequent improvement can be measured rather than asserted.
Assign a named owner

The function it sits in matters less than the accountability, since a programme distributed across IT, HR and compliance without a single owner tends to lapse within a few cycles.

Keep training, simulation and follow-up coaching as one process
Training without simulation remains theoretical, and simulation without coaching produces a scorecard and resentment.

Review monthly rather than annually

A monthly review of reporting trends allows content to be adjusted while the data is still current, rather than identifying a problem in an annual review months after it emerged.

Some SMEs run this internally and run it well. For others, the combination of platform administration, content maintenance and monthly reporting exceeds what an IT team can sustain alongside support demand. Where external support adds value, it is usually in maintaining the reporting cycle and the consistency rather than in the technology, since the technology is the least demanding component.

Reporting to the board

Leadership, compliance functions and insurers increasingly expect more than confirmation that training took place.
A quarterly summary presenting report rate and time to report as trend lines, alongside the changes made in response, provides something that can be assessed. It also supports the answer to the human risk questions that now appear routinely in customer security questionnaires.

Where Utilize comes in

If it all feels overwhelming or you’re not sure where to start, you could look at a fully managed security solution or take the first step with our comprehensive, fixed-fee IT Security Audit.

Book a Free Consultation
Written by
charlie.hickling
charlie.hickling Read more about