Training
What is cyber awareness training?
Cyber security awareness training is structured education that teaches staff to recognise and respond correctly to security threats they encounter at work — primarily phishing, social engineering, credential theft and unsafe data handling. It is typically delivered as short recurring online modules, and its effectiveness is measured through simulated phishing exercises and reporting rates rather than completion figures alone.
At a glance
- Primary risk addressed
- Human-operated attacks: phishing, BEC, social engineering
- Typical format
- 5–15 minute online modules, monthly or quarterly
- Measurement
- Simulated phishing click rate and report rate
- Relevant to
- Cyber Essentials, ISO 27001, GDPR accountability
What the training covers
Content varies by provider, but a credible programme addresses the attack types staff actually encounter rather than abstract security theory.
- Recognising phishing emails, including targeted spear-phishing and invoice fraud.
- Business email compromise — verifying payment and bank detail change requests out of band.
- Password practice and password managers, and why credential reuse matters.
- Multi-factor authentication, including MFA fatigue and prompt-bombing attacks.
- Safe handling of personal and client data, and secure file sharing.
- Device security, public Wi-Fi and remote working.
- How and when to report a suspected incident internally.
How effectiveness is measured
Completion rate measures compliance, not behaviour. The meaningful metrics come from simulated phishing: the proportion of staff who click a simulated malicious link, the proportion who submit credentials to a simulated fake login page, and — most useful of all — the proportion who report the message.
A rising report rate is the strongest signal that training is working, because it shows staff are actively identifying suspicious messages rather than simply avoiding them. Organisations that run regular simulations typically see click rates fall substantially over the first six to twelve months and then plateau.
Frequency and format
Annual training has limited durable effect: awareness decays within weeks. Short, frequent modules — commonly five to fifteen minutes, monthly or quarterly — sustain recognition better than a single long session, and fit around working patterns without meaningful productivity loss.
Effective programmes also treat simulation failures as teaching moments rather than disciplinary events. Punitive approaches suppress reporting, which is the behaviour most worth encouraging.
Sources
The definitions and figures on this page are drawn from the primary sources below. Where guidance changes, the source takes precedence over our summary of it.
- Top Tips for Staff: cyber security training — National Cyber Security Centre
- Cyber Security Breaches Survey — UK Department for Science, Innovation and Technology
- Small Business Guide: Cyber Security — National Cyber Security Centre
FAQ
What is cyber awareness training — common questions
Direct answers to the questions asked most often about this topic.
Does cyber awareness training actually reduce risk?
+
Evidence from phishing simulation programmes consistently shows that regular training reduces click rates on simulated attacks and, more importantly, increases the rate at which staff report suspicious messages. That matters because the majority of breaches affecting small organisations begin with a person — a clicked link, a credential entered on a fake login page, or a fraudulent payment request actioned without verification. Training does not eliminate the risk, and it should never be the only control; multi-factor authentication, email filtering and endpoint protection remain necessary. What it does is shorten detection time and reduce the number of incidents that reach a technical control at all.
How often should staff be trained?
+
Short modules delivered monthly or quarterly work better than a single annual session, because recognition of attack patterns decays within weeks without reinforcement. A common pattern is a short baseline module during onboarding, followed by five to ten minute refreshers on a rotating set of topics, with simulated phishing running continuously in the background at varying difficulty. Annual training is often enough to satisfy a compliance checkbox but rarely changes behaviour measurably. Staff in higher-risk roles — finance, payroll, executive assistants, anyone who can move money or change bank details — benefit from additional targeted content.
What does awareness training cost for a small business?
+
Awareness training is normally priced per user per month, and for SMEs typically falls between a few pounds and around ten pounds per user monthly, depending on whether phishing simulation, policy management and reporting are bundled. A twenty-person business is therefore usually looking at a low hundreds of pounds per year rather than a major capital cost. Free material is available from the NCSC and is worth using, though it lacks per-user tracking and simulation reporting, which is what most organisations need to evidence the control for insurers, auditors or certification.
Is awareness training required for Cyber Essentials?
+
Cyber Essentials assesses five technical controls and does not include a dedicated staff training requirement, so training is not strictly mandatory for certification. However, several of the technical requirements — password practice, account handling, recognising when software is unsupported — depend on staff behaviour to hold in practice. Other frameworks are more explicit: ISO 27001 requires awareness, education and training as a formal control, and UK GDPR accountability obligations effectively require organisations to demonstrate staff understand how to handle personal data. Insurers frequently ask about training during underwriting as well.
Should phishing simulation results be shared with managers?
+
Aggregate results are useful for managers and boards: overall click rates, report rates and trends by department show whether the programme is working and where additional support is needed. Individual results are more sensitive. Programmes that name and penalise individuals tend to reduce reporting, because staff become reluctant to admit mistakes — and rapid reporting is precisely the behaviour that limits damage during a real incident. The more effective approach is to route repeat clickers into short additional training automatically, keep individual data confidential, and publicly recognise reporting rather than punishing clicking.

