Services

Cyber Security Awareness Training for Staff

Your staff are the control that catches what the technology misses. We train them with realistic examples from UK businesses, measure it honestly, and build a culture where people report rather than hide mistakes.

FORMAT
Live Sessions, Remote or On-Site
SIMULATION
Realistic UK-Context Phishing
CADENCE
Quarterly Recommended
MEASURES
Click Rate and, More Importantly, Report Rate
In short

Does security awareness training actually reduce risk?

Yes, when it is short, frequent and specific to real threats — and when reporting a suspicious email is easy and blame-free. Annual slide decks change little. Regular simulated phishing combined with brief, practical coaching measurably reduces click rates and, more importantly, increases reporting.

Why most awareness training fails

The standard model — a compliance video once a year, a quiz, a certificate — produces a record of completion and almost no change in behaviour. It is too infrequent to build habit, too generic to be recognisable, and often framed in a way that makes people feel stupid, which is the fastest route to nobody reporting their mistakes.

What works is the opposite: short and frequent rather than long and annual, built around examples that look like the emails your staff actually receive, and framed so that reporting a mistake is treated as a good outcome. The organisations that survive phishing well are not the ones where nobody clicks — they are the ones where the person who clicked said so within five minutes.

What we cover

The core session is 45 minutes and covers the attacks that genuinely reach UK SMEs: phishing and how to spot the modern versions that have no spelling mistakes, invoice and payment redirection fraud, MFA fatigue and prompt-bombing, password reuse and why the company password manager matters, and safe handling of personal data under UK GDPR.

Finance teams and managers get an additional short briefing, because they are targeted specifically and differently — business email compromise concentrates on whoever can move money or change bank details.

  • Recognising modern phishing, including AI-written and well-formatted attempts
  • Invoice fraud and bank detail change requests — verify out of band, always
  • MFA prompt fatigue and what to do when an unexpected prompt appears
  • Password managers, reuse and credential stuffing
  • Handling personal data and recognising a reportable data breach
  • How and when to report — the single most valuable behaviour to build

Phishing simulation done fairly

Simulated phishing is useful for measurement and for creating teachable moments in the exact instant someone is most receptive. It is not useful as a trap. We do not run simulations designed to humiliate — the fake bonus or fake redundancy notice produces a high click rate and a workforce that resents the security team.

Campaigns are realistic, results are reported at group level rather than as a list of names to be disciplined, and anyone who clicks gets a brief, non-judgemental explanation of what they missed. The metric we care most about is not click rate but report rate, and it is the one that improves fastest.

What you receive

Included in every engagement

Fixed scope, agreed in writing before we start. If the scope changes, we stop and re-quote rather than invoicing the difference.

Frequently asked questions

Security Awareness Training — your questions answered

How often should staff receive security awareness training?
A full session at induction and annually, with short simulated phishing exercises quarterly in between. Frequency matters more than duration — brief and regular beats a long annual session.
Is security awareness training required for Cyber Essentials?
Cyber Essentials focuses on five technical controls rather than mandating training, but staff awareness underpins several of them and is expected by ISO 27001 and by most cyber insurance questionnaires. Our reporting is designed to evidence it.
Will you name the employees who fail a phishing test?
Not by default. Results are reported at group level. Naming individuals reliably reduces reporting, which is the behaviour that actually protects you. Where an individual needs support we suggest a private, coaching-led conversation.
Can training be delivered on-site?
Yes — on-site across Leicester and the East Midlands, and remotely anywhere in the UK. Sessions are recorded where you want a version for new starters.
How do you measure whether it worked?
Baseline click and report rates from the first simulation, then tracked over subsequent campaigns. Falling click rate matters; rising report rate and shortening time-to-report matter more, because they are what limits real incidents.

Question not answered here? Call +44 7424 967568 or email support@cipherknights.com.

Ready to talk about security awareness training?

Book a free, no-obligation consultation with our Leicester team, or call us and we will point you in the right direction whether or not you become a client.