Annual security training exists in most organisations, and in most organisations it accomplishes very little. An hour-long module in November, a quiz that can be passed by guessing, a completion certificate filed for the auditor, and eleven months of nothing. People do not retain a single long session, and attackers are not confined to November.
What works is short, frequent, and specific — combined with realistic simulation, because recognising a phishing email is a skill built by practice rather than by being told it exists.
Phishing simulation
We send controlled, realistic phishing to your people on an ongoing basis, matched to the lures actually circulating. When someone clicks, the moment is used for a short piece of in-context teaching rather than a reprimand — that distinction determines whether the programme works or whether people simply learn to hide their mistakes.
That last point is worth dwelling on. A programme that punishes clicks produces employees who click, realise, and say nothing. Those are the incidents that run for weeks. A programme built on the idea that reporting is always the right move produces the opposite, and the opposite is what you want.
Training that respects people's time
Short modules, delivered regularly, targeted at the risk a given role actually faces. Finance staff need to recognise invoice fraud and payment-change requests. Executives need to understand why they are personally targeted and why their assistant is targeted too. Clinical and operational staff need something relevant to their day rather than a generic corporate video.
The threats have changed, and the training has to keep up
The advice that worked five years ago — look for bad grammar, check for a generic greeting — is now actively misleading. Generative tools have made phishing fluent, personalised, and cheap to produce at scale. Voice cloning has made the "urgent call from the CFO" a practical attack rather than a hypothetical one, and it needs only a few seconds of audio, which any executive who has spoken publicly has already provided.
The defence has shifted accordingly. It is less about spotting a fake and more about process: verifying payment changes through a known channel, treating urgency itself as the signal, and never letting a single unverified request move money.
Reporting that satisfies the people who ask for it
Completion rates, simulation results, trend over time, and per-department breakdowns — exported in a form that answers the training question on an insurance renewal or an audit request without anyone assembling a spreadsheet by hand. New hires enrol automatically, which closes the most common gap in otherwise well-run programmes.
Where this fits
Awareness training is a control, not a substitute for one. It reduces the number of incidents that start, and it dramatically improves how early the ones that do start get noticed. It does not remove the need for managed security to catch what gets through, or a 24/7 SOC to act on it. Any provider selling training as the answer to phishing is selling you a false comfort.
Want a baseline simulation to see where your organisation actually stands today?