Corrective action: fixing the cause rather than the symptom
A corrective action stops a problem recurring. Most of what gets recorded as one is a repair — the thing you do to the affected item, which changes nothing about the next occurrence.
Security awareness training works when it changes what people do under pressure. Most of the market sells annual modules; a small company gets more from four topics and a culture where reporting is safe.
Security awareness training is the practice of teaching the people in an organisation to recognise and handle the threats that arrive through them rather than through the network — phishing, invitations to move money, requests to bypass a process because someone senior is in a hurry. It matters because the attacks that actually succeed against small companies are overwhelmingly of that kind. The firewall is rarely the way in; a person under time pressure is.
There is a large market of platforms selling annual modules and simulated phishing campaigns, and for organisations of a certain size they are worth buying. For a company of fifteen, the honest position is that most of the benefit comes from four topics, a short conversation, and one cultural rule.
The finance-facing part earns its place ahead of everything else. Payment redirection fraud has a higher expected cost for a small company than almost any technical attack, and the defence is procedural rather than technical: bank detail changes are verified by a phone call to a number you already had, every time, with no exception for urgency.
The standard format — a video course each year, a quiz, a completion record — is designed to demonstrate that training happened. It is much weaker at changing behaviour eleven months later, when the message arrives. The reason is not that people are careless; it is that recognition under time pressure is a different skill from recall in a quiz, and the annual format practises the wrong one.
What works better is frequency over depth. Ten minutes at a monthly team meeting, one real example — ideally something that actually arrived at your company — and a short discussion of what made it convincing. That is cheap, it stays current, and it produces the specific thing you want: someone who hesitates at the right moment.
Sending fake phishing emails to your own staff is the most common measurement technique and the easiest to get wrong. Used to find out which topics need reinforcement, it is useful. Used to identify and embarrass individuals, it destroys the reporting culture that is worth more than the test — people who fear being caught stop reporting real incidents too.
If you run one, say in advance that simulations happen, report results as an aggregate, never single anyone out, and avoid the cruel lures — fake bonus announcements and the like generate impressive click rates and lasting resentment.
Ettex Records handles the register: one row per person with the topics covered, the date, and the date the next session is due, so the question of who has been trained on what has an answer that is not somebody's memory. The write-ups of real incidents used as teaching material can sit alongside as their own entries.
It is not a training platform. There is no course content, no video modules, no quizzes, no phishing simulation and no completion tracking that runs by itself — someone marks the register after the session. If you need a programme with content and simulations included, that is a specific product category and buying one is a reasonable decision; what we cover is the record that it happened.
Phishing, payment redirection fraud, passwords and multi-factor authentication, data handling, device basics, and how to report something quickly.
Short and frequent beats long and annual. Ten minutes monthly with a real example changes behaviour more than an hour-long course each year.
Payment verification. Redirection fraud has a higher expected cost than most technical attacks, and the defence is a phone call to a number you already had.
As aggregate measurement, yes. As a way to identify individuals, no — it suppresses reporting of real incidents, which costs more than the test is worth.
Yes. Customer questionnaires, insurers and certification schemes all ask, and a register takes a minute to update.
Not for a small company. At larger sizes, content and simulations bought as a package start to make sense.
Cover the threats that would actually cost you, ten minutes a month with real examples, make the payment verification rule absolute, and never punish somebody for reporting fast.
A corrective action stops a problem recurring. Most of what gets recorded as one is a repair — the thing you do to the affected item, which changes nothing about the next occurrence.
A conflict of interest policy is mostly a register and a habit. The point is not to forbid overlapping interests but to have them written down before anyone has reason to ask.
A record of processing activities lists what personal data you hold, why, where it goes and how long you keep it. It is dull to build and it answers half the questions anyone will ever ask you.