← All postsSecurity

Security awareness training: what to cover when you cannot buy a programme

Security awareness training works when it changes what people do under pressure. Most of the market sells annual modules; a small company gets more from four topics and a culture where reporting is safe.

SecurityS

Security awareness training is the practice of teaching the people in an organisation to recognise and handle the threats that arrive through them rather than through the network — phishing, invitations to move money, requests to bypass a process because someone senior is in a hurry. It matters because the attacks that actually succeed against small companies are overwhelmingly of that kind. The firewall is rarely the way in; a person under time pressure is.

There is a large market of platforms selling annual modules and simulated phishing campaigns, and for organisations of a certain size they are worth buying. For a company of fifteen, the honest position is that most of the benefit comes from four topics, a short conversation, and one cultural rule.

What security awareness training should actually cover

  • Phishing and its expensive cousin, the message that appears to come from a colleague or a supplier asking for something urgent.
  • Payment fraud specifically: changed bank details, invoices arriving from a familiar-looking address, requests to skip the approval step.
  • Passwords and multi-factor authentication — mostly by explaining that reused passwords are how one breach becomes five.
  • Data handling: what may be sent where, which tools are approved, why customer data does not go into a personal account.
  • Devices: locking screens, updates, what to do when something is lost.
  • How to report, and the promise that reporting fast is never punished.

The finance-facing part earns its place ahead of everything else. Payment redirection fraud has a higher expected cost for a small company than almost any technical attack, and the defence is procedural rather than technical: bank detail changes are verified by a phone call to a number you already had, every time, with no exception for urgency.

Why annual modules underperform

The standard format — a video course each year, a quiz, a completion record — is designed to demonstrate that training happened. It is much weaker at changing behaviour eleven months later, when the message arrives. The reason is not that people are careless; it is that recognition under time pressure is a different skill from recall in a quiz, and the annual format practises the wrong one.

What works better is frequency over depth. Ten minutes at a monthly team meeting, one real example — ideally something that actually arrived at your company — and a short discussion of what made it convincing. That is cheap, it stays current, and it produces the specific thing you want: someone who hesitates at the right moment.

Running it in a small company

  1. Write down the four or five threats that would actually hurt you, in order of expected cost.
  2. Cover the top two properly during onboarding, before anyone gets access to anything.
  3. Take ten minutes a month with one real example rather than an hour a year with generic ones.
  4. Rehearse the payment verification rule until it is reflexive, and make it apply to everyone including the founder.
  5. Tell people exactly who to contact when something looks wrong, including out of hours.
  6. Say clearly, and repeatedly, that reporting a mistake quickly is the desired behaviour.
  7. Keep a record of who was trained and when — it is what a customer questionnaire or insurer will ask for.
  8. After any real incident or near miss, write up what happened and use it as the next session.

Simulated phishing, carefully

Sending fake phishing emails to your own staff is the most common measurement technique and the easiest to get wrong. Used to find out which topics need reinforcement, it is useful. Used to identify and embarrass individuals, it destroys the reporting culture that is worth more than the test — people who fear being caught stop reporting real incidents too.

If you run one, say in advance that simulations happen, report results as an aggregate, never single anyone out, and avoid the cruel lures — fake bonus announcements and the like generate impressive click rates and lasting resentment.

Keeping the record

Ettex Records handles the register: one row per person with the topics covered, the date, and the date the next session is due, so the question of who has been trained on what has an answer that is not somebody's memory. The write-ups of real incidents used as teaching material can sit alongside as their own entries.

It is not a training platform. There is no course content, no video modules, no quizzes, no phishing simulation and no completion tracking that runs by itself — someone marks the register after the session. If you need a programme with content and simulations included, that is a specific product category and buying one is a reasonable decision; what we cover is the record that it happened.

Frequently asked

What should security awareness training cover?

Phishing, payment redirection fraud, passwords and multi-factor authentication, data handling, device basics, and how to report something quickly.

How often should it happen?

Short and frequent beats long and annual. Ten minutes monthly with a real example changes behaviour more than an hour-long course each year.

What is the highest-value topic for a small company?

Payment verification. Redirection fraud has a higher expected cost than most technical attacks, and the defence is a phone call to a number you already had.

Is simulated phishing a good idea?

As aggregate measurement, yes. As a way to identify individuals, no — it suppresses reporting of real incidents, which costs more than the test is worth.

Should training completion be recorded?

Yes. Customer questionnaires, insurers and certification schemes all ask, and a register takes a minute to update.

Is a platform necessary?

Not for a small company. At larger sizes, content and simulations bought as a package start to make sense.

Cover the threats that would actually cost you, ten minutes a month with real examples, make the payment verification rule absolute, and never punish somebody for reporting fast.

MI
Written by Maria I.

Part of the Ettex team — writing about product, engineering and the future of work.

More posts
Get the best of the Ettex blogProduct news, guides and tips — straight to your inbox, no spam.