Every organisation we assess has security awareness training. Almost none of them can show it changed anything. The reason is consistent: the training is designed to be completed, not to be effective, and those two goals pull in opposite directions.
A completion-optimised programme is annual, universal, video-based and followed by a five-question quiz that nobody fails. It produces a clean compliance record and a workforce that has learned exactly one thing — that security training is something you click through.
Start from your incidents, not from a syllabus
Generic curricula cover the full threat landscape because they have to sell to everyone. Your organisation does not face the full threat landscape; it faces a handful of realistic attack paths, and it has a history of the ones that nearly worked.
Before writing any material, we go through the incident log, the helpdesk tickets and the results of a baseline phishing simulation. That produces a ranked list of what actually reaches your people. In most organisations the top three are business email compromise, credential phishing against the single sign-on portal, and a supplier-invoice fraud pattern targeting finance specifically.
Three risks, three tailored modules, delivered to the roles they affect. That is a very different programme from twelve chapters delivered to everyone.
Make it short, frequent and role-specific
Attention is the constraint. A forty-minute annual session is worse than eight five-minute sessions spread across the year, and dramatically worse than a two-minute intervention delivered at the moment somebody nearly falls for something.
Role-specific matters as much as short. The finance team needs to be genuinely expert at spotting payment-redirection fraud, because they are the ones targeted by it. The engineering team needs to understand credential hygiene and dependency risk. The reception desk needs to know what physical pretexting looks like. Sending all three the same content wastes everyone's time and teaches the specialists nothing.
Simulate, but do it honestly
Phishing simulation is the only part of most programmes that produces real data, and it is frequently run in a way that destroys trust.
Two rules make the difference. First, never punish a click. The moment reporting a mistake becomes risky, people stop reporting, and your detection time goes from minutes to weeks. The metric that matters is not click rate; it is report rate, and specifically the time from first delivery to first report.
Second, do not use cruel lures. Simulated bonus announcements and fake redundancy notices work spectacularly in the click statistics and cost you the goodwill of the entire workforce. The point is to build a reporting reflex, not to prove people can be fooled — everyone can be fooled by a sufficiently good lure, including the security team.
Measure something that means anything
Completion percentage measures compliance. These measure security:
- Time to first report on a simulated campaign, tracked over successive rounds
- Report rate as a proportion of recipients, not just of clickers
- Repeat-click cohort size, which tells you where targeted coaching is needed
- Real incidents caught by a person, versus caught by tooling
The last one is the point of the whole exercise. A workforce that reports quickly turns a potential breach into an alert, and that is worth more than any percentage on a compliance dashboard.
Give people somewhere to go
The most valuable output of a good programme is not knowledge, it is a habit: when something feels wrong, tell someone immediately.
That requires a route that takes seconds and carries no social cost — a report button in the mail client, a channel that is monitored, and a visible practice of thanking people for reports that turn out to be nothing. Organisations that get this right find their mean time to detection drops before their click rate does.
Security awareness training is part of our managed services practice, alongside security risk analysis and employee training sessions built around the systems your staff actually use.
