The email that will cost your company money will not arrive in the IT department. It will arrive in administration, asking to change a supplier's bank account; in HR, with a CV attached; at reception, warning about a held package. The people receiving those messages do not need technical training. They need a cybersecurity awareness programme designed around their real work, not a simplified version of the developer course.

What makes cybersecurity awareness different

Technical training aims to help someone build safer systems. Awareness has a narrower target: that a person recognises an abnormal situation in their routine and knows what to do in the next two minutes. That is the whole scope, and it is why the content has to be written in the language of each role.

Explaining a man-in-the-middle attack to the person in charge of invoicing changes little. Explaining that a long-standing supplier can write from their real address, with the previous conversation below, asking to update the bank account for the next invoice, changes a lot. It is their job, it is plausible and they know exactly when it could happen.

What each area should learn

A generic programme for the whole company wastes half of almost everyone's time. Segmenting by function costs little and makes the training far more useful:

  • Administration and finance: CEO fraud, supplier bank account changes, altered invoices, urgency and confidentiality as warning signs.
  • Human resources: candidate attachments, requests for employee data, impersonation of management asking for payroll or employment documents.
  • Sales: fake profiles, CRM credentials, open Wi-Fi and personal mobile use outside the office.
  • Reception and customer service: calls asking for internal information, unexpected visitors, USB drives that appear and packages nobody expected.
  • Management: they are the most impersonated target and the group most likely to ask for exceptions to the processes they approve.
  • Everyone: passwords and password managers, second factor, approval fatigue and what to do with a lost phone.

Smishing that impersonates the tax agency, courier companies or social security deserves its own module, because it reaches your team's personal phones and then spills into work without anyone noticing.

Cadence: little and often

The annual two-hour session exists so someone can say it happened. It is forgotten in two weeks and creates no habit. A lighter sustained structure works better:

  • An initial sixty-minute session, in person if possible, using cases from your own company.
  • Short refreshers every month or two, five to ten minutes on one topic.
  • A quarterly phishing simulation that measures and teaches at the same time.
  • Mandatory onboarding during each new employee's first week.
  • A targeted warning when an active campaign is genuinely affecting you.

The practical rule is that no refresher should take longer than reading a long email. Ask for more time than people have and they will start skipping it, including the important messages.

Make reporting normal and appreciated

This is where most programmes win or lose. A suspicious message reported after five minutes is an incident that does not happen. The same message discovered three weeks later, when the supplier asks about a payment already sent elsewhere, is a serious problem.

Four concrete conditions make people report:

  1. One obvious channel: an email address, a mail-client button or a chat, always the same one, that everyone remembers without searching.
  2. Fast visible response: someone answers the same day, even if only to say it was legitimate. Silence teaches that reporting is pointless.
  3. No consequences for being wrong: reporting ten false alarms must be acceptable. Ridicule one and there will not be an eleventh.
  4. Explicit recognition: mentioning in a team meeting that someone spotted a real attempt, with thanks, is worth more than any slide.

One more condition is often forgotten: a person who clicked must also be able to speak up without fear. An employee who hides a mistake because they expect blame is the most expensive scenario, so the company message has to be unambiguous: late reporting is far better than no reporting.

How to measure whether it works

The percentage of people who completed the course measures attendance, nothing more. These signals show progress:

  • Number of suspicious messages reported each month, including the ones that turn out to be legitimate.
  • Average time between a fraudulent message arriving and the first internal warning.
  • Questions sent to the channel before a payment or bank-detail change.
  • How reporting and clicking evolve across repeated simulations.
  • Incidents detected by employees instead of by a provider or customer.

The programme does not replace process

No awareness programme can withstand a badly designed process. If one person can change a supplier bank account and order the payment without anyone else verifying it, that process will eventually fail even if the training is excellent. Out-of-band verification for any bank-detail change, dual authorisation above a threshold and a written first-day incident procedure are controls that support people when the message is convincing.

Our security awareness programmes start from the real risks in each area and use periodic simulations. If you want to start with one thing today, choose the reporting channel, announce it and answer every report during the first month. The rest of the programme builds much better on that habit.

Want to know how exposed your website is?

Ciphraverse's Security Assessment checks websites, portals and e-commerce with a professional external audit designed for SMEs.

Discover Security Assessment