Cibernetica.io

Advisory

Security Awareness Training

Training that changes what your team does, not just what they have completed.

Most successful attacks on smaller organisations begin with a person rather than a system — a convincing email, a fraudulent invoice, a phone call from someone claiming to be IT. Awareness training addresses that directly. It is also the security spend most likely to be bought badly, because completion rates are easy to measure and behaviour change is not.

What good training looks like, and what to avoid

Delivery models vary. Some providers offer a platform with short modules staff work through on a schedule, usually with phishing simulation attached. Others deliver live sessions, which cost more but suit smaller teams and allow real questions. Role-specific training for finance teams, who are the primary target for invoice fraud and payment redirection, is often worth more than general training for everyone. Phishing simulation sends realistic test emails and reports who clicked. Used well, it identifies where support is needed and measures whether training is working. Used badly, it becomes a trap that embarrasses staff and teaches them to distrust internal communications — which is why the follow-up matters more than the click rate. Punitive framing reliably reduces reporting, because people who fear consequences stay quiet. For compliance purposes, most frameworks expect evidence that training happened and was completed. If you are pursuing ISO 27001, SOC 2, or Cyber Essentials, confirm the provider produces completion records in a form an auditor will accept. The honest caution: annual training that everyone clicks through changes very little. Short, frequent, and relevant beats comprehensive and yearly, and no amount of training substitutes for technical controls that make mistakes survivable.

Who needs it

  • Organisations where staff handle payments, invoices, or customer data
  • Companies needing documented training evidence for ISO 27001, SOC 2, or Cyber Essentials
  • Businesses that have already experienced a phishing incident or attempted invoice fraud
  • Teams onboarding new staff regularly, where training needs to be repeatable rather than one-off

What you get

The right delivery model for your team

Platform-based modules suit larger or distributed teams. Live sessions suit small teams and allow genuine discussion. Which is better depends on your size, not on which is more popular.

Simulation handled properly

Providers matched on how they run phishing simulation and what happens after a click. The follow-up determines whether it improves reporting or suppresses it.

Evidence auditors will accept

Where training supports a compliance requirement, completion records need to be in a form your assessor recognises. Worth confirming before you buy rather than after.

Frequently asked questions

How often should staff be trained?

More often and more briefly than most organisations manage. An annual session that everyone clicks through satisfies a compliance box and changes little. Short, regular content — a few minutes monthly or quarterly — holds attention better and keeps the material current with what attackers are actually doing.

Does phishing simulation actually work?

It works as a diagnostic and as reinforcement, provided the follow-up is supportive rather than punitive. Naming and shaming people who clicked reliably reduces reporting, because staff who fear embarrassment stay quiet — and a phishing email nobody reports is considerably more dangerous than one somebody clicked and flagged. The metric worth tracking is reporting rate, not click rate.

What does it cost?

Platform-based training is usually priced per user per year and is among the cheaper security investments available to a small organisation. Live delivery costs more per session but suits small teams and allows the content to be tailored to your actual sector and risks.

Will this satisfy our compliance requirement?

Most frameworks require evidence that awareness training took place and was completed, rather than mandating a specific provider or format. Confirm that the provider produces completion records your auditor will accept. If training is being bought principally for an audit, say so at the outset — it changes what evidence you need.