Organisations can invest heavily in firewalls, endpoint protection, identity management and threat detection, yet attackers will still look for opportunities to persuade an employee to do something they should not.
Click a link.
Approve an MFA request.
Reveal a password.
Make a payment.
Open an attachment.
Share sensitive information.
Modern social engineering increasingly targets human decision-making rather than purely technical vulnerabilities.
That makes employee cyber security awareness an important layer of organisational defence.
But effective cyber security awareness training should involve more than requiring employees to complete an annual online course.
Attack techniques change. Employees forget. New staff arrive. Roles carry different risks. And knowing the correct answer to a security quiz does not necessarily mean someone will make the right decision when confronted with a convincing request during a busy working day.
The objective should therefore move from:
“Have our employees completed their cyber training?”
to:
“Are our employees becoming more likely to make secure decisions?”
This guide examines what IT and security teams should compare when selecting employee security awareness and training programmes.
At a Glance: What Security Awareness Buyers Should Compare
| Area | What IT Teams Should Consider |
|---|---|
| Objectives | Compliance, awareness, behaviour or risk reduction |
| Threats | Phishing, vishing, social engineering and emerging attacks |
| Content | Relevance, realism and frequency of updates |
| Delivery | Online, classroom, immersive and scenario-based learning |
| Phishing | Simulation, reporting and follow-up training |
| Roles | Different training for different employee risks |
| Engagement | Participation, relevance and retention |
| Reporting | Whether employees know how and when to report |
| Measurement | Behavioural outcomes rather than completion alone |
| Culture | Whether training encourages reporting rather than blame |
| Integration | Links with wider technical security controls |
| Frequency | Continuous reinforcement rather than annual intervention |
What Is Cyber Security Awareness Training?
Cyber security awareness training teaches employees how to recognise, avoid and respond to security threats they may encounter through their work.
Common subjects include:
- Phishing
- Social engineering
- Password security
- Multi-factor authentication
- Data protection
- Remote working
- Public Wi-Fi
- Ransomware
- Physical security
- Insider threats
- Incident reporting
The National Cyber Security Centre provides exercises covering many of these areas through its Exercise in a Box programme, including phishing, passwords, ransomware, cloud productivity tools and secure connectivity.
NCSC – Exercise in a Box – https://www.ncsc.gov.uk/section/exercise-in-a-box/overview
But awareness is only the first stage.
An employee might know that unexpected login requests can be suspicious.
The real test comes when a convincing message apparently from IT arrives while that employee is busy and asks them to authenticate immediately.
Security Awareness Principle
The ultimate question isn’t:
“Did they know the answer?”
It is:
“What did they actually do?”
Move from Compliance to Behaviour Change
Many organisations have historically approached cyber awareness primarily as a compliance requirement.
Employees:
Receive course → complete modules → answer questions → pass test
The organisation can then demonstrate completion.
There is value in establishing baseline knowledge, but completion alone tells security teams relatively little about how employees will behave during an actual attack.
Immersive training providers are increasingly challenging this model.
Esc. The Cyber Escape Room, for example, places employees into interactive scenarios involving situations such as ransomware incidents, compromised equipment and information-security risks.
Esc. The Cyber Escape Room – https://www.cyberescaperoom.co/
The principle is closer to rehearsal than instruction.
Employees need to:
- Identify information
- Make decisions
- Work under pressure
- Experience consequences
- Discuss what happened
That creates an interesting question for buyers: Does the training simply transfer information, or does it allow employees to practise secure behaviour?
Security Awareness Training Should Reflect Current Threats
Threats evolve much faster than many corporate training programmes.
A course built several years ago may still teach employees to identify phishing through:
- Poor spelling
- Bad grammar
- Generic greetings
- Unprofessional formatting
Those indicators can still occur. But they are no longer sufficient. Generative AI can help attackers create polished, convincing and personalised communications at scale.
Protrona highlights this shift in its own analysis of security awareness, arguing that AI-generated phishing increasingly moves the challenge away from spotting obvious mistakes and towards making informed decisions under pressure.
Protrona – Why Traditional Security Awareness Training Needs to Change – https://www.protrona.com/blogs/why-traditional-security-awareness-training-needs-to-change
Training content therefore needs to evolve alongside the threat environment.
Buyer Tip
Ask prospective providers:
“When was this training scenario last updated, and what has changed since the previous version?”
A training library containing hundreds of modules has limited value if the scenarios do not resemble the attacks employees are actually receiving.
Phishing Awareness Training
Phishing remains one of the most important areas of employee security training.
But effective phishing education should go beyond teaching employees to look for suspicious links.
Employees may need to consider:
- Sender identity
- Context
- Urgency
- Requests for credentials
- Payment changes
- Unexpected attachments
- Login pages
- QR codes
- Requests to bypass process
Increasingly, employees should also understand that a phishing message may look completely professional.
The better question can become:
“Is this request normal, expected and independently verifiable?”
rather than:
“Does this email look badly written?”
Phishing Simulation
Simulated phishing can help organisations understand how employees respond when presented with realistic messages.
IntaForensics, for example, provides phishing assessments designed to simulate real-world phishing attacks, identify awareness gaps and support employee education.
IntaForensics – Cyber Security Services – https://www.intaforensics.com/services/cyber-security/
Metrics might include:
- Emails opened
- Links clicked
- Credentials submitted
- Attachments opened
- Messages reported
But organisations should use these results carefully.
The purpose should be to identify patterns and improve behaviour rather than simply catch employees making mistakes.
A high click rate might indicate:
- Poor training
- An unusually convincing simulation
- Risk within a particular department
- Weak reporting processes
- A need for stronger technical controls
Measurement Insight
A phishing simulation should generate learning, not simply a league table of failure.
Reporting Can Matter as Much as Clicking
Security teams often concentrate on the number of employees who click a simulated phishing link.
But another metric can be equally important: How quickly did somebody report it?
Imagine a phishing email reaching 1,000 employees.
Ten click.
But the first recipient reports the email within two minutes, enabling security teams to investigate and potentially block the attack.
That employee has become an active security sensor.
Organisations should therefore train people to recognise when something feels wrong and provide a simple reporting route.
That might involve:
- A phishing-report button
- Service desk
- Security mailbox
- Hotline
- Teams/Slack channel
The process should be easy enough to use without hesitation.
Build a Positive Security Reporting Culture
Employees sometimes fail to report mistakes because they fear being blamed.
That can make an incident worse.
Someone who clicks a suspicious link and immediately tells the security team may allow credentials to be reset or malicious activity contained quickly.
Someone who hides the same mistake may give an attacker more time.
Training should therefore reinforce messages such as:
“If something feels wrong, report it.”
and:
“If you’ve made a mistake, tell us quickly.”
This requires security awareness to be part of organisational culture rather than a periodic test employees feel they are expected to pass.
Social Engineering Beyond Email
Employee security awareness should not be synonymous with email phishing.
Attackers may approach people through:
- Telephone calls
- SMS
- Messaging platforms
- Social media
- Video calls
- Physical visits
Voice phishing (or vishing) can be particularly effective because employees may feel pressure to respond immediately.
An attacker could impersonate:
- IT support
- A senior executive
- A supplier
- A bank
- A customer
Esc. The Cyber Escape Room includes voice-phishing simulation within its wider portfolio, allowing employees to practise responding to suspicious calls rather than merely reading about them.
Esc. – https://www.cyberescaperoom.co/
This reflects a wider shift towards training employees across multiple attack channels.
AI-Enabled Social Engineering
Generative AI is changing both the quality and scale of social engineering.
Attackers can potentially use AI to help produce:
- Personalised emails
- Convincing business language
- Translated messages
- Synthetic voices
- Fake imagery
- Deepfake video
The practical lesson for employees is important.
Traditional cues such as:
“It sounds like my boss”
or
“The email is professionally written”
provide weaker assurance than they once did.
Employees increasingly need to understand verification processes.
For example, an unusual payment request may need independent confirmation through a known communication channel regardless of how convincing the original request appears.
Protrona’s 2026 analysis similarly emphasises the shift towards AI-generated messages that can mimic legitimate business communications and exploit organisational context.
Protrona – https://www.protrona.com/
Password and Authentication Training
Employees should understand not only password rules but why authentication controls matter.
Training may cover:
- Unique passwords
- Password managers
- MFA
- Credential theft
- Password reuse
- MFA fatigue
- Suspicious login prompts
The NCSC’s Exercise in a Box includes dedicated exercises around password use and password managers.
NCSC – Using Passwords – https://www.ncsc.gov.uk/section/exercise-in-a-box/using-passwords
Practical training can help employees connect seemingly inconvenient controls with the attacks those controls are designed to prevent.
That context can improve adoption.
Role-Based Cyber Security Training
Not every employee carries the same cyber risk.
A receptionist, software developer, finance director and system administrator encounter different threats.
Training can therefore be segmented.
Finance
- Payment fraud
- Invoice redirection
- Executive impersonation
HR
- Personal data
- Malicious attachments
- Employee impersonation
Executives
- Spear phishing
- Sensitive information
- Account compromise
IT administrators
- Privileged credentials
- Remote access
- Administrative security
Customer-facing staff
- Identity verification
- Social engineering
- Information disclosure
Arcanum Cyber Security’s wider consultancy work spans risk assessment, security governance, incident management and scenario-based testing, illustrating how organisational cyber risks extend well beyond a generic employee training module.
Arcanum Cyber Security – https://arcanum-cyber.com/
Training Principle
Everyone needs security awareness. Not everyone needs identical security awareness.
Training should reflect the decisions people actually make in their roles.
Training for Senior Leaders
Executives require particular attention.
They may:
- Hold privileged information
- Authorise payments
- Access sensitive communications
- Be publicly identifiable
- Become targets for impersonation
They also play a critical role during incidents.
Cyber exercises should therefore include leadership as well as IT.
The NCSC recommends senior-leader involvement in several of its tabletop scenarios, including ransomware and heightened cyber-threat exercises.
NCSC – Tabletop Exercises – https://www.ncsc.gov.uk/section/exercise-in-a-box/tabletop-exercises
Senior training can cover both personal security behaviour and organisational decision-making during an incident.
Cyber Crisis Simulations
There is a significant difference between asking:
“Do we have an incident response plan?”
and discovering:
“Can people actually follow it under pressure?”
Core to Cloud provides immersive cyber crisis simulations designed to bring technical and business teams together to stress-test response plans, identify gaps and improve confidence before a real incident occurs.
Core to Cloud – https://www.coretocloud.co.uk/
The NCSC similarly describes cyber exercising as a way for organisations to practise response in a safe environment and identify areas for improvement.
NCSC – Effective Steps to Cyber Exercise Creation – https://www.ncsc.gov.uk/guidance/effective-steps-to-cyber-exercise-creation
Possible scenarios include:
- Ransomware
- Data breach
- Supplier compromise
- Insider threat
- Credential theft
These exercises move awareness into organisational resilience.
Immersive Cyber Security Training
One challenge with employee training is attention.
If employees see cyber awareness as something to click through as quickly as possible, its value is inevitably limited.
Interactive formats can include:
- Escape rooms
- Workshops
- Games
- Scenario exercises
- Tabletop simulations
- Live demonstrations
Esc. The Cyber Escape Room uses physical and digital scenarios to place employees inside security situations and require them to make decisions collaboratively.
Esc. – https://www.cyberescaperoom.co/services/
The NCSC also provides short interactive micro exercises covering subjects including phishing, passwords, ransomware and secure working.
NCSC – Micro Exercises – https://www.ncsc.gov.uk/section/exercise-in-a-box/micro-exercises
The important procurement question is not whether training is entertaining for its own sake.
It is whether engagement improves: attention → retention → decision-making → behaviour
Continuous vs Annual Security Awareness Training
Security awareness is unlikely to be most effective as a single annual event.
Employees may benefit from shorter, repeated interventions throughout the year.
For example:
January: phishing
March: password and authentication
May: social engineering
July: remote working
September: ransomware exercise
November: AI-enabled fraud
The programme might combine:
- Online modules
- Microlearning
- Simulated phishing
- Workshops
- News updates
- Immersive experiences
- Tabletop exercises
This creates reinforcement rather than relying on one annual knowledge transfer.
Cyber Awareness and New Employees
New joiners create another important training moment.
Employees should ideally understand security expectations before insecure habits develop.
Onboarding might include:
- Acceptable use
- Passwords and MFA
- Phishing reporting
- Data handling
- Remote working
- Physical security
- Incident reporting
But onboarding should be the beginning of the programme, not the end.
Security awareness needs to continue as roles, technologies and threats change.
Remote and Hybrid Working Security
Employees increasingly operate outside traditional corporate environments.
Training may need to address:
- Home networks
- Personal devices
- Public Wi-Fi
- Screen privacy
- Shared spaces
- Video conferencing
- Lost devices
- Cloud applications
IntaForensics includes remote and home-working security within its employee cyber-awareness training alongside phishing, password security, physical security and incident-response awareness.
IntaForensics – Cyber Security Awareness Training – https://www.intaforensics.com/training-events/cyber-awareness-training/
Organisations should ensure training reflects where employees genuinely work rather than assuming everybody operates from a controlled office environment.
Security Awareness Is Not a Substitute for Technical Controls
There is a danger in treating employees as the final answer to every cyber threat.
Even well-trained people make mistakes.
Protrona highlights the importance of combining awareness with controls such as MFA, email security, monitoring and access management.
Protrona – https://www.protrona.com/blogs/why-traditional-security-awareness-training-needs-to-change
The appropriate model is therefore:
Technology + process + people
not:
Technology fails → employee must spot everything
A convincing attack that reaches an employee should ideally still encounter additional layers of protection.
Human Risk Principle
Employees should be an important layer of defence.
They should not be the only layer standing between an attacker and a serious incident.
Measuring Security Awareness Training
One of the most important procurement questions is how success will be measured.
Basic metrics include:
- Training completion
- Test scores
- Attendance
Useful, but limited.
More behavioural measures could include:
- Phishing-reporting rates
- Time to report
- Simulation outcomes
- Repeat risky behaviour
- Password-manager adoption
- MFA adoption
- Security queries raised
- Incident-reporting behaviour
Organisations can also track trends over time.
For example:
Quarter 1: 14% phishing susceptibility
Quarter 4: 6% phishing susceptibility
But numbers require context.
The simulations may have changed in difficulty.
Training success should therefore be evaluated across several indicators rather than reduced to one score.
Measure Risk, Not Activity
A training platform may report: 98% course completion
That tells the organisation the programme was delivered.
It does not necessarily tell it whether cyber risk fell.
Buyers should ask providers:
“How will your programme demonstrate that employee behaviour is improving?”
Potential evidence could include:
- More suspicious messages reported
- Faster reporting
- Fewer repeat simulation failures
- Improved scenario decisions
- Stronger authentication behaviour
- Better incident escalation
Measurement Principle
Completion measures activity. Behaviour measures impact.
Both can be useful, but they answer different questions.
Avoid Creating a Blame Culture
The phrase “people are the weakest link” is common in cybersecurity.
It is also potentially counterproductive.
Employees operate within systems designed by organisations.
If people regularly approve fraudulent requests, the organisation should ask:
- Was the process clear?
- Was verification practical?
- Did technical controls fail?
- Was training realistic?
- Were employees under inappropriate pressure?
Effective awareness programmes should create confidence rather than fear.
Employees should feel able to: Pause → question → verify → report
without worrying that asking for help will be viewed as failure.
Choosing a Security Awareness Training Provider
Buyers should begin by defining the problem.
Is the objective to:
- Meet compliance requirements?
- Reduce phishing susceptibility?
- Improve incident reporting?
- Train high-risk departments?
- Prepare executives?
- Build a security culture?
- Exercise incident response?
Different providers may be appropriate for different requirements.
Some specialise in:
- Online learning platforms
- Phishing simulations
- Immersive training
- Consultancy
- Cyber exercises
- Specialist technical training
A mature programme may use several approaches rather than relying on one format.
What Should Buyers Compare?
Threat relevance
Does training reflect current attack techniques?
Engagement
Will employees actually pay attention?
Behaviour
Does training provide opportunities to practise decisions?
Personalisation
Can content be adapted by department or risk?
Simulation
Are realistic phishing or social-engineering exercises available?
Reporting
Does the programme encourage employees to report suspicious activity?
Measurement
Can the organisation track behaviour change over time?
Delivery
Are classroom, remote, digital and immersive options available?
Content updates
How quickly are new threats incorporated?
Integration
Does training complement wider security controls and incident response?
Questions to Ask Security Awareness Training Suppliers
- What employee behaviours is your programme designed to change?
- How do you assess our existing human cyber risk?
- How frequently is training content updated?
- How do you incorporate emerging threats such as AI-enabled phishing?
- Can training be tailored by role or department?
- Do you provide phishing simulations?
- Can you simulate threats beyond email?
- How do you encourage employees to report suspicious activity?
- How do you avoid creating a blame culture?
- What immersive or scenario-based training is available?
- Can you train remote and hybrid employees?
- What options exist for executives and senior leaders?
- Do you provide incident-response exercises?
- How is employee progress measured?
- Can you measure behavioural change rather than simply completion?
- How do you identify repeat areas of risk?
- What reporting is available to security teams?
- Can the programme integrate with our existing security tools?
- How do you benchmark performance over time?
- What would success look like after 12 months?
Frequently Asked Questions
What is cyber security awareness training?
Cyber security awareness training helps employees recognise, avoid and report cyber threats including phishing, social engineering, credential theft and suspicious activity.
How often should employees receive cyber security training?
Rather than relying solely on annual training, organisations can use regular reinforcement through microlearning, simulations, exercises and threat updates throughout the year.
What is phishing simulation?
Phishing simulation involves sending controlled, realistic phishing messages to employees to understand how they respond and identify opportunities for further training.
Does cyber security awareness training work?
Training can improve knowledge and behaviour, but its effectiveness depends on factors including relevance, engagement, frequency, realism and reinforcement. Organisations should measure behavioural outcomes as well as course completion.
What should security awareness training cover?
Common topics include phishing, social engineering, passwords, MFA, ransomware, data protection, remote working, physical security and incident reporting.
What is immersive cyber security training?
Immersive training places employees into interactive scenarios in which they practise responding to security situations rather than simply receiving information about them.
Should cyber security training be different for different employees?
Often, yes. Employees in finance, HR, IT, executive leadership and other roles may face different threats and benefit from role-specific training.
Product Guide
Employee cyber security awareness can range from baseline training and phishing assessment through to immersive exercises, specialist consultancy and full cyber-crisis simulations. Buyers should consider which combination best addresses their organisation’s particular human risks. These solutions are among those you can meet at the Elevate Tech Summit and Cyber Secure Forum.
Featured Suppliers
Esc. The Cyber Escape Room
Cyber security awareness specialist using immersive physical and digital experiences to help employees practise responding to realistic security situations. Its portfolio includes portable cyber escape rooms, digital scenario-based learning and social-engineering simulations, with an emphasis on behaviour change rather than passive instruction.
Website: https://www.cyberescaperoom.co/
Protrona
Cybersecurity provider combining managed services, security operations, governance, compliance and security-culture support. Its employee-security approach focuses on strengthening the organisation’s ‘human firewall’, including awareness of evolving social-engineering and AI-enabled phishing techniques.
Website: https://www.protrona.com/
Arcanum Cyber Security
NCSC Assured Cyber Security Consultancy providing services spanning cyber risk assessment, governance, incident management, penetration testing, digital forensics and scenario-based testing. Its wider risk-led approach can help organisations connect employee behaviour and security awareness with technical and organisational cyber resilience.
Website: https://arcanum-cyber.com/
Core To Cloud Ltd
Cybersecurity specialist supporting CISOs and IT teams through services including continuous security assurance, threat intelligence, managed detection and response, third-party risk management and cyber crisis simulation. Its simulations bring technical and business teams together to rehearse real-world incident response and identify gaps before an attack occurs.
Website: https://www.coretocloud.co.uk/
IntaForensics
Cyber security and digital-forensics specialist providing employee cyber-awareness training, phishing assessments, first-responder training and incident-response tabletop exercises. Awareness courses cover areas including phishing, social engineering, passwords, remote working, physical security and incident reporting, with remote and in-person delivery available.
Website: https://www.intaforensics.com/
Explore Employee Security Awareness & Training
Cyber security awareness ultimately needs to bridge a deceptively difficult gap:
Knowing what someone should do
and
doing it when it matters.
That is why organisations should look beyond course completion when evaluating employee security programmes.
Realistic scenarios, repeated reinforcement, phishing simulations, simple reporting processes and role-specific training can help turn abstract security guidance into behaviours employees can apply during their working day.
The goal is not to create a workforce frightened of clicking anything.
It is to create people who feel confident enough to:
Pause. Question. Verify. Report.
And that human layer should operate alongside (rather than instead of) strong technical security controls.
The Elevate Tech Summit and Cyber Secure Forum connect senior IT and cybersecurity professionals with carefully selected providers of employee security awareness, cyber training and wider security solutions through a programme of pre-arranged one-to-one meetings.
Explore employee security awareness and training solutions, compare specialist providers and discover approaches that can help turn cyber security from an annual compliance requirement into an everyday organisational behaviour.
Sources
IntaForensics – Cyber Security Services – https://www.intaforensics.com/services/cyber-security/
National Cyber Security Centre – Exercise in a Box – https://www.ncsc.gov.uk/section/exercise-in-a-box/overview
National Cyber Security Centre – Micro Exercises – https://www.ncsc.gov.uk/section/exercise-in-a-box/micro-exercises
National Cyber Security Centre – Tabletop Exercises – https://www.ncsc.gov.uk/section/exercise-in-a-box/tabletop-exercises
National Cyber Security Centre – Effective Steps to Cyber Exercise Creation – https://www.ncsc.gov.uk/guidance/effective-steps-to-cyber-exercise-creation
Esc. The Cyber Escape Room – https://www.cyberescaperoom.co/
Esc. – Interactive Security Awareness Experiences – https://www.cyberescaperoom.co/services/
Protrona – https://www.protrona.com/
Protrona – Why Traditional Security Awareness Training Needs to Change – https://www.protrona.com/blogs/why-traditional-security-awareness-training-needs-to-change
Arcanum Cyber Security – https://arcanum-cyber.com/
Core To Cloud – https://www.coretocloud.co.uk/
IntaForensics – Cyber Security Awareness Training – https://www.intaforensics.com/training-events/cyber-awareness-training/
Image credit: https://unsplash.com/photos/woman-using-macbook-pro-6U4n-I2_R2M




