User Awareness Training

Your staff learn to spot and report phishing, fraud and social engineering. Phishing simulations, role-based training and progress you can measure and show your board.

Service Details

User awareness training gives your staff the skills to spot phishing, invoice fraud and social engineering, and the habit of reporting it quickly. You get a programme of phishing simulations and short role-based modules, with reporting that shows how behaviour changes over time.

It sits within our continuous operations services, alongside the identity, endpoint and cloud work that keeps your organisation secure month after month.

INFO

Your people see suspicious emails before anyone else. Training turns that position into an early warning, so threats reach IT while there is still time to act.


Why attackers target people

Phishing and social engineering are among the most common ways attacks begin, according to the UK Government’s Cyber Security Breaches Survey. A convincing email or phone call can get around technical controls by asking someone to enter a password, approve a payment or open a file. An annual slide deck does little to change that. Regular, realistic practice does more.


Staff who report phishing instead of clicking it

We start with a simulated phish to set a baseline, train each group on the threats they actually face, then test again. You see click rates and report rates move over time.

Finance teams practise spotting invoice and payment fraud, executives see targeted impersonation attempts, and everyone covers the fundamentals. Anyone who clicks gets private coaching, because staff who fear blame stop reporting mistakes.

A trainer presenting to colleagues seated in a bright training room

What the programme includes

Measured practice rather than annual box-ticking:

Baseline Simulation

A realistic simulated phish before training starts, so progress is measured rather than guessed.

Role-Based Modules

Short sessions for finance, HR, executives, developers and general staff, focused on the threats each role sees.

Ongoing Simulations

Regular tests that change in style and difficulty, so awareness keeps pace with new attack methods.

Board Reporting

Click-rate, report-rate and completion trends in a format your leadership team can act on.


Who it is for

The programme suits organisations that want staff to be an active part of their security, not just a compliance checkbox. It works well if you handle payments or client money, hold personal data, or need to show auditors and regulators that training happens and works. For financial services and insurance firms, it also supports the evidence regulators expect on operational resilience.

How the programme runs

  1. Agree the approach — We set scope, simulation rules and who is informed, so testing is fair and your staff are treated with respect.
  2. Baseline — A simulated phish shows where you start, broken down by team.
  3. Train — Staff complete short modules matched to their role, with completion tracked.
  4. Test and coach — Regular simulations follow, and anyone who clicks gets a short, private coaching moment.
  5. Report — You receive trends and recommendations, ready to share with your board.

The human layer of defence

Training adds to technical controls rather than replacing them. Phishing-resistant sign-in limits what a stolen password unlocks, and managed devices contain the click that still happens. Each layer covers the gaps in the others.

Train

Staff who spot and report threats

Harden

Phishing-resistant authentication

Contain

Managed devices limit the damage


Evidence for audits and regulators

A documented programme gives you records auditors ask for. ISO 27001 includes a control for information security awareness, education and training (Annex A 6.3). PCI DSS requires a formal security awareness programme, and DORA requires ICT security awareness and training for staff and management in EU financial entities. UK GDPR expects appropriate organisational measures, which usually include training, and NIS2 lists cyber hygiene and training among its required measures for organisations in scope in the EU.

Cyber Essentials does not require training, but training covers risks its five technical controls do not. Our compliance support team can turn your training records into an audit-ready evidence pack.

Services that work alongside

Awareness training is strongest when paired with technical controls. Identity and access management adds phishing-resistant sign-in, endpoint management keeps devices patched and contained, and Microsoft 365 or Google Workspace administration tightens email filtering and sharing settings. To test how your people and processes hold up against a realistic attack, see penetration testing.


Frequently asked questions

Make your people part of your defence

Tell us about your teams and the threats that worry you most. You get a clear view of how a training programme would run, what it would measure, and how it supports your compliance evidence.