Every technical control you buy sits behind the same final safeguard: somebody deciding whether to click. That makes staff awareness the best return on any security spending most businesses can make — and the one most consistently skipped.
The numbers, as they currently stand
The government’s Cyber Security Breaches Survey for 2025/26 found that 43% of UK businesses identified a breach or attack in the previous twelve months, around 612,000 organisations. The rate rises with size: 46% of small businesses and 65% of medium-sized businesses.
Phishing remains far and away the most common form, affecting 38% of businesses. More striking, the proportion of businesses experiencing only phishing — no other type of breach at all — has risen to 51%. For most organisations, phishing is not one risk among several. It is the risk.
Set against that, one figure stands out. Just 19% of businesses carried out any staff training or awareness activity. Among large businesses, the figure is 84%.
That gap is the whole argument. Large organisations, which have the most technical controls, still put the most effort into training their people — because they have learned where attacks actually succeed.
Why smaller businesses are now targeted
It was once reasonable to assume attackers were interested in large organisations. That stopped being true when the cost and skill required to run an attack collapsed. Phishing infrastructure is now rented by the month, and campaigns are indiscriminate rather than targeted.
There is a second driver: supply chains. Larger organisations increasingly understand that their weakest point may be a supplier, and they are pushing security requirements down to the businesses they buy from. Many of our clients first look seriously at this because a customer asked them to, not because they were attacked.
Would your team spot these?
Four situations taken from the kind of thing that actually lands in UK inboxes. Pick what you would do.
What actually works
Awareness training has a poor reputation, largely deserved. An annual hour-long module that everyone clicks through while doing something else changes nothing measurable.
What works looks different in four ways.
It is little and often. A few minutes regularly beats an hour annually, because recognition needs refreshing and attacks change. Knowledge decays; the interval matters more than the depth.
It is relevant to the job. Finance needs to recognise invoice redirection. HR needs to recognise fake CVs carrying malware. Everyone needs to recognise a credential-harvesting page. Generic content aimed at nobody in particular is ignored by everybody in particular.
It is tested, not just delivered. Simulated phishing shows you where the actual risk sits rather than who completed the module. The point is the measurement, not catching people out.
It is safe to fail. This is the one most often got wrong. If clicking a simulated phish leads to embarrassment, people stop reporting real ones — and an unreported real click is far more dangerous than a reported one. The response to the first person who admits a mistake sets the tone for everyone watching.
Beyond training: two rules worth writing down
Training reduces how often someone is fooled. Process determines whether it matters.
The first rule: any change to payment details is verified by phone, on a number you already held, before anything is paid. Not a number in the email.
The second: anyone can stop a payment without needing to justify it. Invoice fraud works on urgency and on people not wanting to appear obstructive. Removing the social cost of asking is free and unusually effective.
How we help with this
We deliver awareness programmes through usecure, which gives us a library of short, varied modules, role-relevant content, and phishing simulation with reporting that shows where the genuine gaps are. It runs automatically on a schedule rather than needing somebody to remember to send it.
The NCSC also publishes free resources that are genuinely good, and for a very small business they may be enough on their own. We would rather tell you that than sell you something you do not need.
If you would like to know how your team would actually perform, a baseline phishing simulation is a quick piece of work and the results are usually clarifying. It tends to be a more persuasive argument than any statistic.
Figures from the UK government’s Cyber Security Breaches Survey 2025/26.





