Support desk — Monday to Friday, 08:30 to 17:30Client AreaGet help now →

How Do I Increase Staff Cyber Awareness?

Every technical control you buy sits behind the same final safeguard: somebody deciding whether to click. That makes staff awareness the best return on any security spending most businesses can make — and the one most consistently skipped.

The numbers, as they currently stand

The government’s Cyber Security Breaches Survey for 2025/26 found that 43% of UK businesses identified a breach or attack in the previous twelve months, around 612,000 organisations. The rate rises with size: 46% of small businesses and 65% of medium-sized businesses.

Phishing remains far and away the most common form, affecting 38% of businesses. More striking, the proportion of businesses experiencing only phishing — no other type of breach at all — has risen to 51%. For most organisations, phishing is not one risk among several. It is the risk.

Set against that, one figure stands out. Just 19% of businesses carried out any staff training or awareness activity. Among large businesses, the figure is 84%.

That gap is the whole argument. Large organisations, which have the most technical controls, still put the most effort into training their people — because they have learned where attacks actually succeed.

Why smaller businesses are now targeted

It was once reasonable to assume attackers were interested in large organisations. That stopped being true when the cost and skill required to run an attack collapsed. Phishing infrastructure is now rented by the month, and campaigns are indiscriminate rather than targeted.

There is a second driver: supply chains. Larger organisations increasingly understand that their weakest point may be a supplier, and they are pushing security requirements down to the businesses they buy from. Many of our clients first look seriously at this because a customer asked them to, not because they were attacked.

Quick check

Would your team spot these?

Four situations taken from the kind of thing that actually lands in UK inboxes. Pick what you would do.

1. An email from your MD asks you to arrange a payment urgently. The address is right, the tone is right, and they are travelling. What is the giveaway you should check?
Business email compromise relies on a display name you recognise. The reply-to is frequently a lookalike domain or a free mail account, and it is visible in two clicks. The real control, though, is a rule that payment changes are verified by phone on a number you already had — never one supplied in the email.
2. A supplier emails to say their bank details have changed, with new details attached on headed paper. What now?
Headed paper is trivial to produce and replying to the email reaches whoever sent it. Invoice redirection fraud is one of the most costly attacks on UK SMEs, and the only reliable defence is an out-of-band check using contact details you already had.
3. Someone calls saying they are from your IT provider and need you to approve an MFA prompt they are about to send. What do you do?
A real provider will not phone to ask you to approve a prompt they triggered. This is a standard technique for defeating MFA, and it works because the call makes the prompt feel expected. Hanging up and calling back on a known number costs nothing and defeats it entirely.
4. A colleague reports that they clicked a link and entered their password, an hour ago. What is the most useful response?
The response to the first report determines whether you ever get a second one. Speed matters far more than the lesson — and the lesson lands better later. A culture where people hide mistakes is considerably more dangerous than one where people click things.
Score: 0 of 4

What actually works

Awareness training has a poor reputation, largely deserved. An annual hour-long module that everyone clicks through while doing something else changes nothing measurable.

What works looks different in four ways.

It is little and often. A few minutes regularly beats an hour annually, because recognition needs refreshing and attacks change. Knowledge decays; the interval matters more than the depth.

It is relevant to the job. Finance needs to recognise invoice redirection. HR needs to recognise fake CVs carrying malware. Everyone needs to recognise a credential-harvesting page. Generic content aimed at nobody in particular is ignored by everybody in particular.

It is tested, not just delivered. Simulated phishing shows you where the actual risk sits rather than who completed the module. The point is the measurement, not catching people out.

It is safe to fail. This is the one most often got wrong. If clicking a simulated phish leads to embarrassment, people stop reporting real ones — and an unreported real click is far more dangerous than a reported one. The response to the first person who admits a mistake sets the tone for everyone watching.

Beyond training: two rules worth writing down

Training reduces how often someone is fooled. Process determines whether it matters.

The first rule: any change to payment details is verified by phone, on a number you already held, before anything is paid. Not a number in the email.

The second: anyone can stop a payment without needing to justify it. Invoice fraud works on urgency and on people not wanting to appear obstructive. Removing the social cost of asking is free and unusually effective.

How we help with this

We deliver awareness programmes through usecure, which gives us a library of short, varied modules, role-relevant content, and phishing simulation with reporting that shows where the genuine gaps are. It runs automatically on a schedule rather than needing somebody to remember to send it.

The NCSC also publishes free resources that are genuinely good, and for a very small business they may be enough on their own. We would rather tell you that than sell you something you do not need.

If you would like to know how your team would actually perform, a baseline phishing simulation is a quick piece of work and the results are usually clarifying. It tends to be a more persuasive argument than any statistic.

Figures from the UK government’s Cyber Security Breaches Survey 2025/26.

Found this useful?

We write these because the same questions keep coming up. If one of them is yours, the answer is usually a short conversation away.

Keep reading