If your business uses usecure, you will get a short security course every few weeks and, now and again, a practice phishing email that is not from anyone real. Neither is a test you can fail in any way that matters. Here is what to expect and how to get at it without hunting for a password you never had.
There is no password
This is the thing worth knowing first, because it is the commonest reason people give up. You do not have an account with a password. You get in by link.
- The training emails you are sent contain a link straight into the course.
- The invitation email has a Log In button in it.
- From a course you can click Go to Portal, which sits in the top right next to the language dropdown, and also appears when you finish a course.
- If you have lost all of those, you can go to the portal and enter your email address, and it will send you a fresh link.
There is a fixed web address for your organisation’s portal that works any time, rather than a one off link in an email. Ask whoever runs your IT for it and bookmark it. It saves digging through your inbox every time.
What the portal shows you
- Courses you still have outstanding, and the ones you have finished.
- How you have done on the practice phishing emails, including your average rate of being caught.
- Any policies still waiting for your signature.
- Any data breaches your email address has turned up in, with the date and how serious each one was.
That last one is worth looking at. It is not saying your work account has been hacked. It means your address appeared in somebody else’s breach, usually a website you signed up to years ago. If you used the same password there as anywhere that matters, change it.
The courses
Short, multiple choice, and there is a pass mark. If you do not pass, the course comes round again, which is the point rather than a punishment. The first thing you are sent is a longer questionnaire, ten to fifteen minutes, which works out which topics you personally need and sets the order of everything after it. It is worth doing properly rather than clicking through, because the rest of the programme is built on the answers.
The practice phishing emails
If a practice phishing email takes you to a sign in page and you type your password in, that password is not recorded. usecure state plainly that they do not collect or store anything typed into those pages. The system logs that somebody reached the page, and nothing else.
If you are caught by one, you will usually be sent a short piece of training there and then, and if it happens again it will be a slightly more advanced one. That is the whole consequence. There is no list being kept for your manager to read out.
What to do when you spot one
Report it, exactly as you would a real one. You will not be told off for reporting a practice email; reporting is the behaviour the whole exercise is trying to build, and a business where people report things is far safer than one where people merely avoid clicking. There is a separate guide on how to spot and report phishing.
Common questions
- I clicked one. Am I in trouble?
- No. A meaningful proportion of every organisation clicks, including the people who run these programmes. It is why the practice exists.
- I clicked something and now I am not sure it was a practice one.
- Then treat it as real and ring us on 03333 22 11 00 straight away. Ring rather than email. Nobody will be cross with you, and we would far rather hear about it now than next week.
- Can I do the training on my phone?
- Yes. The courses work in a phone browser.
- I keep getting reminders for a course I have done.
- Finish it right to the end rather than closing the tab at the last screen, which is the usual cause. If it still nags, tell us and we will look.
- I have left the courses too long.
- Just start. Nobody is keeping score in the way you are imagining.
If you get stuck
Call the service desk on 03333 22 11 00 or email support@easylifeit.com.
Take this guide with you
A clean branded copy you can print or save as a PDF, with our service desk details on every page.
Checked against usecure’s help centre, Help users understand their progress with the End User Portal, Accessing uLearn courses and How we track phishing simulations, September 2026. Some of what you see is set by your own organisation, so the wording of individual emails will vary.




