Somewhere in your business, in the next few weeks, an email will arrive that is not what it claims to be: an invoice with new bank details, a Microsoft login prompt that is not Microsoft’s, a message from “the MD” needing something urgent doing quietly. Whether that email becomes nothing or becomes the worst quarter in your company’s history is decided in about four seconds, by whichever human happens to open it.
Every technical defence on this site (filters, EDR, MFA) exists because those four seconds sometimes go wrong, and phishing training exists to make them go wrong less often. The catch is that most phishing training does not work: an annual slideshow, a quiz, a certificate, and click rates unchanged. This page covers the version that does.
Why the slideshow version fails
Annual awareness training fails for a human reason, not a content one: recognising phishing is a reflex, not a fact. Facts survive a year between slideshows; reflexes decay in weeks without practice. Worse, slideshow training teaches yesterday’s phish (the misspelled Nigerian prince) while real attacks have moved on to pixel-perfect Microsoft login pages, supplier-invoice fraud that quotes real project details, and, in the legal sector’s hard-learned experience, payment redirection that arrives mid-transaction looking entirely routine.
Effective training has three components, run continuously: simulation, coaching, and culture.
Component 1: Simulated phishing
Realistic but harmless phishing emails, sent to your staff on an irregular schedule by your training platform. Clicks do no damage; they route the clicker to a short, immediate lesson: this is what you missed, this is where hovering would have shown the truth.
The design details that separate useful simulation from theatre:
- Realism that tracks real attacks: current lure types (login prompts, invoice changes, delivery notices, HR-themed messages), not museum pieces.
- Variety and irregular timing, so staff learn vigilance rather than “spot the monthly test”.
- Difficulty that ramps: early campaigns catch the easy clicks; later ones test against tailored lures of the kind actually aimed at businesses like yours.
- No name-and-shame. The report is aggregate (click rate by campaign, trend over time), and the individual experience is a private teachable moment. Simulation run as a gotcha exercise poisons the culture component below, and the culture component is worth more.
Component 2: Coaching in the moment
The click-then-learn loop is where the reflex actually forms: a two-minute lesson at the moment of the mistake outperforms an hour of theory six months prior. Supplemented by short, occasional refreshers (minutes, not mornings) and induction training for every new starter, because staff churn is how trained organisations quietly become untrained ones; sectors with seasonal or volunteer workforces need this wired into onboarding as standard.
Component 3: A report-first culture
The metric that predicts real-world outcomes best is not the click rate; it is the report rate: how many staff flagged the suspicious email, and how fast. One report gives your IT provider the thread to pull (quarantine the campaign from every mailbox, block the sender, warn the team) turning one person’s vigilance into everyone’s protection.
Building it takes two things. A one-click way to report (a button in Outlook, not a process document), and a response that rewards reporting: fast acknowledgement, zero blame, including (especially) when someone reports *after* clicking. The employee who clicked and reported within minutes just saved you from the employee who clicked and kept quiet for three days; treat them accordingly, in public if possible. This is the same blameless principle your incident response plan depends on, practised weekly at low stakes.
What to measure
Four numbers tell the story: click rate per campaign (expect early figures that alarm you; industry baselines commonly sit in double digits before training), report rate (the one to celebrate as it climbs), time-to-first-report (your real-world early-warning speed), and repeat-click patterns (which trigger extra coaching, not disciplinary theatre). Improvement is typically visible within two or three campaigns, and the trend line is exactly the evidence insurers and client questionnaires increasingly ask for when they probe “security awareness training”.
Where training fits (and its limits)
Honesty requires the caveat: training reduces clicks; it cannot zero them, which is why it sits inside layers rather than replacing them. MFA makes a harvested password useless; filtering thins the volume; EDR catches the payload that does land; and tested backups make even the worst case survivable. Training is the layer that makes every other layer’s job smaller, and it satisfies the security-awareness expectations in Cyber Essentials preparation and insurance questionnaires along the way.
As part of our managed security service, we run the whole loop: platform, campaigns tuned to your sector’s actual lures, the reporting button, and quarterly trend reports written for management rather than for auditors.
Frequently asked questions
How often should phishing training run?
Continuously: simulated campaigns on an irregular monthly-ish rhythm, instant coaching on clicks, short refreshers a few times a year, and induction training for every starter. Annual-only training measurably decays.
What is a good phishing click rate?
Untrained organisations commonly start with double-digit click rates on realistic simulations; sustained programmes typically drive this into low single digits. The report rate matters more: a rising report rate with falling clicks is the healthy signature.
Should employees be disciplined for failing phishing tests?
No, and doing so damages the metric that matters most: reporting. Repeat patterns get quiet extra coaching; the culture goal is staff who report instantly, including after their own mistakes, because hidden clicks are the expensive ones.
Do simulations annoy staff?
Badly run ones do (gotcha framing, name-and-shame, cruel lures like fake bonus announcements). Well-run programmes with private coaching and no-blame framing consistently land as professional development, and the first real phish someone catches tends to convert them permanently.
Does phishing training satisfy Cyber Essentials or insurers?
It contributes directly: security awareness features in certification preparation and appears by name in insurer questionnaires, and a documented programme with trend data is exactly the evidence they want. Training complements the technical controls; neither substitutes for the other.
What does phishing training cost?
Platform costs typically run a few pounds per user per month, and within our managed security arrangements the programme is included rather than an add-on. Set against phishing’s role as the leading entry route for ransomware and payment fraud, it is among the highest-return security spend available.
Find out your click rate before an attacker does
Every business has a click rate; most have simply never measured it. A baseline simulation is part of how we start security engagements, and the free IT health check will tell you where training fits among your other gaps. Get in touch; the four-second moments are coming either way.