Most security awareness training is theatre. An hour-long video once a year, a quiz everyone clicks through, a completion certificate for the compliance file, and no measurable change in behaviour. It satisfies an auditor and protects nobody.
Here is what the effective version looks like, and why the metric almost everyone tracks is the wrong one.
Why people are the target
Your technical controls have improved considerably. Endpoint protection is genuinely good now, cloud platforms enforce sensible defaults, and patching is largely automatable. So attackers went around them.
The attacks that cost small businesses money mostly involve no malware at all:
- Business email compromise — an attacker in a real mailbox, watching a genuine invoice thread, who sends updated bank details at exactly the right moment
- Credential phishing — a convincing Microsoft 365 login page that harvests the password and the MFA code in real time
- Invoice and vendor fraud — no technology compromise whatsoever, just a plausible request to a person with payment authority
- Help-desk social engineering — calling IT support as an executive to get a password reset
No endpoint agent fires on any of these, because nothing malicious runs. The only control in the path is a person deciding something feels wrong.
The metric almost everyone gets wrong
Most programmes are judged on click rate — what percentage of staff clicked the simulated phish. It is the wrong headline number, and optimising for it actively causes harm.
Track time-to-report instead.
Consider two employees. One clicks a phishing link, realises immediately, and tells IT within two minutes. The other clicks nothing, notices a colleague acting strangely, and says nothing. The first is the outcome you want. Click-rate scoring records them as failure and success respectively.
This matters because the damage from most incidents is a function of how long the attacker goes unnoticed. A reported click is a contained incident. An unreported one is a breach discovered in six weeks by a customer.
Which leads to the rule that decides whether a programme works: reporting a mistake must be consequence-free, visibly and consistently. The moment someone is embarrassed in a company meeting for failing a simulation, you have trained everyone to stay quiet. Punitive programmes produce excellent click-rate numbers and worse security.
What effective training looks like
Short and recurring. Five to ten minutes monthly or quarterly. An annual hour is forgotten by February and describes techniques that have moved on.
Relevant to the actual job. Finance staff need invoice fraud and payment verification. Executives need impersonation, because they are impersonated. IT needs help-desk social engineering. Generic training is ignored because it is generic.
Simulated phishing, run honestly. Regular, varied and realistic — but announced as a programme. Staff should know simulations happen; they should not know which message is one. Simulations designed to be unfair — fake bonus announcements, fake layoff notices — generate resentment and teach people to distrust internal communications, which has its own cost.
A reporting button that works. One click, in the mail client, no judgement. And crucially, somebody must respond to reports. A report button that sends mail into a void trains people to stop using it within a month.
A verification process, not just awareness. The most valuable outcome is not a vigilant workforce, it is a rule: any change to payment details is confirmed by phone, on a number we already had, every time, regardless of who appears to be asking. That process stops invoice fraud even when the person is fooled. Awareness helps; process is what holds when awareness fails.
What it costs
Cheap, relative to everything else. Huntress publishes Managed security awareness training at $1.75 per learner per month at a 100-learner tier, with a 50-learner minimum for direct purchase. Delivered inside a managed security plan it is normally bundled rather than billed separately.
For a 25-person company that is roughly the price of a few coffees a month against a class of attack that routinely costs five or six figures in a single wire transfer. It is the highest return-per-dollar control available, which is why it is odd that it is so often the first thing cut.
Insurers have noticed. Many carriers now ask about documented recurring training on applications and renewals, alongside MFA and EDR. Per-person completion records are what satisfies the question — worth running through a platform that produces that reporting automatically rather than reconstructing it from memory at renewal.
A programme that fits a small business
If you are starting from nothing:
- Turn on MFA first. Training is not a substitute for the control that makes stolen passwords useless.
- Write the payment-verification rule, put it in writing, and tell every person with payment authority that following it will never be questioned — even when the request appears to come from the owner.
- Deploy a one-click report button and commit to responding to every report the same day.
- Run short monthly training, role-relevant where you can.
- Start simulations after two months of training, not before. Testing people on material they have not been given is just a trap.
- Report on time-to-report, not click rate. Share the improvement with the team.
That programme takes very little management time once running, and it addresses the attacks most likely to actually cost you money.
Where training will not save you
Be realistic about the ceiling. Sufficiently good attacks fool competent, trained, attentive people — a real compromised mailbox, a real invoice thread, correct context, correct timing. Nobody spots that reliably every time.
So training is a layer, not a strategy. It sits alongside MFA, managed EDR with 24/7 response, email filtering and tested backups. The point of layers is that each one only has to catch what the others missed.
We run security awareness training as part of our managed cybersecurity plan — recurring short training, realistic phishing simulations, per-person reporting for your insurer, and a report button that reaches a real SOC. It bundles with managed EDR, email protection and managed IT. Start with a free security assessment.

Houston IT Developers
Houston IT Developers is a leading software development and digital marketing agency based in Houston, Texas. We specialize in web development, mobile apps, and digital solutions.
View all posts →Need Help With Your Project?
Our team of experts is ready to help you build your next web or mobile application. Get a free consultation today.
Get in Touch


