Start with a measurement rather than a lecture: run a simulated phishing message and see how many people clicked the link and how many reported it. Then write one page of rules, run fifteen-minute sessions for each role, and measure again a quarter later. That gives the training a number that shows whether it works.
Key takeaways
The first cycle fits into three months and needs neither a separate budget nor a platform. Its job is not to “train everyone” but to get a baseline and close the most expensive scenarios.
The owner should be a manager who can gather people and insist on regularity, not the system administrator. The technical settings stay with IT.
Attacking a person needs no vulnerability and no way past the defences: a convincing message and a reason to hurry are enough. That is why phishing remains the most common type of fraud, and its sequel — forged business correspondence — the most expensive.
Put those numbers side by side and the case for training becomes clear. Direct losses from phishing itself are modest — around $216M across almost two hundred thousand complaints in the 2025 FBI report. What follows it is expensive: forged business correspondence and payments made “on the director's instruction” took fourteen times more.
Hence the priority: train first the people who handle money and outside correspondence — accounting, sales, procurement, executives and their assistants. The IT team needs its own, deeper programme.
Phishing means messages disguised as genuine ones: a bank, the tax office, a colleague, a manager, a marketplace. The goal is always the same — make you click a link, open a file or type in credentials. The tells are almost always identical.
One rule closes most scenarios: any unusual request about money, passwords or access is verified through an independent channel — a call to a known number, not a reply to the message. The mail domain settings that make it harder to forge messages from your company are covered in the article on designing information protection.
Tactics change faster than training materials get updated. Scenarios that older leaflets never described have joined the classic email, and the team needs to hear about them separately.
AI-generated voice messages and calls. In an advisory dated 19 December 2025 the FBI describes a scheme in which attackers send text and voice messages in the name of known figures, quickly move the conversation to an encrypted messenger, and then ask for a confirmation code, copies of documents or a money transfer. The tells match those of a phishing email: haste, a change of channel, a request for a code.
QR phishing. A code in a message or on a slip of paper moves the victim to a phone, where corporate defences are absent and the address bar is harder to read. According to Microsoft, in the first quarter of 2026 the volume of such attacks rose from 7.6M in January to 18.7M in March.
Stolen and guessed credentials remain one of the main ways in: in the Verizon DBIR 2026 credential abuse is the initial vector in 13% of breaches, right behind exploitation of vulnerabilities. A separate lecture about “strong passwords” does not solve this; tools and rules do.
A password manager also solves half of the training problem: it will not fill a saved password into a fake site because the address does not match. An employee does not have to be an expert to notice the substitution.
The same programme for everyone does not work: an accountant and a developer face different risks and different scenarios. A reasonable minimum is four roles and different session frequencies.
| Role | Main risks | Topics | How often |
|---|---|---|---|
| Accounting and finance | Forged invoices, changed payment details, an “urgent payment from the director” | Verifying payments through a second channel, tells of forged messages, what to do when in doubt | Quarterly |
| Sales and customer service | Phishing from marketplaces and messengers, database exports, attachments from “customers” | Handling attachments and links, rules for exporting data, what to do with a suspicious order | Quarterly |
| Executives and assistants | Impersonation, deepfakes, access requests made in management's name | Verifying who you are talking to, changes of channel, what must never be confirmed in chat | Twice a year |
| IT and development | Administrator access, keys and tokens in code, the supply chain | Secure development, storing secrets, incident response, permission reviews | Twice a year, plus a review after every incident |
New hires take the basic part in their first week. That item is the easiest to forget and the most expensive to lose: a person without the rules is dangerous not because they are careless but because they do not know who to tell.
A simulated phishing message is one you send to your own employees to measure the response. The tool is useful, but handled carelessly it damages trust inside the team and creates a new risk of its own.
The law points the same way: article 19 of the Law on Personal Data No. ZRU-547 requires the volume and nature of processed data to match the purpose of processing. For a training exercise the purpose is to measure the response, and the typed password is not needed for that.
Important If someone has already clicked or entered a password, they must say so within minutes: change the password, disconnect the device from the network and notify the person responsible. Speed matters more than blame — where incidents are punished, people simply stop reporting them.
Training is measured by behaviour during an attack, not by the number of hours delivered. Four or five numbers, counted the same way quarter after quarter, are enough.
The approach in which training is run as a continuous programme with roles, a plan and an assessment of results is described in NIST SP 800-50 Rev. 1. A single annual lecture does not fit that description: the skill of spotting attacks fades without practice, and the tactics change every few months.
The results are not a grade for people but an input to the risk register: where exactly training fails to close a scenario and which technical measure has to be added. Raising the report rate without technical changes eventually stalls.
How to turn such observations into priorities and deadlines is covered in the article on information security risks, and what to do when a leak has already happened is in the piece on personal data breaches. Roles, policy and the cadence of sessions are usually fixed in the documents of a management system: that is covered in the article on building an ISMS.
We do not sell “employee training” or “phishing simulations” as a separate service with its own price. Training is part of the work on protecting data and access from $4,000, together with sorting out permissions, encryption, protecting mail against spoofing and phishing, backups and incident procedures.
If it is not clear where to begin, the sensible first step is an information security audit from $1,200. It shows who holds which access, what happens when an employee leaves and which attack scenarios are realistic for your company; the training programme is built from that. Watching events and responding under an agreed procedure runs from $800 a month. The full scope is on the cybersecurity for business page.
We do not resell a simulation platform and we do not treat training as a substitute for technical protection. The two work together: a second factor lowers the cost of a mistake, and a trained employee shortens the time until someone raises the alarm.
Let’s discuss your project
Tell us what you need, and we will estimate the timeline and cost and suggest a solution.
Once a year isn't enough: the skill fades without practice, and attackers' methods change every few months. Finance and sales need quarterly sessions, managers with assistants and IT twice a year, and newcomers a basic session in their first week.
Everyone, but differently. Social engineering usually targets not IT specialists but accounting, sales, procurement and executive assistants: they have access to money and to outside correspondence. The IT team needs its own programme: administrator access, storing keys, incident response.
Tell the responsible person within minutes, change the password and disconnect the device from the network. After that you check login logs, mail forwarding rules and active sessions. Speed matters more than blame: the earlier an incident is known, the smaller the damage.
Get written sign-off from management, warn the team in advance that such checks happen, and never collect real passwords: Article 19 of Law ZRU-547 requires the volume of data collected to match the purpose, and here the purpose is measuring the response. Results are compiled by department, with no list of names.
Not for the first cycle. A mailbox, a simple landing page and a table with two numbers — clicks and reports — will do. A platform pays off later, when there are many employees, several scenarios and a need for automatic reporting by department.
By the trend in four numbers from quarter to quarter: the click rate, the report rate, the time to the first report and the share of people who filled in the fake form. A rising report rate is a more reliable sign than a falling click rate.
We don't price training separately: it's part of the work on protecting data and access, from $4,000. If it's unclear where to start, begin with an information security audit from $1,200 — it shows the attack scenarios that are realistic for your company, and the training programme is built from those.
Sources