Syntra Systems
Cases Services Products About Blog IT Caravan
+998 70 010 68 44 +7 999 900 22 12
RusEngUzb
Silhouettes of people on lit steps with their reflection below — an image of a team learning to notice phishing
Security

Cybersecurity training for employees: where to start

By Nikita Zhulin · · 9 min read · updated

Start with a measurement rather than a lecture: run a simulated phishing message and see how many people clicked the link and how many reported it. Then write one page of rules, run fifteen-minute sessions for each role, and measure again a quarter later. That gives the training a number that shows whether it works.

Key takeaways

  • The first step is a measurement rather than a lecture: a simulated message shows how many people clicked the link and how many reported it.
  • Train first the people who handle money and outside correspondence: FBI figures for 2025 put company losses to business email compromise at $3.05B.
  • A simulated exercise is approved by management in writing, real passwords are never collected, and results are reported by department rather than by name.
  • The key metric is not the click rate but the report rate and the time until the first signal.
  • We do not price “training” or “phishing simulations” separately: training is part of protecting data and access from $4,000, and most companies start with an audit from $1,200.

Where to start: the first 90 days

The first cycle fits into three months and needs neither a separate budget nor a platform. Its job is not to “train everyone” but to get a baseline and close the most expensive scenarios.

  1. Agree it with management in writing: what you test, on whom, what happens to the results, and that nobody gets punished.
  2. Run the first simulated message across the company and record two numbers: the share who clicked and the share who reported it.
  3. Write one page of rules: what a suspicious message looks like, who to tell and how, what to do if you already clicked.
  4. Run short sessions by role: accounting and sales separately from IT, fifteen to twenty minutes, using real messages your company received.
  5. Turn on a second factor for mail, the CRM and remote access, and roll out a password manager — training without this runs idle.
  6. A month later repeat the exercise with a different scenario and compare the numbers.
  7. Add training to onboarding: a new hire gets the rules in the first week, not a year later.

The owner should be a manager who can gather people and insist on regularity, not the system administrator. The technical settings stay with IT.

Why people remain the main way in

Attacking a person needs no vulnerability and no way past the defences: a convincing message and a reason to hurry are enough. That is why phishing remains the most common type of fraud, and its sequel — forged business correspondence — the most expensive.

Put those numbers side by side and the case for training becomes clear. Direct losses from phishing itself are modest — around $216M across almost two hundred thousand complaints in the 2025 FBI report. What follows it is expensive: forged business correspondence and payments made “on the director's instruction” took fourteen times more.

Hence the priority: train first the people who handle money and outside correspondence — accounting, sales, procurement, executives and their assistants. The IT team needs its own, deeper programme.

Phishing: how to spot the message

Phishing means messages disguised as genuine ones: a bank, the tax office, a colleague, a manager, a marketplace. The goal is always the same — make you click a link, open a file or type in credentials. The tells are almost always identical.

One rule closes most scenarios: any unusual request about money, passwords or access is verified through an independent channel — a call to a known number, not a reply to the message. The mail domain settings that make it harder to forge messages from your company are covered in the article on designing information protection.

Newer tactics: deepfakes, QR codes and messengers

Tactics change faster than training materials get updated. Scenarios that older leaflets never described have joined the classic email, and the team needs to hear about them separately.

AI-generated voice messages and calls. In an advisory dated 19 December 2025 the FBI describes a scheme in which attackers send text and voice messages in the name of known figures, quickly move the conversation to an encrypted messenger, and then ask for a confirmation code, copies of documents or a money transfer. The tells match those of a phishing email: haste, a change of channel, a request for a code.

QR phishing. A code in a message or on a slip of paper moves the victim to a phone, where corporate defences are absent and the address bar is harder to read. According to Microsoft, in the first quarter of 2026 the volume of such attacks rose from 7.6M in January to 18.7M in March.

Passwords and the second factor

Stolen and guessed credentials remain one of the main ways in: in the Verizon DBIR 2026 credential abuse is the initial vector in 13% of breaches, right behind exploitation of vulnerabilities. A separate lecture about “strong passwords” does not solve this; tools and rules do.

A password manager also solves half of the training problem: it will not fill a saved password into a fake site because the address does not match. An employee does not have to be an expert to notice the substitution.

A programme by role: who is taught what

The same programme for everyone does not work: an accountant and a developer face different risks and different scenarios. A reasonable minimum is four roles and different session frequencies.

RoleMain risksTopicsHow often
Accounting and financeForged invoices, changed payment details, an “urgent payment from the director”Verifying payments through a second channel, tells of forged messages, what to do when in doubtQuarterly
Sales and customer servicePhishing from marketplaces and messengers, database exports, attachments from “customers”Handling attachments and links, rules for exporting data, what to do with a suspicious orderQuarterly
Executives and assistantsImpersonation, deepfakes, access requests made in management's nameVerifying who you are talking to, changes of channel, what must never be confirmed in chatTwice a year
IT and developmentAdministrator access, keys and tokens in code, the supply chainSecure development, storing secrets, incident response, permission reviewsTwice a year, plus a review after every incident

New hires take the basic part in their first week. That item is the easiest to forget and the most expensive to lose: a person without the rules is dangerous not because they are careless but because they do not know who to tell.

How to run a simulated phishing exercise without doing harm

A simulated phishing message is one you send to your own employees to measure the response. The tool is useful, but handled carelessly it damages trust inside the team and creates a new risk of its own.

  1. Get written approval from management: the goal, the scope, the timing, what happens to the results.
  2. Announce in advance that such checks will happen — but not when exactly.
  3. Do not collect real passwords: the fake form records the fact that something was typed, not the contents of the field.
  4. Report results as statistics by department, not as a list of names to be reviewed.
  5. Show a short explanation immediately after a click: what in the message gave it away.
  6. Vary the scenarios: the same story on a second run measures memory, not skill.

The law points the same way: article 19 of the Law on Personal Data No. ZRU-547 requires the volume and nature of processed data to match the purpose of processing. For a training exercise the purpose is to measure the response, and the typed password is not needed for that.

Important If someone has already clicked or entered a password, they must say so within minutes: change the password, disconnect the device from the network and notify the person responsible. Speed matters more than blame — where incidents are punished, people simply stop reporting them.

Which metrics show that training works

Training is measured by behaviour during an attack, not by the number of hours delivered. Four or five numbers, counted the same way quarter after quarter, are enough.

The approach in which training is run as a continuous programme with roles, a plan and an assessment of results is described in NIST SP 800-50 Rev. 1. A single annual lecture does not fit that description: the skill of spotting attacks fades without practice, and the tactics change every few months.

What to do with the results and where training hits its limit

The results are not a grade for people but an input to the risk register: where exactly training fails to close a scenario and which technical measure has to be added. Raising the report rate without technical changes eventually stalls.

How to turn such observations into priorities and deadlines is covered in the article on information security risks, and what to do when a leak has already happened is in the piece on personal data breaches. Roles, policy and the cadence of sessions are usually fixed in the documents of a management system: that is covered in the article on building an ISMS.

How we do it and what it costs

We do not sell “employee training” or “phishing simulations” as a separate service with its own price. Training is part of the work on protecting data and access from $4,000, together with sorting out permissions, encryption, protecting mail against spoofing and phishing, backups and incident procedures.

If it is not clear where to begin, the sensible first step is an information security audit from $1,200. It shows who holds which access, what happens when an employee leaves and which attack scenarios are realistic for your company; the training programme is built from that. Watching events and responding under an agreed procedure runs from $800 a month. The full scope is on the cybersecurity for business page.

We do not resell a simulation platform and we do not treat training as a substitute for technical protection. The two work together: a second factor lowers the cost of a mistake, and a trained employee shortens the time until someone raises the alarm.

Let’s discuss your project

Tell us what you need, and we will estimate the timeline and cost and suggest a solution.

Order a security audit

Frequently asked questions

Is one training session a year enough?

Once a year isn't enough: the skill fades without practice, and attackers' methods change every few months. Finance and sales need quarterly sessions, managers with assistants and IT twice a year, and newcomers a basic session in their first week.

Should everyone be trained, or only the IT department?

Everyone, but differently. Social engineering usually targets not IT specialists but accounting, sales, procurement and executive assistants: they have access to money and to outside correspondence. The IT team needs its own programme: administrator access, storing keys, incident response.

What should someone do if they have already clicked a phishing link?

Tell the responsible person within minutes, change the password and disconnect the device from the network. After that you check login logs, mail forwarding rules and active sessions. Speed matters more than blame: the earlier an incident is known, the smaller the damage.

How do we run a simulated phishing test without raising complaints?

Get written sign-off from management, warn the team in advance that such checks happen, and never collect real passwords: Article 19 of Law ZRU-547 requires the volume of data collected to match the purpose, and here the purpose is measuring the response. Results are compiled by department, with no list of names.

Do we need a paid platform for simulated exercises?

Not for the first cycle. A mailbox, a simple landing page and a table with two numbers — clicks and reports — will do. A platform pays off later, when there are many employees, several scenarios and a need for automatic reporting by department.

How do we know the training actually works?

By the trend in four numbers from quarter to quarter: the click rate, the report rate, the time to the first report and the share of people who filled in the fake form. A rising report rate is a more reliable sign than a falling click rate.

How much does employee training cost?

We don't price training separately: it's part of the work on protecting data and access, from $4,000. If it's unclear where to start, begin with an information security audit from $1,200 — it shows the attack scenarios that are realistic for your company, and the training programme is built from those.

Read also