What a good programme covers
Recognising phishing and spear phishing, verifying payment and access requests through a second channel to stop BEC, using a password manager and MFA, handling sensitive data, using AI tools safely, physical security and, above all, how and when to report something suspicious.
Phishing simulations
Simulated phishing emails show who clicks, who enters credentials and, most importantly, who reports. Used well, they are a learning tool with immediate feedback, not a way to catch people out. The reporting rate is often a better indicator than the click rate.
Making it stick
Short, frequent sessions work better than a long yearly course. Content adapted to each role (finance, IT administrators, executives, new joiners) is more relevant, and real examples from the company's own sector make it credible. Results should be tracked and reported to management.
Where it shows up in compliance
ISO 27001 requires information security awareness, education and training (Annex A 6.3), and the ENS and NIS2 include equivalent obligations. NIS2 also requires members of management bodies to receive cybersecurity training. Our article on security awareness under ISO 27001 explains what auditors look for.




