AwarenessPhishingSMEs

Cybersecurity awareness: why employees are your first line of defence (and your first weakness)

A firewall cannot protect you when an employee unwittingly hands over their credentials. Cybersecurity awareness is the only measure that addresses this attack vector. Here is how to make it effective.

Hakim Djelili8 min read

Your firewall is up to date. Your EDR is running. Your VPN is patched. Yet an employee clicked an email that looked like an HR notification, entered their credentials on a fake login page, and an attacker now has access to your email system.

This scenario is not unusual. It is the most common one.

Why it matters

What an attacker looks for first

74%

Of breaches

Involve human error as the initial vector

17 min

Median time

Between receipt of a phishing email and the first click

€3.4m

Average cost of a breach

For a European SME in 2025 (IBM Security)

An attacker seeking access to your information system has two options: find a technical vulnerability in your infrastructure or convince someone inside to open the door. The second option is faster, less risky and less expensive.

The techniques are well practised: an email impersonating your IT department, a fake Microsoft 365 notification, a text message from a supposed delivery company or a phone call from an “IT support employee”. These attacks require no advanced technical skills. They require an understanding of how people behave under pressure.

What to cover

The 5 habits an awareness programme must instil

Effective training is not simply a matter of explaining what phishing is. It creates automatic responses that kick in under stress, when an employee is in a hurry and an email appears urgent.

  • Recognise a phishing email: check the actual sender (not the displayed name), spot inconsistencies in the URL, never click a link without hovering over it to see the destination, and report rather than delete it.
  • Manage passwords: understand why reuse is the central problem, use a password manager and enable MFA on every business account without exception.
  • Identify vishing and smishing: attackers also call. An IT employee will never ask for your password over the phone. A delivery company will never ask for your credentials by text message.
  • Adopt safe everyday habits: lock your workstation when you step away, do not connect unknown USB drives, avoid public Wi-Fi networks without a VPN, and do not share your screen without checking what is visible.
  • Know what to do when it happens: who to notify about a suspicious email, what to do after clicking inadvertently, and how to respond if your account appears compromised. Prompt reporting changes the scale of the damage.

What actually works

Why annual training is not enough

Most companies run one awareness session a year, often as e-learning with a quiz at the end. Employees click through to the end, receive their certificate and forget 80% of the content within the next two weeks.

This is not unwillingness. It is cognitive psychology: behaviours are built through repetition in varied contexts, not through a single session.

  1. Month 1

    Baseline and first phishing simulation

    Measure the initial click rate before any training. This figure becomes your benchmark. On average, 30% to 40% of employees click a well-designed simulation.

  2. Months 1 to 3

    Short, focused modules

    Sessions lasting 5 to 10 minutes on specific topics: phishing, passwords and risky behaviour. Short enough to hold people's attention, frequent enough to build habits.

  3. Month 3

    Second simulation campaign

    The same exercise with a different scenario. Measure the change in click rate. Most organisations see a 40% to 60% decrease after 3 months in the programme.

  4. Month 6 and beyond

    Reinforcement and emerging threats

    Attack techniques evolve. An awareness programme must keep pace with new forms of phishing, including voice deepfakes, malicious QR codes and phishing through Teams or Slack.

Measure the impact

The metrics that matter

An awareness programme without measurement is a budget without a return. Track these metrics:

  • Click rate in phishing simulations: the primary measure of progress. It should fall from one campaign to the next. A residual rate of 5% to 8% is considered acceptable in mature organisations.
  • Reporting rate: employees who report a suspicious email rather than ignoring it or clicking it. A good programme raises this rate as much as it lowers the click rate.
  • Module completion rate: simple, but a useful indicator of uptake. A rate below 80% points to a problem with engagement or format.
  • Security incidents involving the human factor: the true long-term metric. An effective programme reduces the number of incidents caused by human error.

Our offer

The Cyber Expert cybersecurity awareness programme

Cyber Expert offers an awareness programme designed for SMEs and mid-sized companies without a dedicated IT department. No software to install, no train-the-trainer course and no maintenance.

The subscription includes:

  • A library of short modules (5 to 10 minutes) covering phishing, passwords, vishing, risky behaviour and incident response.
  • Scheduled phishing simulation campaigns, with scenarios updated regularly to reflect current attacks.
  • A monitoring dashboard for each employee and team: completion rate, click rate and progress over time.
  • Monthly reports for management: overall progress, at-risk teams and recommendations.
  • Continuous updates: new modules as threats evolve, including deepfakes, Teams phishing and malicious QR codes.

Ready to begin? View the cybersecurity awareness plans or contact us for a 20-minute conversation.

Need a second opinion?

Let's talk for 30 minutes — no commitment

A direct conversation with a senior consultant to frame your cybersecurity priorities and clarify your obligations.

Book a call