Almost every serious incident in a small business starts with a person. Not because people are careless, but because a convincing message arrived at a busy moment and doing the sensible thing took thirty seconds nobody had.
The standard response is annual security awareness training. It does not work, and it is worth being precise about why.
Why annual training fails
Three reasons.
It is forgotten. An hour in March has no measurable effect in September, and the incidents do not schedule themselves around your training calendar.
It teaches the wrong thing. Recognising an obviously fake message in a slide deck bears no relation to spotting a plausible one in your inbox while on a call. Real phishing is well written, contextually appropriate and arrives from a compromised account of somebody you know.
It is framed as compliance. People complete it to have completed it. Nobody has ever changed a habit because a progress bar reached one hundred per cent.
What works instead
Short and frequent
Five minutes a month beats an hour a year. One realistic example, what the giveaway was, what to do. That is enough, and the frequency is what builds the reflex.
Simulations that are actually realistic
Run simulations monthly or every six weeks, and make them convincing. A phishing test that everybody spots teaches nothing except that phishing tests are easy.
The ones that work reference real context: a supplier your business uses, an internal process, a delivery, something plausible for the time of year. Vary the difficulty so people cannot pattern-match on the tests themselves.
Measure reporting, not clicking
This is the most important change most businesses can make.
Click rate is the obvious measure and it is the wrong one, because it can be driven down by fear — and fear suppresses reporting, which makes you less safe rather than more.
Reporting rate is the number that matters. A team that reports a suspicious message within minutes gives you the chance to remove it from every other inbox before somebody else acts on it. That is the actual defensive value.
Make reporting one click. In Microsoft 365 that is the built-in report button, which alerts your administrators and helps train the filtering.
Track the time from the first person receiving a phishing message to the first person reporting it. Getting that number down is worth more than any click-rate target.
Remove blame entirely
Somebody will click something eventually. The question is whether you find out in ten minutes or in ten days, and that depends entirely on whether reporting feels safe.
Say explicitly, in writing, that reporting a mistake promptly will never be treated as a disciplinary matter. Then honour it without exception. One punished self-report and you will never hear about the next one, which is precisely the situation where you needed to.
Better still, thank people publicly for reporting — including for false alarms. A team that over-reports is a team that is paying attention.
The four checks worth teaching
Not a list of twelve indicators. Four questions, memorable enough to use under pressure.
- Was I expecting this? Unexpected invoices, unexpected password resets, unexpected file shares.
- Is this normal for this person? Does your director usually ask for anything by text? Does that supplier usually attach a document with no message?
- Is it rushing me or asking me to keep it quiet? Urgency and secrecy are the two levers in almost every social engineering attempt, and they appear together.
- Where does the link actually go? Hover, read and be suspicious of anything asking you to sign in.
Plus one absolute rule with no exceptions: any request to change bank details or move money is verified by phone, on a number you already had. Not the number in the email. Invoice redirection fraud is the attack that costs UK small businesses the most money and this single rule prevents it.
The technical half
Training reduces the number of messages people have to judge. It does not replace the controls that stop most of them arriving.
- Multi-factor authentication everywhere, so a harvested password is not enough.
- Safe Links and Safe Attachments on Business Premium, which check links at click time rather than only on arrival.
- External sender warnings so a message claiming to be internal is visibly not.
- Blocked external auto-forwarding, which removes the attacker's usual next step. This and the rest are in the security settings checklist.
- SPF, DKIM and DMARC at reject, so nobody can convincingly spoof your own domain. The mechanics are in this article.
A programme that fits a small business
- Monthly: a five-minute example, and a simulation.
- Quarterly: a fifteen-minute session covering what has been reported and what changed.
- On joining: the four checks and the money rule, in the induction.
- Always: reporting is one click, thanked, never punished.
That is under an hour per person per year of actual time, spread so it sticks.
Our security solutions service includes simulation and training programmes for UK businesses alongside the technical controls, because neither half works properly on its own. Get in touch.








