Skip to main content

Security Awareness Training That Changes Behaviour, Not Just Completion Rates

Media Security Awareness Training That Changes Behaviour, Not Just Completion Rates

Most security awareness programmes can prove that employees completed a course.

Far fewer can prove that employees behave more securely afterwards.

A company may report a 98% training completion rate while staff still approve unexpected multifactor authentication prompts, reuse passwords, share sensitive files incorrectly or trust urgent payment requests received by email.

Completion matters, but it is only the beginning.

Effective security awareness training should change what people do when they encounter a real threat. Employees should recognise warning signs, pause before acting and know exactly how to report concerns.

The goal is not to turn every employee into a cybersecurity expert.

It is to make safer behaviour easier, faster and more natural than the risky alternative.

Why Completion Rates Can Be Misleading

Completion rates are easy to measure.

They show:

  • Who received the training
  • Who opened the course
  • Who finished it
  • Who passed the quiz
  • Who missed the deadline

Those figures are useful for administration and compliance, but they do not tell you whether employees can apply the lessons under pressure.

A person may correctly answer a question about phishing and then click a convincing link two weeks later. Another employee may recognise a suspicious message but stay silent because reporting it feels complicated or embarrassing.

A stronger awareness programme measures behaviour such as:

  • Whether suspicious emails are reported
  • How quickly incidents are reported
  • Whether staff verify unusual payment requests
  • Whether unexpected MFA prompts are rejected
  • Whether sensitive information is shared correctly
  • Whether employees know who to contact
  • Whether repeat mistakes reduce over time

Training should create visible improvements in those areas.

Start With the Risks Your Employees Actually Face

Generic training often covers everything from social-media privacy to advanced malware.

Employees remember very little because most of it feels unrelated to their daily work.

Begin with the threats that are most relevant to your organisation.

For many small and medium-sized businesses, these include:

  • Phishing emails
  • Business email compromise
  • Fake invoice and bank-detail changes
  • Password theft
  • MFA fatigue attacks
  • QR-code phishing
  • Malicious file-sharing links
  • Impersonation through Microsoft Teams
  • Unsafe use of AI and cloud applications
  • Accidental data sharing
  • Lost or stolen devices

Different teams face different risks.

Finance employees need strong payment-verification habits. HR staff handle sensitive personal information. Administrators need training on privileged access and consent attacks. Executives are frequently impersonated and targeted with urgent requests.

A relevant programme feels less like an annual lecture and more like practical job training.

Teach Specific Actions

“Be careful online” is not useful guidance.

Employees need clear actions they can remember during a real incident.

For example:

Suspicious email

  • Do not click the link.
  • Do not reply.
  • Use the company reporting button.
  • Contact the sender through a known channel if the request may be genuine.

Unexpected MFA prompt

  • Select deny.
  • Change the password if credentials may have been entered elsewhere.
  • Report the prompt immediately.
  • Do not keep approving requests to make the notification disappear.

Bank-detail change

  • Do not rely on the email thread.
  • Call the supplier using a previously verified telephone number.
  • Require a second person to approve the change.
  • Record the verification.

Lost company device

  • Report it immediately.
  • Provide the approximate time and location.
  • Do not wait until the next working day.
  • Let IT lock, wipe or retire the device where possible.

Training becomes useful when employees leave knowing exactly what to do next.

Use Short, Frequent Training

A single annual course asks employees to remember information for the next twelve months.

That is unrealistic.

Short, recurring training is usually more effective because it reinforces key behaviours throughout the year.

A practical programme might include:

  • A short onboarding session
  • Monthly five-minute lessons
  • Quarterly phishing simulations
  • Brief alerts after relevant threats
  • Targeted refreshers for high-risk teams
  • Annual incident-response exercises

One month might focus on payment fraud. The next might cover MFA prompts. Another might explain how attackers use Microsoft Teams or QR codes.

Frequent training also lets the programme respond to new attack techniques without waiting for the next annual cycle.

Make Training Look Like Real Work

Security threats rarely arrive as badly written messages with an obvious warning banner.

Training examples should reflect the situations employees actually encounter:

  • A supplier asks for new bank details.
  • A director requests an urgent confidential payment.
  • A Microsoft 365 file-sharing notification appears genuine.
  • A Teams message arrives from an external user.
  • A QR code claims to open a secure document.
  • A help-desk caller asks the employee to approve an MFA prompt.
  • A free AI tool requests access to company files.

Use your organisation’s systems, terminology and working practices where appropriate.

A realistic example is more memorable than a generic slide showing a cartoon hacker in a hoodie.

Use Phishing Simulations Carefully

Phishing simulations can help measure behaviour and provide practice, but they can also damage trust when handled badly.

A useful simulation should:

  • Reflect realistic threats
  • Avoid humiliating employees
  • Provide immediate education
  • Measure reporting as well as clicking
  • Become more targeted gradually
  • Protect sensitive personal circumstances
  • Support improvement rather than punishment

Avoid scenarios involving serious personal distress, such as fake medical results or redundancy notices. A simulation should challenge judgement without manipulating employees cruelly.

When someone clicks, show a short explanation:

  • Which warning signs were present
  • What action should have been taken
  • How to report similar messages
  • Where to get help

The exercise should leave the employee better prepared—not merely embarrassed.

Measure Reporting, Not Just Failure

A falling click rate can be encouraging, but it is not the only measure that matters.

Employees may avoid clicking simulated emails while ignoring real threats or deleting them without telling anyone.

Measure positive behaviour too:

  • Percentage of simulated phishing messages reported
  • Time between delivery and first report
  • Number of genuine suspicious emails reported
  • Percentage of users who follow the correct process
  • Reduction in repeat mistakes
  • Number of early reports that prevented an incident

A single fast report can protect the whole organisation by allowing IT to remove the message, block the sender and warn other users.

Reporting should be treated as a security success.

Make Reporting Easy

Employees will not report suspicious activity if the process is difficult.

Provide simple routes such as:

  • A Report Phishing button in Outlook
  • A dedicated telephone number
  • A clear service-desk option
  • A Teams channel monitored by IT
  • A short emergency process outside normal hours

Do not require employees to:

  • Export message headers
  • Complete a long form
  • Decide whether the email is definitely malicious
  • Find the correct security administrator
  • Wait until they have gathered evidence

Their role is to report suspicion. The investigation belongs to the security or IT team.

Always acknowledge the report. A short response encourages the employee to report again in future.

Remove the Fear of Getting It Wrong

Employees may stay silent because they worry about wasting IT’s time.

They may also delay reporting after clicking something because they fear blame or disciplinary action.

The training programme should make two points clear:

Reporting something harmless is better than ignoring something dangerous.

And:

Reporting a mistake quickly gives the company the best chance to contain it.

This does not mean removing accountability for deliberate misconduct. It means creating an environment where honest mistakes are reported before they become major incidents.

Early reporting often matters more than the original click.

Train Managers and Executives

Security awareness cannot be a rule imposed on junior employees while senior leaders ignore it.

Managers and executives should participate visibly.

They should understand:

  • Why urgent requests are frequently impersonated
  • Why finance staff must verify payment instructions
  • Why they should not pressure employees to bypass controls
  • How to report suspicious activity
  • What happens during a cyber incident
  • Why security exceptions need formal approval

A finance employee is less likely to challenge a strange payment request when senior management regularly treats security checks as an inconvenience.

Leadership behaviour sets the real security culture.

Provide Role-Based Training

The core programme should apply to everyone, but some roles need additional content.

Finance

Focus on:

  • Invoice fraud
  • Bank-detail changes
  • Executive impersonation
  • Payment approval
  • Out-of-band verification

HR

Focus on:

  • Personal data
  • Fake employee requests
  • Payroll changes
  • Confidential file sharing
  • Recruitment fraud

IT administrators

Focus on:

  • Privileged accounts
  • OAuth consent
  • Conditional Access
  • Emergency access
  • Malicious application registrations

Executives

Focus on:

  • Targeted phishing
  • Travel-related risk
  • Impersonation
  • Confidential transactions
  • Incident communications

Customer-facing teams

Focus on:

  • Identity verification
  • Fraudulent customer requests
  • Secure document exchange
  • Escalation procedures

Role-based training keeps the content relevant and reduces unnecessary noise.

Fix the Systems Around the User

Training should not be used to compensate for weak technical controls.

Employees will make mistakes. Security should limit the consequences.

Support awareness with controls such as:

  • Multifactor authentication
  • Phishing-resistant authentication for high-risk users
  • Email filtering
  • Safe Links and Safe Attachments
  • External sender identification
  • Automatic external-forwarding blocks
  • Conditional Access
  • Device compliance
  • Data Loss Prevention
  • Easy phishing reporting
  • Restricted application consent

If a process routinely invites mistakes, improve the process.

For example, telling users not to share sensitive data incorrectly is less effective when every sharing link defaults to organisation-wide access.

Good training and good technical design reinforce each other.

Use Real Incidents as Learning Opportunities

After an incident or near miss, provide a short anonymised lesson.

Explain:

  • What happened
  • Which warning signs appeared
  • What action helped
  • What could have reduced the impact
  • What employees should do next time

For example:

A supplier email account was compromised, and fraudulent bank details were inserted into an existing conversation. The request appeared genuine because it came from the supplier’s real address. Future bank-detail changes must be verified by telephone using a previously stored number.

This is more memorable than a theoretical fraud example because employees understand that the risk is real.

Remove unnecessary personal details and avoid turning the incident into public blame.

Track Behaviour Over Time

Choose a small set of meaningful measures.

These might include:

  • Training completion
  • Phishing simulation reporting rate
  • Phishing simulation click rate
  • Average reporting time
  • Number of genuine reports
  • Repeat failure rate
  • MFA-related incidents
  • Payment-verification compliance
  • Data-sharing incidents
  • Help-desk feedback

Look for trends rather than judging one monthly result.

A temporary increase in suspicious-email reports may be a positive sign because employees are becoming more confident about speaking up.

Metrics should guide improvements, not create a league table designed to shame departments.

A Practical Awareness Programme

Month 1: Establish the baseline

  • Review recent incidents.
  • Identify high-risk roles.
  • Run an initial simulation.
  • Measure reporting routes and response times.

Month 2: Improve reporting

  • Deploy or promote the phishing-report button.
  • Explain what employees should report.
  • Confirm every report receives acknowledgement.

Month 3: Focus on payment fraud

  • Train finance and managers.
  • Introduce telephone verification.
  • Review payment-change procedures.

Month 4: Cover identity attacks

  • Explain MFA fatigue and token theft.
  • Review password and passkey guidance.
  • Test unexpected authentication prompts.

Month 5: Address data handling

  • Review SharePoint and OneDrive sharing.
  • Explain sensitivity labels.
  • Cover AI and unapproved cloud applications.

Month 6: Test the programme

  • Run a realistic tabletop exercise.
  • Review behavioural metrics.
  • Update weak processes.
  • Set the next six-month plan.

This creates a continuous programme without overwhelming employees.

Common Awareness Training Mistakes

Treating Completion as Success

Finishing a course does not prove safer behaviour.

Delivering the Same Training to Everyone

Different roles face different threats.

Sending Training Only Once a Year

Employees forget the content long before the next course.

Punishing Simulation Failures

People become defensive and stop reporting mistakes.

Measuring Clicks but Ignoring Reports

The programme overlooks its strongest positive behaviour.

Using Training Instead of Technical Controls

Users remain the only barrier between the attacker and company data.

Making Reporting Difficult

Suspicious activity goes unreported until the damage is obvious.

Final Thoughts

Security awareness training should change what employees do when something feels wrong.

That means moving beyond completion percentages and quiz scores.

Teach clear actions. Use realistic examples. Reinforce the message frequently. Make reporting effortless and reward early reporting. Give high-risk teams relevant additional training and ensure managers follow the same rules as everyone else.

Then measure behaviour:

  • Are people reporting more quickly?
  • Are they verifying unusual requests?
  • Are repeat mistakes falling?
  • Are incidents being contained earlier?

The best programme does not create employees who can recite cybersecurity definitions.

It creates employees who pause, verify and report when it matters.

Need Security Awareness Training That Produces Real Results?

Hamilton Group can help your organisation build a practical security awareness programme focused on safer behaviour rather than box-ticking.

Our experts can help you:

  • Assess your organisation’s main human risks
  • Create role-based training
  • Run realistic phishing simulations
  • Improve suspicious-email reporting
  • Train finance teams against payment fraud
  • Educate users about MFA and identity attacks
  • Build incident-reporting procedures
  • Measure behavioural improvements
  • Run cybersecurity tabletop exercises
  • Combine user training with Microsoft 365 security controls

Visit hgmssp.com, call Hamilton Group on 0330 043 0069, or book a meeting with one of our experts to build security awareness training your employees will remember and use.