CONTACT

Do You Need Security Awareness Training?

security awareness training

This guide is for UK business leaders deciding whether to invest in security awareness training, or whether the annual course they already run is doing anything. It covers what the training should include, how often to run it, what the evidence says about whether it works, and what it costs per user.

Security awareness training teaches staff to recognise and report phishing, protect passwords and devices, and handle personal data safely. If you process personal data, the ICO expects initial and refresher training. But research shows an annual course on its own changes little, so short, frequent sessions backed by MFA and email filtering work better.

Security awareness training is regular instruction that teaches staff to recognise threats such as phishing and report them quickly. The NCSC says small, frequent sessions work better than an hour once a year. Training can’t stop every click, so pair it with MFA and email filtering.

What Is Security Awareness Training?

Security awareness training is instruction that helps staff recognise cyber threats, handle data safely and report problems early. The NCSC’s free Top Tips for Staff course sets a sensible baseline with four topics: using strong passwords, securing devices, defending against phishing and reporting incidents. It takes less than 30 minutes and needs no login.

Beyond that baseline, cyber security training for employees should follow the threats your staff actually see. Phishing was the most common attack in the government’s 2025/26 breaches survey, hitting 38% of businesses, and impersonation of the organisation or its staff hit 12% of all businesses and 47% of large ones. Give people a clear way to report, too: among large businesses, 94% have an agreed process for staff to follow when they identify a fraudulent email.

If you handle personal data, the ICO’s data security guidance adds your UK GDPR responsibilities, how to identify callers, the danger of people obtaining data by deception and any limits on personal use of your systems. The NCSC’s 10 Steps guidance says to work out the knowledge and behaviours each person needs before you build or buy anything. Give extra content to anyone who approves payments or holds admin rights.

Some programmes go further and score each person’s risk. Transputec, a Premier Mimecast Partner, includes Mimecast Awareness Training and Human Risk Management in every email security engagement it runs in the UK, scoring each user on behaviour such as clicks, reports and simulation results and targeting short training modules at the gaps.

Is Security Awareness Training a Requirement in the UK?

If you handle personal data, the regulator expects it. UK GDPR requires appropriate technical and organisational measures to keep personal data secure, and the ICO’s data security guidance says to give staff appropriate initial and refresher training. Cyber Essentials doesn’t require it. Even so, only 19% of UK businesses gave staff any cyber security training in the past year.

On Cyber Essentials specifically, the NCSC’s Requirements for IT Infrastructure v3.3 (April 2026) set five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. None of them is staff training. The only education point sits in the password guidance, which asks you to support users by educating them about avoiding common passwords. Our guide to the 5 Cyber Essentials controls covers the rest.

The government’s Cyber Security Breaches Survey 2025/26, published on 30 April 2026, shows how uneven take-up is. Just 14% of micro businesses ran training or awareness sessions in the previous 12 months, against 33% of small, 54% of medium and 84% of large businesses. Across all businesses the figure was flat at 19%, the same as the year before.

Planning Staff Training? Run It Alongside Email Security

Transputec delivers Mimecast Awareness Training and Human Risk Management as part of its Mimecast email security engagements, with phishing simulations and microlearning targeted by each user's risk score. Talk to our team about the security work behind your staff training.

Get a Strategic Consultation

Does Security Awareness Training Actually Work?

On its own, less than you’d hope. A UC San Diego study of 19,500 healthcare employees found no significant relationship between recently completing annual training and falling for phishing, and embedded training reduced the likelihood of clicking a phishing link by only 2%. The NCSC advises judging training by reporting as well as clicks.

The study ran for eight months and was presented at the IEEE Symposium on Security and Privacy in May 2025. Three in four users spent a minute or less on the embedded training material, and a third closed it straight away. In the first month, 10% of employees clicked a simulated phishing link. By the eighth month, more than half had clicked at least one. The researchers concluded that two-factor authentication and password managers that only work on the correct domains would give a better return.

The NCSC reaches a similar view. Its phishing guidance says no training package, including phishing simulations, can teach users to spot every phishing attempt. Its 10 Steps guidance warns that awareness is only the first step, because knowing about a risk doesn’t mean people will act on it. So training still earns its place. It gives people a way to report and meets the ICO’s expectation. It just can’t be the only control.

How Often Should Staff Do Security Awareness Training?

Little and often, starting when someone joins. The NCSC’s 10 Steps guidance says consistent small messages are more digestible and more effective than an hour-long session once a year, and the ICO expects initial and refresher training. In practice, that means an induction module, then short refreshers through the year.

The UC San Diego result points the same way: how recently someone had completed their annual course wasn’t linked to whether they clicked. The government’s breaches survey also found a split by size. Larger organisations tended to train staff continuously, while smaller ones mentioned initial training when people joined but said a lack of resource stopped them doing more.

A workable rhythm for staff cyber training looks like this:

  • At induction: the basics in someone’s first week, including how to report a suspicious email. The NCSC course fits here.
  • Through the year: short modules every month or quarter. Microsoft’s documentation for Attack simulation training uses monthly awareness training as its example of a training campaign.
  • When threats change: a quick update when a new lure appears. Microsoft, for example, ships built-in training modules on malicious digital and printed QR codes.
  • By role: extra content for people who approve payments, manage personal data or hold admin rights.

Should You Run Phishing Simulations?

Yes, as long as they’re used to teach reporting and nobody is punished for clicking. The NCSC warns that punishing people for clicking on emails you’ve sent starts to resemble entrapment, and that employees who are afraid for their jobs won’t report mistakes. It also says to check with HR before running any simulation.

The breaches survey found 22% of UK businesses tested staff with mock phishing exercises in the past year. If you’re one of them, two things matter. First, a click rate depends on how hard the test was. In the UC San Diego study, only 1.82% clicked a fake Outlook password update, but 30.8% clicked a fake update to the employer’s holiday policy. So track how many people report the email and how quickly they do it; the NCSC recommends focusing on reports as well as clicks. Second, base your lures on the threats you actually receive. Our explainer on phishing simulations covers how a campaign runs.

If you’re on Microsoft 365, check your licence before buying another tool. Attack simulation training needs Microsoft 365 E5 or Defender for Office 365 Plan 2. Business Premium and E3 include Plan 1, which doesn’t have it, although E3 customers get a limited trial. Transputec delivers Mimecast phishing simulations and awareness training for organisations that want the programme run alongside their email security.

How Much Does Security Awareness Training Cost Per User in the UK?

It can cost nothing. The NCSC’s Top Tips for Staff e-learning is free, needs no login and takes less than 30 minutes. Microsoft’s Attack simulation training comes with Defender for Office 365 Plan 2, which is £3.80 per user per month on Microsoft’s UK price list, paid yearly and before VAT, or inside Microsoft 365 E5.

The NCSC course is the cheapest phishing awareness training UK organisations can use, and the NCSC says it’s aimed mainly at SMEs, charities and the voluntary sector. That matters, because micro and small businesses were the least likely to train staff in the breaches survey, and some smaller organisations said budget limited how much training they could do.

OptionWhat you getUK cost per userSuits
NCSC Top Tips for StaffE-learning on passwords, devices, phishing and reporting, downloadable in SCORM formats for your own learning platformFreeA baseline for every organisation, including micro businesses
Microsoft 365 Business Premium or E3Defender for Office 365 Plan 1 email protection, with no Attack simulation training (E3 gets a limited trial)Already in the licenceProtecting inboxes, with training added separately
Defender for Office 365 Plan 2Attack simulation training, training-only campaigns and built-in modules, including QR code phishing£3.80 per month, paid yearly, before VATMicrosoft 365 tenants that want simulations run inside Microsoft
Microsoft 365 E5Defender for Office 365 Plan 2 includedIncluded in E5Organisations already licensed for E5
Mimecast Awareness Training via TransputecPhishing simulations, microlearning targeted by user risk score and dashboards showing behaviour change over timePart of the Mimecast email security engagementOrganisations that want training run alongside managed email security

Whichever option you pick, count staff time as part of the cost, and keep budget for the controls that catch what training misses.

What Else Stops Phishing If Training Doesn't?

Controls that still work after someone clicks. The NCSC’s phishing guidance sets out four layers: make it hard for attackers to reach your users, help users identify and report phishing, protect the organisation from phishing emails that succeed, and respond quickly to incidents. Training covers the second layer only.

  • Layer 1, filtering. Microsoft 365 Business Premium includes Defender for Office 365 Plan 1, with Safe Links, Safe Attachments and impersonation protection. Our Mimecast deployments add Email Security 360, including URL Protect, Attachment Protect and impersonation defence.
  • Layer 3, limiting the damage. Two-factor authentication means a stolen password isn’t enough on its own, yet only 47% of UK businesses have it in place. Our guide to Conditional Access in Microsoft 365 shows how to enforce MFA, and EDR records activity on each device so an attack that gets through can be traced and stopped, as our EDR vs XDR guide explains.
  • Layer 4, responding fast. Someone has to act when a report comes in or an account is compromised. Transputec’s MDR security services run 24/7/365 from a UK-staffed team, and our cyber incident response service puts Tier 3 analysts on a 24/7 hotline.

Your Security Awareness Training Checklist

Use this to check whether your programme is doing its job.

  1. Give every new starter a short induction module, including how to report a suspicious email.
  2. Run short refreshers through the year instead of one long annual session.
  3. Make cyber security training for employees cover phishing, impersonation, passwords, devices and the ICO’s data protection topics.
  4. Add role-specific content for people who approve payments or hold admin rights.
  5. Give staff one simple way to report a suspicious email, and thank people who use it.
  6. Check with HR before running phishing simulations, and never discipline people who click.
  7. Measure how many people report simulated and real phishing, and how fast, alongside click rates.
  8. Keep email filtering, MFA and EDR in place for the phishing that gets through.
  9. Record who has completed training, so you can evidence it if a customer or the ICO asks.
  10. Review the programme each year against NCSC guidance and the attacks you’ve actually seen.

Conclusion

Staff training is something almost every UK organisation that handles personal data should run, and it’s cheap to start: the NCSC’s course is free and takes under 30 minutes. The research is blunt about its limits. An annual course on its own won’t stop people clicking, so the programmes worth paying for are frequent and built around reporting.

The rest of the work is technical, which is why the NCSC treats staff training as one of four layers of phishing defence. Filtering cuts what reaches inboxes and MFA limits what a stolen password can do. When something still gets through, someone needs to act quickly.

Transputec does both. As a Premier Mimecast Partner, we run Mimecast Awareness Training and Human Risk Management inside our email security engagements, and our cyber security services cover detection and response around the clock.

If a customer or your own phishing reports have raised the question, talk to us about the security work behind your staff training.

FAQs

No. The NCSC’s Requirements for IT Infrastructure v3.3 (April 2026) set five technical controls, and staff training isn’t one of them. The closest item is in the password guidance, which asks you to support users by educating them about avoiding common passwords and encouraging longer ones.

Yes. The NCSC’s Top Tips for Staff e-learning is free, needs no login and takes less than 30 minutes. It covers strong passwords, securing devices, defending against phishing and reporting incidents, and organisations can download it in SCORM formats to run inside their own learning platform.

Only some plans. Attack simulation training needs Microsoft 365 E5 or Defender for Office 365 Plan 2, which is £3.80 per user per month on Microsoft’s UK price list. Business Premium and E3 include Plan 1, which doesn’t have it, although E3 customers get a limited trial. Transputec’s Microsoft 365 services include Defender for Office configuration.

No. The NCSC says blaming users for clicking on links doesn’t work, that punishing people for clicking emails you sent starts to resemble entrapment, and that employees afraid for their jobs won’t report mistakes. It wants people to feel supported to come forward, even after they’ve clicked.

About one in five. The Cyber Security Breaches Survey 2025/26, published on 30 April 2026, found 19% of businesses had run cyber security training or awareness sessions in the previous 12 months. That rose to 54% of medium businesses and 84% of large ones, and the figure for charities was 17%.

This article was drafted with AI assistance and reviewed by the Transputec team. Featured image: AI-generated.

Ready to experience the Transputec difference?

Turn IT headaches into operational strength. Book a free consultation and see exactly what we can streamline inside your business. 

Get a Strategic Consultation

Sonny Sehgal

CEO & Co-Founder

Since co-founding Transputec, Sonny has guided hundreds of enterprises through every major shift in technology- from the birth of the PC to the rise of Global Cloud and now Generative AI. Known for his "straight-talking" approach to cyber security and IT strategy, he provides the bridge between complex technical infrastructure and boardroom-level business outcomes.

Share Blog »

← Blogs

Contact

Get in Touch