Cybersecurity

Someone will click. What matters is whether they tell you.

A person icon beside a speech-bubble badge, representing a member of staff reporting a suspicious email rather than being scored on whether they clicked it

A business we spoke to had run phishing simulations for a year. The click rate had come down from something embarrassing to something respectable, the platform produced a nice graph, and everyone felt the money was working. Then somebody asked how many real phishing emails staff had reported in the same period. Nobody knew. There was no way to report one.

That is the shape of the problem. Phishing training has become a thing businesses buy and measure rather than a thing that changes what happens on a Tuesday morning when a convincing invoice lands. We sell staff phishing-awareness training ourselves, on the £77 plan, so read the rest of this with that in mind. It is also the layer the National Cyber Security Centre says gets over-emphasised, and they are right.

How often this actually lands

The government's Cyber Security Breaches Survey for 2025/2026 is blunt about the scale. Among businesses that identified any breach or attack in the previous twelve months, phishing was the most common by far, at 88 per cent. The next category down, impersonation, was 28 per cent. It was also named the most disruptive type of attack by 69 per cent of affected businesses.

One figure from that survey deserves more attention than it gets. When businesses were asked why phishing was the most disruptive thing that happened to them, the most common answer was not stolen money or lost files. It was staff time spent investigating potential attacks, at 21 per cent. Ahead of downtime. Ahead of the training itself.

Read that again, because it changes what you are buying. For most small businesses the cost of phishing is not one catastrophic click. It is hours, every month, spent working out whether things are real.

Set against that, 19 per cent of UK businesses did any staff training or awareness activity in the last year. That number has not moved: it was 19 per cent the year before too. Large businesses sit at 84 per cent. So the gap is not between good practice and bad practice, it is between big companies and everyone else.

NCSC has a section headed "The problems with phishing simulations"

Not a caveat buried in a footnote. A heading, in the middle of their main guidance on defending an organisation against phishing, listed in the contents at the top of the page.

The argument runs like this. No training package, simulations included, can teach users to spot every phishing attempt, and asking people to examine every email they receive in depth will not leave enough hours in the day. Since spotting all of them is impossible, punishing somebody for clicking on an email you deliberately sent them starts to resemble entrapment. NCSC's practical advice is to check with your HR department before running simulations at all.

Then the line that most vendors would rather you did not read: blaming users for clicking on links doesn't work. People click for a range of reasons, including personality and how stressed they are that afternoon, and none of those things respond to being told off.

There is a wrinkle worth knowing if you run a business with twelve staff. That guidance says it is written for medium to large organisations, and points smaller ones at NCSC's Cyber Action Toolkit first. The reasoning still applies to you. The assumption that you have a security team to run any of it does not.

Why the click rate is the wrong number

Click rate is popular because it is easy to produce and it goes down over time, which makes it look like progress. NCSC's objection is sharper than "it is a crude measure". Their wording is that metrics express an organisation's values, and if you appear to value the absence of reports of problems, you incentivise people to keep quiet about issues.

That is worth sitting with. A business that celebrates a falling click rate has told its staff, without ever saying it, that the goal is for nothing to be reported. Which is achievable. You just stop hearing about things.

The replacement NCSC suggests is simple: as well as counting how many people clicked, focus on how many reported it. Reports are the only signal you have that a campaign is hitting your business right now, and they arrive within minutes rather than in next quarter's summary.

In practice, three things are worth writing down each month. How many suspicious emails were reported. How long it took from the first one arriving to somebody telling you. And whether anything was done with the report, because if the answer is no, the reports will stop on their own soon enough.

The four layers, and where training sits

NCSC frames the whole subject as four layers, and the point of the framing is that no single one of them holds:

  • Make it difficult for attackers to reach your users at all.
  • Help users identify and report suspected phishing.
  • Protect your organisation from the effects of the ones that get through.
  • Respond quickly to incidents.

Training is layer two. Only layer two. The guidance describes it as the layer that is often over-emphasised in phishing defences, which is a strange thing to find in official advice and a very useful one.

The instruction attached to the model is the part small businesses should actually take away: if you cannot implement all of the mitigations, try to address at least some from within each of the layers. Something from each row beats everything from one row. A business with a mediocre training video, working DMARC, MFA everywhere and a person who knows what to do at 4pm on a Friday is in far better shape than one with an award-winning training programme and nothing else.

Layer one is where the cheap wins are

Stopping the message arriving costs less than teaching two hundred people to recognise it.

Publishing SPF, DKIM and DMARC records stops other people sending email that appears to come from your domain, which protects your customers and your suppliers as much as your own staff. It is a DNS change, it is free, and we have written the plain-English version of how it works. NCSC lists it first in this layer for a reason.

The other half of layer one is quieter. Attackers use what is freely available on your website and social media to make a message convincing, and the more senior the target the more of it there tends to be. Job titles, direct email addresses, the finance manager's name in a press release, holiday photos that say the managing director is in Spain this week. None of that needs deleting in a panic. It does deserve a look, particularly for the handful of people an attacker would most want to impersonate.

Make reporting the easy option

This is the part that gets skipped, and it is nearly free.

If reporting a suspicious email means forwarding it to an address nobody can remember, then writing an explanation, then wondering whether it was worth the fuss, most people will delete it and get on with their day. You never find out that the same message went to eleven other staff. Microsoft 365 and Outlook have a built-in report button. Turning it on is a ten-minute job and it converts reporting into the same effort as the mistake.

The second half is cultural and it cannot be bought. NCSC says not to reprimand users who struggle to recognise phishing emails, because people who fear reprisals will not report mistakes promptly, if at all. Training should reassure staff that they will not get in trouble for reporting, and the guidance is explicit that this needs buy-in across HR, support and senior management, not just from whoever runs IT.

The hardest version of this is somebody who clicked, entered a password, and only started to worry twenty minutes later. That person needs to feel able to say so immediately, because twenty minutes is recoverable and two days often is not. If your culture makes them hesitate, you have paid for training that produces silence.

NCSC also offers an alternative to simulations that costs nothing and is more interesting: get staff to write their own phishing emails. Trying to fool your colleagues teaches you far more about influence and urgency than being fooled does, and a friendly competition avoids the us-versus-them feeling that testing creates.

Give the exposed people extra help

Everyone gets the same twenty-minute video and everyone forgets it at the same rate. That is not a plan, it is a compliance tick.

NCSC names the groups worth treating differently. Customer-facing staff, because they receive high volumes of unsolicited email and cannot simply ignore messages from people they have never met. Anyone with access to sensitive information or authority over money. And whoever administers your IT, because their account is the one worth the most, which is also why the admin account should not be the one reading email.

For the money side, the control is a process rather than a lesson. Important email requests get verified using a second type of communication, meaning a phone call to a number you already had, not the one in the signature. That single habit is most of the defence against invoice fraud, and it works even when the person is convinced the email is genuine, which is exactly when training has already failed.

What catches the ones nobody reports

Assume the click happens. Some of them will.

If the message was after a password, multi-factor authentication is what stands between a stolen credential and a mailbox somebody else is reading. If it was after a machine, endpoint protection is the layer that notices something unusual running, which is the difference we covered in antivirus versus EDR. And when it does go wrong, the useful thing is not blame but a plan, which is what the first hour of a ransomware incident is about.

Those three are layers three and four. They are where the money goes when a business decides to be serious, and they work regardless of who clicked what.

Cyber Essentials does not ask for any of this

Worth knowing before you assume certification covers it. The five technical controls are firewalls, secure configuration, security update management, user access control and malware protection. Staff awareness training is not among them. A business can certify without ever having trained a single person about phishing.

That is not a criticism of the scheme, which is deliberately about technical controls that can be verified. It just means the paperwork and the risk are pointing at different things, and phishing sits mostly in the gap. For the record, 5 per cent of UK businesses reported adhering to Cyber Essentials last year and 2 per cent to Cyber Essentials Plus, so for most readers this is academic anyway.

Said plainly, since this section names the scheme: Alpha IT does not hold Cyber Essentials or Cyber Essentials Plus, and we are not an assessor. We use the published requirements because anybody can read them, which makes them a better reference than our opinion. If certification is the goal, our guide to the five controls covers the rest.

What we sell, and what it will not do

Our Professional plan is £77 per user per month excluding VAT and includes staff phishing-awareness training alongside email security and anti-phishing filtering. Essential, at £50, does not include either. It covers monitoring, automated patch management, endpoint antivirus, an asset register and a monthly health report. We would rather say that than let anybody assume the cheaper plan has a layer it does not have.

What it will not do is turn people into a filter, and we are not going to imply it might. Nobody can sell you that, whatever the brochure says. What it can reasonably do is make the fakes familiar, tell people exactly how to report one, and make it clear that reporting is welcome. The rest of the work is filtering, authentication, MFA and having somebody to ring.

If you want to know where you currently stand, the free IT health check asks about training in the last twelve months alongside the technical side, and you get the answers back whether or not you ever become a client.

Or start with the number that costs nothing to find. Go and look at how many phishing emails your staff reported last month. If it is zero, that is not a quiet month.

Frequently asked questions

Do phishing simulations actually work?+

They do one job well and another job badly. As a way of showing people what a convincing fake looks like, they are useful. As a measure of how safe you are, they are close to worthless, because NCSC's own position is that no training package, simulations included, can teach users to spot every phishing attempt. Run them if you want, but do not let the click rate become the number the board looks at.

Should we discipline someone who clicks a simulated phishing email?+

No, and NCSC goes further than advising against it. Since spotting every phishing email is impossible, punishing people for clicking on emails you sent them starts to look like entrapment, which is why the guidance says to check with your HR department before running simulations at all. The practical damage is worse than the legal question. People who fear reprisals stop reporting, and reporting is the part that actually protects you.

What should we measure instead of click rate?+

How many people reported it, and how quickly. NCSC's wording is that metrics express an organisation's values, and if you appear to value the absence of reports of problems, you incentivise people to keep quiet. So count reports as a success, not an inconvenience. A month with forty reports and two false alarms is a healthier month than one with silence.

How often should staff have phishing training?+

There is no legal interval and no magic number. Our own free IT health check asks whether the team has had phishing-awareness training in the last twelve months, which is a reasonable floor for a small business. What matters more than frequency is that the people at higher risk get extra attention, and that everyone knows how to report something in under ten seconds.

Does Cyber Essentials require staff security training?+

No. The five technical controls are firewalls, secure configuration, security update management, user access control and malware protection. Staff awareness training is not one of them, and you can certify without ever training a single person. Alpha IT does not hold Cyber Essentials or Cyber Essentials Plus and is not an assessor, so this is a reading of the published scheme, not a mark on anyone's homework.

Who in a small business needs more than the standard training?+

Three groups, and NCSC names them. Customer-facing staff, because they receive high volumes of unsolicited email and cannot simply ignore strangers. Anyone who moves money or handles supplier bank details. And whoever administers your IT, because their account is the most valuable one in the building. Give those people extra support rather than putting everyone through more of the same.

Is a report button worth setting up in Outlook?+

Yes, and it is the highest-value ten minutes in this whole subject. If reporting means forwarding an email to an address nobody can remember, most people will just delete the message and move on, and you never learn that forty other staff got it too. A button in the toolbar turns reporting into one click, which is the same effort as the mistake you are trying to catch.

Can training stop phishing on its own?+

It cannot, and that is NCSC's central point rather than ours. Training is one layer of four, and it is the one most often over-emphasised. The other three are making it harder for attackers to reach your inbox at all, limiting the damage when a message gets through, and being able to respond quickly. If your entire phishing strategy is an annual training video, you have bought the smallest part of the answer.

Call usFree consultation