Skip to main content

Cyber Security

Security awareness training for staff

Security awareness training for staff: phishing simulations, short practical sessions, a clear policy and a reporting route, with modest, measurable aims.

In short

Security awareness training teaches your staff to recognise phishing, handle passwords and MFA properly, spot payment fraud and report anything odd quickly. Dig IT Solutions combines simulated phishing emails with short, plain-English sessions and a simple written policy. The aim is modest and measurable: fewer risky clicks, more reports and staff who know what to do when something looks wrong.

When you need this

Signs this is the right conversation

  • Our biggest risk is someone clicking something they shouldn't.
  • We've had phishing emails get through and staff didn't report them.
  • We have no security policy that people have actually read.
  • Insurers and clients now ask whether we train staff.
  • Previous training was an hour-long video everyone ignored.

Scope

What we deliver

  • 01

    Phishing simulations

    Realistic but safe test emails sent to staff on a schedule, with click and report rates tracked so you can see improvement over time.

  • 02

    Short staff sessions

    Thirty to forty-five minute sessions, in person or on Teams, covering phishing, passwords, MFA, invoice fraud, safe remote working and what to report.

  • 03

    Micro-learning after a click

    Anyone who clicks a simulation sees a brief, non-judgemental explanation of what to look for next time.

  • 04

    Acceptable use and security policy

    A short policy in plain English covering devices, passwords, data handling, remote working and reporting, ready to sign at induction.

  • 05

    Reporting route

    A report button and clear instruction on who to tell, so suspicious emails reach our helpdesk in minutes.

  • 06

    Progress reporting

    Quarterly summary of simulation results, session attendance and recommended follow-ups for management.

Outcomes

What you get out of it

  • Staff who pause before clicking and know how to report.
  • Measurable reduction in risky clicks over time.
  • Evidence of training for insurers, Cyber Essentials and client questionnaires.
  • A policy people have actually read and signed.

FAQ

Questions we are asked

Straight answers. If yours is not here, call 020 8482 4020 or 01992 939 365 and ask an engineer.
Does security awareness training actually work?
It reduces risk without eliminating it. Regular, short, relevant training combined with simulations typically lowers click rates and, more importantly, raises reporting rates, which is what lets IT respond quickly. It works best alongside technical controls such as MFA and email filtering, and it fades if it stops. We'd rather promise a measurable improvement in behaviour than claim that trained staff never click.
How often should staff receive security training?
A session at induction, a refresher at least annually and phishing simulations spread through the year work well for most businesses. Short and frequent beats long and rare. We also send brief updates when a new scam is circulating, for example a wave of fake Microsoft login pages or a courier scam. The NCSC's free Top tips for staff resource is a good supplement.
Will phishing simulations upset staff?
Not if they're introduced properly. We tell staff in advance that simulations will happen, explain why, and make it clear the goal is learning rather than blame. Results are reported by team or overall, not by naming individuals. Framing it as a shared defence, with reports celebrated, gets far better engagement than a gotcha approach.
What should a security policy for a small business include?
Keep it short: how to choose and store passwords, that MFA is required, how to treat company devices and personal devices, what data can be stored where, rules for remote working and public Wi-Fi, how to verify payment requests, and how to report incidents. A two-page document people read beats a twenty-page one they don't. We supply a template and adapt it with you.
Does training count towards Cyber Essentials?
Cyber Essentials assesses technical controls rather than training, so training is not a scored requirement. It does help you meet the spirit of the user access control and malware protection controls, and it's a common request from cyber insurers and larger clients in supply-chain questionnaires. We include training evidence in the pack we prepare for certification.

Next step

Talk to an engineer, not a sales script

Tell us what is not working, or what you are planning, and we will give you a straight view on what it would take to fix.

WhatsApp us