Cyber security awareness training helps employees recognise, avoid and report the threats that technology alone cannot prevent. But effective awareness is no longer about asking everyone to complete the same training module once a year. Phishing, impersonation, data handling mistakes and increasingly convincing social engineering mean people remain an important part of an organisation’s cyber security. The challenge is to make security awareness part of the way people work.
The Human Element Hasn’t Gone Away
The UK Government’s Cyber Security Breaches Survey 2025/26 found phishing remained the most commonly identified type of cyber breach or attack, experienced by 38% of businesses. This increased to 60% of medium businesses and 63% of large businesses. Full report here
Technology continues to improve, but so do the techniques used to persuade people to bypass it. Good technical controls remain essential, but they need to be supported by people who can recognise when something doesn’t look right and know what to do next.
Why Annual Training Isn’t Enough
Annual training provides an important baseline and helps organisations demonstrate that key areas have been covered. But people forget information. Threats change. Employees move roles. New starters join. And new technology creates different risks. The ICO’s current guidance expects organisations to provide induction and refresher training, regularly review their programmes and consider the specific needs of different staff groups.
An effective approach therefore combines formal training with ongoing awareness throughout the year. That might include short updates, team briefings, phishing simulations, scenario-based exercises and reminders linked to current threats. The aim isn’t to turn everyone into a cyber security expert. It’s to make good security decisions part of everyday working behaviour.
Building Awareness with E-Learning
E-learning provides a practical foundation for an ongoing awareness programme, particularly when training is accessible, relevant and easy to deliver across an organisation. Our new Evolve North e-learning courses give organisations a flexible way to provide training across key areas including cyber security, information governance and data protection. Courses can be used for new starter training, organisation-wide refreshers or as part of a wider awareness programme, alongside targeted communications, simulations and role-specific training. It means training can become an ongoing part of an organisation’s approach rather than simply an annual exercise.
Should Everyone Receive the Same Training?
Not necessarily. Everyone with access to organisational systems, information or personal data should receive an appropriate level of awareness training, but some teams face different or greater risks. Finance teams may need additional awareness around payment diversion and supplier impersonation. HR teams regularly handle sensitive personal information. Senior leaders are attractive targets for impersonation and social engineering. Specialist roles in IT, information governance and data protection will require deeper training again. The most effective programmes provide a strong baseline for everyone, with additional training based on role and risk.
What Does Effective Security Awareness Look Like?
A good programme should reflect your organisation. Start with the risks your people genuinely encounter. Make training relevant to their roles, reinforce important messages throughout the year and make it very clear how employees should report something suspicious.
Crucially, measure more than completion rates. Knowledge checks, phishing simulations, employee feedback and incident reporting can provide a much better indication of whether training is translating into behaviour.
Are People Really the ‘Weakest Link’?
We don’t particularly like the phrase. People make mistakes, but employees can also spot suspicious activity, question unusual requests and report incidents before they escalate. The answer isn’t to rely entirely on people or technology. Strong technical controls should limit the impact of human error, while good training gives people the confidence to recognise and respond to risks. With the right combination, your people become another layer of defence.
How Often Should Cyber Security Awareness Training Take Place?
There isn’t a single frequency that suits every organisation. Formal training should be provided during induction and refreshed at appropriate intervals, with shorter awareness activity used throughout the year to keep important risks front of mind. Training should also be reviewed when threats, technology, working practices or employee responsibilities change.
If cyber security awareness in your organisation still largely means an annual training module, it may be worth asking whether it reflects the way your people work today. At Evolve North, we help organisations develop practical training and awareness across cyber security, information governance and data protection, from our new e-learning courses to more targeted training and wider awareness programmes.
To find out more about our training and e-learning options, call 01748 905 002 or email info@evolvenorth.com.
