The most disruptive cyber attacks to hit UK organisations over the past eighteen months have a common feature: they began with impersonation. An attacker convinced a helpdesk agent to reset a password, or persuaded an employee to click, approve or disclose something they should not have. Technical defences performed as designed, yet the organisations were still breached, because the people operating those defences lacked the training to recognise what was in front of them.
This changes how cyber security investment should be approached. For boards and executives, it moves the conversation into the territory of culture, competence and governance. For CISOs and IT leaders, it elevates staff training from a compliance exercise to one of the most effective controls available.
The human element in modern breaches
The UK Government’s Cyber Security Breaches Survey 2025 found that phishing was identified in 85% of business breaches and 86% of charity breaches. Despite this, only 19% of businesses provided any form of cyber security training to staff in the previous twelve months. The figure rises to 76% among large businesses, which leaves a significant gap across the small and medium-sized organisations that make up most UK supply chains.
The 2025 attacks on Marks & Spencer and the Co-op, attributed to the Scattered Spider group, illustrate the point. In both cases, attackers bypassed technical defences by impersonating employees and manipulating IT helpdesk staff into resetting credentials. The Co-op has since reported an £80 million profit hit and £206 million in lost revenue in the first half of 2025, while M&S has estimated a £300 million impact on operating profit. The attackers in both incidents walked through the front door after being handed the keys.
The NCSC has been making this point for some years. As technical controls such as multi-factor authentication and endpoint detection have matured, attackers have shifted their focus to the people who operate those controls. Staff who do not understand why a given process exists, or how a social engineering attempt tends to present itself, can be persuaded to work around even well-designed defences.
From awareness to culture
The NCSC’s guidance on staff awareness, set out in Principle B6 of the Cyber Assessment Framework and in the “10 Steps to Cyber Security” collection, emphasises that training works only when it sits inside a supportive culture. Positive messaging about the role employees play tends to produce better outcomes than warnings about consequences. Short, regular interventions embed knowledge more effectively than an annual hour-long session. Senior leaders need to be seen taking the training themselves, because awareness campaigns that executives are visibly disengaged from lose credibility quickly.
E-learning suits this model because it can be delivered in short modules, tailored to roles, and refreshed as threats evolve. Phishing recognition, handling of confidential information, and awareness of AI-enabled threats such as deepfake voice impersonation all lend themselves to scenario-based content delivered in short bursts throughout the year. Employees should come away able to recognise when a request looks suspicious and confident about how to escalate it.
The regulatory and framework case
Article 32 of the UK GDPR requires organisations to implement appropriate technical and organisational measures, and the ICO’s guidance identifies staff awareness and training among those measures. ICO enforcement activity in 2025 reinforced the point. The overall number of enforcement actions fell, but the value of fines rose sharply. Capita was fined £14 million in October 2025 in connection with its March 2023 breach, and LastPass UK was fined £1.2 million the following month. The ICO’s reasoning in both decisions pointed to inadequate organisational measures, with training forming part of that assessment.
ISO/IEC 27001:2022 sets similar expectations. Clause 7.2 requires that staff performing work under the Information Security Management System are competent on the basis of education, training or experience. Clause 7.3 requires that they are aware of the information security policy, their contribution to the ISMS, and the implications of non-conformance. Annex A control 6.3 translates these into a requirement for an awareness, education and training programme tailored to role. Auditors expect documented training plans, completion records and evidence that understanding has been tested.
Organisations that will fall under the forthcoming Cyber Security and Resilience Bill, or that are already subject to the Network and Information Systems Regulations, face comparable expectations. For FCA-regulated firms, operational resilience is explicitly a board-level responsibility, and staff capability forms part of it.
The commercial case
Cyber insurance underwriters have tightened their requirements considerably over the past two years. Documented staff awareness training, usually supported by phishing simulations, is now a standard expectation at renewal. Organisations that cannot evidence a structured programme are likely to see higher premiums, narrower coverage or, in some cases, refusal of cover. Insurers tend to reward organisations that can evidence a mature approach, and a well-documented training programme is one of the more affordable ways to do so.
Training also features in procurement. Enterprise customers and public sector buyers routinely ask for evidence of staff awareness programmes during supplier due diligence, and the ability to produce clear documentation can shorten sales cycles.
Making e-learning work in practice
Content should be short, engaging and reinforced throughout the year. Modules should be tailored to role, so that finance staff receive relevant content on invoice fraud and payment verification while IT administrators receive deeper material on privileged access and secure configuration. Learning should be backed up by practical reinforcement such as simulated phishing, with results used to identify where more support is needed rather than to penalise individuals. Completion and comprehension should be tracked, so the organisation has evidence of its position rather than an assumption.
Training should run continuously throughout the year. The threat landscape evolves quickly, and the rise of AI-generated phishing, voice cloning and deepfake impersonation means that content designed two years ago is unlikely to reflect the tactics staff are encountering now.
Technical controls remain essential to any security programme. The events of the past year demonstrate, though, that the resilience of an organisation rests heavily on the judgement of its people. Structured, regularly refreshed training is a cost-effective way to support that judgement.
Evolve North has recently launched its new e-learning catalogue, which currently includes six courses covering information security, handling confidential information, a bitesize “spot the phish” module, and several courses on AI-related risks. Further role-specific courses, including modules for virtual DPOs and virtual CISOs, and guidance on planning cyber incident exercises, are in development. Get in touch if you would like to discuss how training fits into your wider security and GRC programme.
