Cyber Security Awareness Training That People Finish
· 5 minute read
Most organisations already run some form of cyber security awareness training. Fewer can say with confidence that most of their staff actually finished it. The UK’s 2025/26 Cyber Security Breaches Survey found that only 19% of businesses had provided staff with cyber security training or awareness activities in the past year, a figure that has stayed flat rather than grown, even as 43% of businesses reported experiencing a breach or attack of some kind, with phishing the most common attack type, affecting 38% of businesses overall.
Why generic training gets skipped
A single, one-size-fits-all module, the same slides for finance, HR, sales and IT, asks a lot of people whose actual daily risk looks nothing alike. Someone in finance who approves payments faces a completely different attack to someone in HR handling job applications, and a course that cannot show either of them their own risk reads as irrelevant to both, which is exactly the kind of cyber security training people deprioritise until it is overdue and then rush through without absorbing it.
The finance-team example
Invoice and payment fraud aimed specifically at businesses shows why role-based training matters. UK Finance’s 2026 Annual Fraud Report recorded £41.3 million lost to invoice and mandate scams in 2025, with 68% of those losses landing on business accounts rather than personal ones, because, as the report puts it, businesses “make genuine higher-value payments more regularly, making it harder to spot and stop a fraudulent one.” CEO fraud, where someone impersonates a senior figure to authorise an urgent payment, showed an average loss of more than £28,000 per case, the highest of any scam type UK Finance tracks. A generic “spot the phishing email” module does not prepare a finance team for either pattern, because the attack does not look like a suspicious email; it looks like a normal, urgent payment request from someone who appears to have the authority to make it, which is the gap our Cyber Security for Finance Teams course is built to close.

What role-based training actually changes
A course built for a finance or payments team can cover the specific verification habits that stop invoice and CEO fraud: confirming a change of bank details through a separate, known channel rather than replying to the email that requested it, and treating urgency itself as a warning sign rather than a reason to move faster. A course built for managers covers a different problem: managers approve spend and access, and are usually the first person told when something looks wrong, so their training needs to cover what to do in the first minutes of a suspected incident, not just how to spot a phishing email themselves, the same role-versus-generic split that stalls Microsoft 365 Copilot adoption when everyone sits through the same session regardless of role.
Assessed, or just watched?
Completion figures like the 19% training rate above almost certainly count anyone who opened a module, whether or not they finished it or understood what was in it. A course gated by a real pass mark, one a learner can fail and has to retake, is the only format that produces a completion record meaning the person actually engaged with the content, not just that a link was opened somewhere on their computer.
What actually gets finished
Length matters as much as relevance. A single foundation course that everyone completes once, followed by shorter, role-specific courses only for the teams facing the sharpest risk, finance, management, HR, tends to get finished at a far higher rate than one long generic course that tries to cover every scenario for every audience at once. People finish training that visibly applies to their own job; they abandon training that clearly does not, however good its intentions were.
Keeping a record that holds up
If your organisation is ever asked what it did to prepare staff against a breach, “we ran some training” is a weaker answer than a dated, per-person completion record with a pass mark attached. That record is also the easiest way to see who still needs to be trained, rather than assuming a firm-wide rollout reached everyone equally, and it is the same record that makes a refresher easier to plan a year later.
Phishing simulations are not training
Many organisations run simulated phishing emails alongside, or instead of, structured training. A simulation is useful for measuring who currently notices a suspicious email, but it teaches nothing on its own to the people who click it: without a short course explaining what gave the email away and what to do differently, a simulation is a test with no lesson attached to a failing grade. The two work best together, not as substitutes for each other, and the combination gives you both a measure of current risk and a way to actually reduce it.

A short checklist
Before you roll out cyber security awareness training, ask whether it separates a general foundation course from role-specific ones for finance, management and any other high-risk function. Ask whether it is assessed with a genuine pass mark rather than a “mark as complete” button. And ask how long it actually takes, since a course with no stated length is one of the clearest signs it will not get finished.
More from Insights
All insights-
Data (Use and Access) Act 2025: What's Confirmed So Far
The Data (Use and Access) Act 2025 commenced most of its data protection changes on 5 February 2026, with a new complaints duty from 19 June 2026.
-
Employment Rights Act 2025 Changes: The Full Timeline
The Employment Rights Act 2025 changes arrive in stages from December 2025 to 2027. The Act was previously called the Employment Rights Bill.
-
Failure to Prevent Fraud Offence: Guidance and Size Test
The failure to prevent fraud offence is a corporate crime that applies only to large organisations, defined by a size test on turnover, assets and staff.
Ready to train your team?
Tell us which courses you're interested in and roughly how many learners, and we'll come back with a price within 24 hours.