How to Run Security Awareness Training in a Small Business
A practical guide to security awareness training for small offices: topics, a yearly schedule, phishing simulations, licensing, and what to measure.
A workable security awareness program for a small business has four parts: a short session for every new hire in their first week, one brief topic each month or quarter, a simulated phishing email a few times a year, and a simple way to report anything suspicious. Measure how often staff report, not only how often they click. The whole thing should cost each employee about two hours a year, and it can be run with free material if there is no budget.
What is security awareness training?
It is ongoing practice that teaches staff to recognize and report attempts to trick them: phishing emails, fake invoices, phone pretexts, and requests for passwords or sign-in codes. “Ongoing” is the important word. A single video at hiring fades within months, which is why federal guidance says to repeat security awareness training regularly.
The case for it is simple. Verizon’s 2026 Data Breach Investigations Report found a human element in 62% of breaches. Technical controls catch a lot, and people are the layer that handles what gets through.
Is training required for your business?
For some, yes.
- Healthcare. The HIPAA Security Rule requires covered entities and business associates to implement a security awareness and training program for all members of the workforce, including management. See our HIPAA IT guide.
- Businesses covered by the FTC Safeguards Rule, which applies to a broad range of non-bank financial businesses. The FTC’s guidance says to provide security awareness training and schedule regular refreshers. See our Safeguards Rule overview.
- Cyber insurance. If you carry a policy, check whether the application or renewal form asks about staff training and phishing tests, and answer accurately.
For everyone else it is optional and still one of the lower-cost protections available.
What should the training cover?
Keep each topic to ten minutes or less.
| Topic | What staff should be able to do afterward |
|---|---|
| Spotting phishing | Run the sender, link, and request checks in our phishing checklist |
| Reporting | Use the Report button and know who to tell, without fear of blame |
| Payment and invoice fraud | Follow the callback rule for any bank detail change. See business email compromise |
| Voice, text, and video impersonation | Verify unusual requests on a saved number. See AI phishing and deepfakes |
| Passwords and sign-in codes | Use the password manager, never share a code, deny unexpected sign-in prompts |
| QR codes and attachments | Treat QR codes as links, and be cautious with unexpected files |
| Devices and physical habits | Lock screens, keep updates on, report lost devices the same day |
| What to do after a mistake | Report within minutes. Who to contact and what happens next |
Voice and text deserve a place on the list. Verizon found that in phishing simulations, click rates on voice and text message lures ran 40% higher than email.
Tailor the examples to the job. The person who pays invoices needs the payment fraud session more than anyone. The front desk needs phone pretexts. Owners and managers need all of it, because they are impersonated most and are often the people exempted from training.
A realistic yearly schedule
| When | Activity | Time per person |
|---|---|---|
| First week for new hires | Basics: phishing checks, reporting, passwords and MFA, payment rule | 30 to 45 minutes |
| Monthly or quarterly | One short topic from the table above | 5 to 10 minutes |
| Three or four times a year | Simulated phishing email, with a short lesson for anyone who clicks | A few minutes |
| Once a year | Review the payment verification procedure with everyone who handles money | 20 minutes |
| After any real incident or near miss | A brief, blame-free walkthrough of what happened | 10 minutes |
Monthly keeps the habit fresher. Quarterly is the floor. Pick the pace you will actually keep, because a modest schedule that happens beats an ambitious one that lapses. Anyone with a login should be included: part-time staff, contractors, and owners.
How do phishing simulations work?
A simulation sends staff a harmless imitation of a phishing email. If someone clicks the link or enters a password on the practice page, they see a short explanation of the clues they missed. Results show which kinds of lures work on your office so the next topic can address them.
Ground rules that keep simulations useful:
- Announce the program, not the dates. Tell staff that practice emails will arrive during the year and why.
- Never punish clicks. Follow a click with a two minute lesson. Punishment teaches people to hide mistakes, and a hidden real mistake is far more costly than a click.
- Start easy and get harder. Use lures that resemble what your office really receives: invoices, shared files, password expiry notices.
- Avoid cruel themes. Fake bonuses or layoffs damage trust for little training value.
- Count reports as the win. Thank the first person who reports each simulation.
Tools and licensing: what you may already have
Microsoft 365
Microsoft’s phishing simulator is called Attack simulation training. It sits in the Microsoft Defender portal under Email and collaboration > Attack simulation training. It can send simulated credential harvest, attachment, link, and QR code lures, assign training automatically, run training-only campaigns with no simulation, and schedule recurring simulations.
Licensing is where offices get caught out. Microsoft states that Attack simulation training requires Microsoft 365 E5 or Microsoft Defender for Office 365 Plan 2. Microsoft 365 Business Premium includes Defender for Office 365 Plan 1, so the simulator is not included in Business Premium by default.
Options as of September 2026:
- Defender Suite for Business Premium, an add-on that includes Defender for Office 365 Plan 2 with attack simulation training, listed at $10.00 per user per month, paid yearly. It requires Business Premium and bundles several other security upgrades, so it makes sense only if you want those too.
- The 90-day Defender for Office 365 trial, which Microsoft offers from the Defender portal, to see whether the tool suits your office.
- The built-in Report button in supported versions of Outlook, which is separate from the simulator. Users choose Report > Report phishing. An administrator sets where reports go in the Defender portal under Settings > Email & collaboration > User reported settings.
Google Workspace
Gmail has a built-in Report phishing option under the More menu next to Reply, so the reporting habit works the same way. For simulated phishing emails and lesson tracking, look at the third-party services below.
Third-party training services
Many companies sell training libraries with phishing simulation, priced per user. Pricing and quality vary, so compare on these points:
- Are lessons short (under ten minutes) and updated during the year?
- Does it cover voice, text message, QR code, and payment fraud, or only email links?
- Does it report on reporting rate as well as click rate?
- Does it work with your email system without weakening your spam filter for real mail?
- Can you export completion records for an insurer or auditor?
- Is there a minimum user count or a multi-year contract?
Free material
If there is no budget, you can still run the schedule above. The FTC publishes free cybersecurity guidance for small businesses covering phishing, business email imposters, ransomware, and tech support scams. CISA’s Secure Our World program offers free tip sheets and videos on phishing, passwords, multi-factor authentication, and updates. One topic per staff meeting, plus the reporting habit, is a legitimate program.
How do you measure whether it is working?
| Measure | What it tells you | How to read it |
|---|---|---|
| Reporting rate (share of staff who report a simulation) | Whether people act on suspicion | The most useful number. It should rise over time |
| Time to first report | How fast a real attack would be flagged | Minutes is the goal |
| Click rate | Susceptibility to a given lure | Depends heavily on how hard the lure was, so compare similar lures |
| Credential entry rate | How many went past the click and typed a password | More serious than a click |
| Repeat clickers | Who needs one-to-one help | Offer coaching, not discipline |
| Completion rate | Whether training is happening at all | Should be everyone, including owners |
| Real suspicious messages reported | Whether the habit carries over to real mail | A rise is good news, not bad |
Do not chase a click rate of zero or judge the program on a single number. A very low click rate can simply mean the simulations were too easy. Microsoft’s tool addresses this with a predicted compromise rate for each lure, so you can compare your result with what was expected for that difficulty.
Review the numbers quarterly, pick the next topic from the weakest area, and keep a simple record of who completed what and when.
Limits of training
Training reduces risk. It does not remove it, and it should never be the only control. Everyone has a distracted day, and some fraudulent messages come from a vendor’s genuine mailbox and look flawless. Pair training with multi-factor authentication, email filtering, and a payment verification rule, so that one click is not enough to cause a loss.
Scale matters too. A three person office does not need a platform. Fifteen minutes at a staff meeting each quarter, a practiced reporting habit, and a written payment rule cover most of the value.
Common mistakes
- One session at hiring and nothing afterward.
- Exempting owners and managers.
- Punishing or naming people who click.
- Measuring clicks and ignoring reports.
- Testing only email links while real attempts arrive by phone and text message.
- Buying a platform and never scheduling anything in it.
- Relying on training in place of technical controls.
Common questions
How often should a small business run phishing simulations?
Three or four times a year suits most small offices. That is frequent enough to keep the habit alive and show a trend, and spaced enough that staff do not start treating every message as a test. Monthly is reasonable for larger teams or higher-risk roles such as accounts payable.
Does Microsoft 365 Business Premium include phishing simulation?
Not by default. Microsoft’s documentation says Attack simulation training requires Microsoft 365 E5 or Defender for Office 365 Plan 2, and Business Premium includes Plan 1. You can add Plan 2 through the Defender Suite for Business Premium add-on, or try it with Microsoft’s 90-day trial.
Should we tell employees before sending a simulated phishing email?
Tell them the program exists and that practice emails will arrive at some point. Do not give dates. Staff who know the purpose, and know that clicking leads to a short lesson instead of a reprimand, are more likely to report both simulations and real mistakes.
What is a good click rate?
There is no universal target, because the result depends on how convincing the lure was. Compare similar lures over time and look for a falling click rate alongside a rising reporting rate. A fast first report matters more than a perfect score.
How we can help
Coastal Growth Co. can set up and run this for small businesses in Orange County: choosing a tool that fits your licensing, configuring the Report button, scheduling simulations and short topics, and sending you a plain summary of the results each quarter. See our managed IT services or get in touch. Scope and price are agreed before any paid work begins.
- security awareness training
- phishing simulation
- employee training
- small business IT
Need a hand with this?
I offer IT support across Orange County, with on-site work in Los Angeles and nearby areas by arrangement.
Let's talk arrow_forward