Skip to content
Security Updated Noah Stegman

How to Run Security Awareness Training in a Small Business

A practical guide to security awareness training for small offices: topics, a yearly schedule, phishing simulations, licensing, and what to measure.

A workable security awareness program for a small business has four parts: a short session for every new hire in their first week, one brief topic each month or quarter, a simulated phishing email a few times a year, and a simple way to report anything suspicious. Measure how often staff report, not only how often they click. The whole thing should cost each employee about two hours a year, and it can be run with free material if there is no budget.

What is security awareness training?

It is ongoing practice that teaches staff to recognize and report attempts to trick them: phishing emails, fake invoices, phone pretexts, and requests for passwords or sign-in codes. “Ongoing” is the important word. A single video at hiring fades within months, which is why federal guidance says to repeat security awareness training regularly.

The case for it is simple. Verizon’s 2026 Data Breach Investigations Report found a human element in 62% of breaches. Technical controls catch a lot, and people are the layer that handles what gets through.

Is training required for your business?

For some, yes.

For everyone else it is optional and still one of the lower-cost protections available.

What should the training cover?

Keep each topic to ten minutes or less.

TopicWhat staff should be able to do afterward
Spotting phishingRun the sender, link, and request checks in our phishing checklist
ReportingUse the Report button and know who to tell, without fear of blame
Payment and invoice fraudFollow the callback rule for any bank detail change. See business email compromise
Voice, text, and video impersonationVerify unusual requests on a saved number. See AI phishing and deepfakes
Passwords and sign-in codesUse the password manager, never share a code, deny unexpected sign-in prompts
QR codes and attachmentsTreat QR codes as links, and be cautious with unexpected files
Devices and physical habitsLock screens, keep updates on, report lost devices the same day
What to do after a mistakeReport within minutes. Who to contact and what happens next

Voice and text deserve a place on the list. Verizon found that in phishing simulations, click rates on voice and text message lures ran 40% higher than email.

Tailor the examples to the job. The person who pays invoices needs the payment fraud session more than anyone. The front desk needs phone pretexts. Owners and managers need all of it, because they are impersonated most and are often the people exempted from training.

A realistic yearly schedule

WhenActivityTime per person
First week for new hiresBasics: phishing checks, reporting, passwords and MFA, payment rule30 to 45 minutes
Monthly or quarterlyOne short topic from the table above5 to 10 minutes
Three or four times a yearSimulated phishing email, with a short lesson for anyone who clicksA few minutes
Once a yearReview the payment verification procedure with everyone who handles money20 minutes
After any real incident or near missA brief, blame-free walkthrough of what happened10 minutes

Monthly keeps the habit fresher. Quarterly is the floor. Pick the pace you will actually keep, because a modest schedule that happens beats an ambitious one that lapses. Anyone with a login should be included: part-time staff, contractors, and owners.

How do phishing simulations work?

A simulation sends staff a harmless imitation of a phishing email. If someone clicks the link or enters a password on the practice page, they see a short explanation of the clues they missed. Results show which kinds of lures work on your office so the next topic can address them.

Ground rules that keep simulations useful:

  1. Announce the program, not the dates. Tell staff that practice emails will arrive during the year and why.
  2. Never punish clicks. Follow a click with a two minute lesson. Punishment teaches people to hide mistakes, and a hidden real mistake is far more costly than a click.
  3. Start easy and get harder. Use lures that resemble what your office really receives: invoices, shared files, password expiry notices.
  4. Avoid cruel themes. Fake bonuses or layoffs damage trust for little training value.
  5. Count reports as the win. Thank the first person who reports each simulation.

Tools and licensing: what you may already have

Microsoft 365

Microsoft’s phishing simulator is called Attack simulation training. It sits in the Microsoft Defender portal under Email and collaboration > Attack simulation training. It can send simulated credential harvest, attachment, link, and QR code lures, assign training automatically, run training-only campaigns with no simulation, and schedule recurring simulations.

Licensing is where offices get caught out. Microsoft states that Attack simulation training requires Microsoft 365 E5 or Microsoft Defender for Office 365 Plan 2. Microsoft 365 Business Premium includes Defender for Office 365 Plan 1, so the simulator is not included in Business Premium by default.

Options as of September 2026:

  • Defender Suite for Business Premium, an add-on that includes Defender for Office 365 Plan 2 with attack simulation training, listed at $10.00 per user per month, paid yearly. It requires Business Premium and bundles several other security upgrades, so it makes sense only if you want those too.
  • The 90-day Defender for Office 365 trial, which Microsoft offers from the Defender portal, to see whether the tool suits your office.
  • The built-in Report button in supported versions of Outlook, which is separate from the simulator. Users choose Report > Report phishing. An administrator sets where reports go in the Defender portal under Settings > Email & collaboration > User reported settings.

Google Workspace

Gmail has a built-in Report phishing option under the More menu next to Reply, so the reporting habit works the same way. For simulated phishing emails and lesson tracking, look at the third-party services below.

Third-party training services

Many companies sell training libraries with phishing simulation, priced per user. Pricing and quality vary, so compare on these points:

  • Are lessons short (under ten minutes) and updated during the year?
  • Does it cover voice, text message, QR code, and payment fraud, or only email links?
  • Does it report on reporting rate as well as click rate?
  • Does it work with your email system without weakening your spam filter for real mail?
  • Can you export completion records for an insurer or auditor?
  • Is there a minimum user count or a multi-year contract?

Free material

If there is no budget, you can still run the schedule above. The FTC publishes free cybersecurity guidance for small businesses covering phishing, business email imposters, ransomware, and tech support scams. CISA’s Secure Our World program offers free tip sheets and videos on phishing, passwords, multi-factor authentication, and updates. One topic per staff meeting, plus the reporting habit, is a legitimate program.

How do you measure whether it is working?

MeasureWhat it tells youHow to read it
Reporting rate (share of staff who report a simulation)Whether people act on suspicionThe most useful number. It should rise over time
Time to first reportHow fast a real attack would be flaggedMinutes is the goal
Click rateSusceptibility to a given lureDepends heavily on how hard the lure was, so compare similar lures
Credential entry rateHow many went past the click and typed a passwordMore serious than a click
Repeat clickersWho needs one-to-one helpOffer coaching, not discipline
Completion rateWhether training is happening at allShould be everyone, including owners
Real suspicious messages reportedWhether the habit carries over to real mailA rise is good news, not bad

Do not chase a click rate of zero or judge the program on a single number. A very low click rate can simply mean the simulations were too easy. Microsoft’s tool addresses this with a predicted compromise rate for each lure, so you can compare your result with what was expected for that difficulty.

Review the numbers quarterly, pick the next topic from the weakest area, and keep a simple record of who completed what and when.

Limits of training

Training reduces risk. It does not remove it, and it should never be the only control. Everyone has a distracted day, and some fraudulent messages come from a vendor’s genuine mailbox and look flawless. Pair training with multi-factor authentication, email filtering, and a payment verification rule, so that one click is not enough to cause a loss.

Scale matters too. A three person office does not need a platform. Fifteen minutes at a staff meeting each quarter, a practiced reporting habit, and a written payment rule cover most of the value.

Common mistakes

  • One session at hiring and nothing afterward.
  • Exempting owners and managers.
  • Punishing or naming people who click.
  • Measuring clicks and ignoring reports.
  • Testing only email links while real attempts arrive by phone and text message.
  • Buying a platform and never scheduling anything in it.
  • Relying on training in place of technical controls.

Common questions

How often should a small business run phishing simulations?

Three or four times a year suits most small offices. That is frequent enough to keep the habit alive and show a trend, and spaced enough that staff do not start treating every message as a test. Monthly is reasonable for larger teams or higher-risk roles such as accounts payable.

Does Microsoft 365 Business Premium include phishing simulation?

Not by default. Microsoft’s documentation says Attack simulation training requires Microsoft 365 E5 or Defender for Office 365 Plan 2, and Business Premium includes Plan 1. You can add Plan 2 through the Defender Suite for Business Premium add-on, or try it with Microsoft’s 90-day trial.

Should we tell employees before sending a simulated phishing email?

Tell them the program exists and that practice emails will arrive at some point. Do not give dates. Staff who know the purpose, and know that clicking leads to a short lesson instead of a reprimand, are more likely to report both simulations and real mistakes.

What is a good click rate?

There is no universal target, because the result depends on how convincing the lure was. Compare similar lures over time and look for a falling click rate alongside a rising reporting rate. A fast first report matters more than a perfect score.

How we can help

Coastal Growth Co. can set up and run this for small businesses in Orange County: choosing a tool that fits your licensing, configuring the Report button, scheduling simulations and short topics, and sending you a plain summary of the results each quarter. See our managed IT services or get in touch. Scope and price are agreed before any paid work begins.

Need a hand with this?

I offer IT support across Orange County, with on-site work in Los Angeles and nearby areas by arrangement.

Let's talk arrow_forward

Get in touch

Talk with Noah

Tell me about your business and what is getting in the way. A recurring problem, an upcoming project, or a setup you would like a second opinion on.

noah@coastalgrowthco.com

Noah Stegman · Coastal Growth Co.

Your message goes to Noah. I will reply by email. Please leave out passwords and sensitive account details.