The person the attacker is actually targeting
Attackers rarely start with a zero-day or a brute-force run at your firewall. They start with a person. Someone clicks a link in an email that looked legitimate. Someone replies to what seemed to be a request from their CEO, possibly built with AI voice cloning. Someone types credentials into a pixel-perfect copy of a real login page.
The government’s Cyber Security Breaches Survey 2025/2026 found that 38% of UK businesses experienced a phishing attack, and that 69% of the businesses and charities breached rated phishing the most disruptive attack they faced. It is the most common threat your staff meet and the one most likely to hurt.
Technical defences matter. Cybersecurity services and managed detection and response catch a great deal. They will not catch every phishing email, every social engineering call or every impersonation attempt. The last control is the person at the keyboard, and training decides which way that goes.
Why annual security awareness training does not change behaviour
Most companies tick the box with one annual session: a long slideshow, a quiz, a certificate nobody opens again. It does not hold. Within a month or so, people are back to their old habits.
Effective training is short, frequent and immediately relevant. Our programme sends one module a month, each under five minutes, covering a single topic with real examples drawn from attacks on UK businesses. Short content gets finished. Hour-long content gets skipped.
Phishing simulations that mirror real attacks
Phishing simulation is the part of the programme that actually tells you something. We send realistic fake phishing emails to your team and measure who clicks, who reports and who hands over credentials.
Our simulations are not generic. We craft campaigns that mirror the specific threats facing your industry. For financial services firms, that means fake wire transfer requests, spoofed investment platform notifications, fraudulent invoice emails from known suppliers, and impersonation of regulatory bodies. These are the exact techniques attackers use against hedge funds, PE firms, and wealth managers in London.
Users who click a simulated phishing link see an immediate coaching page that explains what they missed, what the red flags were, and how to handle similar emails in future. This real-time feedback is significantly more effective than retroactive training because the mistake is fresh and the lesson sticks.
If you are still deciding whether simulated phishing is worth running, we set out the evidence separately — what click rates really tell you, where the numbers mislead, and what changes after a year — in anti-phishing testing for London firms.
The roles attackers go after first
Finance teams, executive assistants and senior leadership are the most targeted people in any organisation. They move money, they carry authority, and their email addresses are usually easy to find. A standard simulation does not stretch them.
So we run quarterly spear-phishing campaigns aimed specifically at those roles, using personalised, well-researched approaches. They test whether your highest-risk people can spot a convincing impersonation, which is the thing general training never quite reaches.
Why punishing the clicker lowers your reporting rate
This is the single biggest determinant of whether a programme works, and it is the easiest part to get wrong.
The NCSC is explicit on this point: naming, shaming or disciplining staff who fall for a phishing simulation is counterproductive. It does not reduce clicking. It reliably reduces reporting — and reporting is the metric that actually protects you. A user who clicks and tells you within two minutes is far more valuable than one who clicks, panics, and says nothing for a week.
Practically, that means:
- No leaderboards of who clicked, at any stage of the programme.
- Never send simulation results to a clicker’s line manager as a performance matter.
- Make reporting a single button, and thank every person who uses it — including the false positives.
- Measure report rate as the headline metric, not click rate.
Firms that only track click rate optimise for silence. The organisations that detect real attacks early are the ones where reporting a mistake is socially free.
A one-off phishing assessment to start
The one-off assessment is a straightforward way to find out where you stand. It is a single fixed fee, quoted on enquiry, and it covers one realistic simulation of your own staff, immediate coaching for anyone who clicks, a board-ready report and a 30-minute debrief. You keep the report whatever you decide next.
For larger teams the same test prices per seat, per month, with continuous simulations rather than a one-off. The ongoing programme — quarterly simulations, continuous training for repeat clickers, a monthly board report — is priced the same way. One test is a snapshot; risk moves as staff and tactics change, so tell us your headcount and we will put a figure to whichever suits you.
What security awareness training costs
Across the UK market this is priced per user, per year. What moves it is whether simulation and management are included. Realistic 2026 ranges:
- Platform-only licence (you run it): £15–£30 per user/year
- Fully managed programme (the provider runs campaigns, triages reports and produces board reporting): £35–£60 per user/year
- Add-on quarterly spear-phishing for high-risk roles: typically £1,000–£2,500 per year for a finance/exec cohort
For a 50-person London firm, a managed programme is usually £1,750–£3,000 per year. That is materially less than the excess on most cyber insurance policies.
Training evidence for Cyber Essentials, ISO 27001 and DORA
Awareness training is one of the few controls that turns up in almost every framework a London firm meets:
| Framework | Requirement |
|---|---|
| Cyber Essentials | Not a technical control, but user education underpins the password and malware requirements — see our v3.3 breakdown |
| ISO 27001 | Annex A 6.3 requires documented, ongoing awareness education with evidence of completion |
| DORA | Article 13 mandates ICT security awareness programmes, including for senior management |
| FCA operational resilience | Expects demonstrable staff capability to recognise and escalate incidents |
| Cyber insurance | Increasingly a condition of cover, and one insurers audit after a claim |
The practical implication: keep the completion records. Most firms can describe their training but cannot evidence it, and evidence is what an auditor or insurer asks for.
Programme targets to measure against
These are the targets we set with a firm starting from no formal programme. They are goals to work toward, not results we are claiming on your behalf:
| Metric | Typical starting point | Target by month 6 |
|---|---|---|
| Phishing click rate | 25–35% | Under 5% |
| Report rate | Under 5% | Above 60% |
| Median time to report | Never / days | Under 10 minutes |
| Training completion | — | Above 90% |
| Repeat clickers | — | Under 3% of staff |
Click rate falling while report rate stays flat is a warning sign, not a success — it usually means people have learned to recognise your simulations rather than phishing.
Roll it out without annoying everyone
- Baseline first, quietly. Run one simulation before any announcement, so you have an honest starting number.
- Announce the programme, not the test. Tell staff a programme is starting and why. Do not tell them when simulations will arrive.
- Deploy the report button before the first campaign. Asking people to report with no mechanism guarantees a bad first result.
- Start monthly and short. Five minutes, one topic. Quarterly hour-long sessions do not change behaviour.
- Brief the executive team separately. They are the most targeted and the most likely to ask for an exemption. Exempting them is how business email compromise succeeds.
- Review at 90 days. Adjust difficulty to your actual report rate rather than a vendor default.
Hand auditors the evidence with monthly reporting
Every month you get simulation click rates, report rates, completion rates and the trend over time. We show which departments and roles are moving and which need more attention, then adjust the programme rather than repeating it.
For FCA-regulated firms, those reports are the evidence that your training meets expectations under SYSC, DORA and GDPR. When an auditor asks what you are doing about human risk, you hand them the dashboard instead of describing it.