Secure & resilient

Why Phishing Training That's Ticked Off Once a Year Solves Nothing

Many companies tick off awareness with one training a year. We explain why that rarely changes anything, and what actually works.

All articles

Why Phishing Training That’s Ticked Off Once a Year Solves Nothing

Somewhere in the calendar there’s a recurring appointment. Every autumn, everyone gets a link to the mandatory phishing e-learning. Twenty minutes of video, a short quiz at the end, a certificate by email. Then it goes quiet again for a year. That exact pattern is what makes the training nearly worthless.

Not because the content is poor. Most trainings explain reasonably well what a phishing email looks like and why people fall for it. We covered that in an earlier article. The problem sits in the timing: awareness that gets switched on once a year isn’t behaviour. It’s a checkbox.

Training doesn’t change behaviour, repetition does

People remember what they encounter regularly, not what they saw once. Someone who learns in January what a suspicious link looks like rarely still applies that knowledge automatically in September, especially on a busy Monday morning between twenty other emails. An annual training actually works against you: it gives management the feeling the topic is handled, while behaviour on the work floor has barely shifted.

That’s why we see awareness not as a course, but as an ongoing process. That sounds heavier than it is. Mostly it means measuring, practising and adjusting in smaller, more frequent steps, instead of one big push once a year.

Start with measuring, not training

Most companies get the order wrong. They buy a training tool first and only afterwards work out what they want to achieve with it. We reverse that order. Before you teach anyone anything, you want to know where your organisation actually stands. Does part of the team consistently click suspicious links? Does an unusual payment request just get processed, even when the sender looks off? Do people report doubt, or do they keep it to themselves out of fear of looking foolish?

That baseline measurement gives you a realistic picture instead of a feeling. Only once you know what current behaviour looks like can you determine what genuinely needs to change and where the risks sit. Without that measurement you’re training in the dark, hoping it lands somewhere.

Policy before training, and before enforcement

Training without clear agreements behind it has nothing to hold onto. If employees don’t know exactly what the company expects, for example that a payment request is always verified by phone or that an unknown attachment is never opened without checking, then a training stays abstract knowledge without consequence.

That’s why we set out what’s allowed and what isn’t before we start enforcing or training. That policy doesn’t need to be thick. It needs to be clear and concrete, and it needs to match how work actually happens in your company. A wholesaler with many external suppliers needs different agreements than a manufacturer that mostly communicates internally.

Bring people along before you make something mandatory

Awareness only works when people understand why something is being asked of them. A mandatory training that feels like control triggers resistance. People fill it in to get it over with, not to learn from it.

We believe in the reverse order. First explain why the topic matters and what’s genuinely at stake, for the company and for the colleague personally, then have the conversation about what’s expected from everyone. Enforcement, for example a conversation after a missed report, comes later and then feels logical instead of arbitrary.

What this means for your business

In practice this means that at Motics we start with a picture of the current situation: a controlled phishing test, a conversation with team leads about what they see in daily practice, and a short review of existing policy. From that picture we determine what’s needed. Sometimes that’s a handful of short, recurring exercises through the year instead of one big session. Sometimes it’s mostly about sharpening policy, so people know what’s expected of them.

This also fits how we look at NIS2. Demonstrating that you work on awareness takes more than an e-learning certificate. It takes an ongoing process with measurement points, where you can show what was measured, what policy is based on it, and how employees were brought along.

We think about this in terms of the whole domain around people and behaviour: from measurement to policy to repetition. That works better than a once-a-year checkbox, and it gives you something you can actually steer by as a business owner.

A few questions we’re often asked

How often should you actually run exercises?

There’s no fixed frequency that works for every company. For most SMEs, a combination of a few short, unannounced exercises spread through the year works better than one big session. The frequency follows from what the baseline measurement shows.

Isn’t a phishing test just tricking people?

It can feel that way, but the goal is never to catch someone out. A good test gives insight into patterns within the organisation, not individual blame, and the outcome is used to improve policy and explanation, not to call people out.

What if employees experience training as distrust?

That feeling usually comes from a training imposed without explanation. If you first show why the topic matters and what’s at stake for the business, the experience shifts from control to working together to prevent something.

Can we pick this up separately from a larger ICT project?

You can, but awareness works best as part of a broader picture of how a company handles risk. Standalone actions help, though the effect grows once measurement, policy and technology are aligned.


Curious where your organisation currently stands when it comes to awareness around phishing and social engineering? We’re happy to think along about an approach that fits how work actually happens at your company.

Newsletter

Practical IT insights, once a month

What happened, what it means for your business and one thing you can do today. No sales talk, unsubscribe anytime.

We only use your address for the newsletter. See our privacy statement.

Questions about your own IT?

Take the free scan and see how your own IT is doing, instead of leaving it at general knowledge. Want to talk it through? A no-strings intro call is always an option.

Free and no-strings, no sales pitch.

May we measure what helps you?

Analytical cookies show us which pages help you and which don't, so we can improve the site. No ads, no selling of data. We only place them after your consent. Read our cookie policy.

You can change your choice later via ‘Cookie preferences’ at the bottom of every page.