All professional firms
Security awareness training that people don't ignore
· PS ProTech · 3 min read
Once a year, everyone at the firm clicks through a forty-minute video about passwords, answers ten questions and forgets all of it by lunch. That's what security training means at most firms, and it's why people assume it doesn't work.
Done differently, it's one of the cheapest protections you can buy.
Why it still matters
Filters and security software stop most attacks. The ones that get through are the ones built to look like normal work: a message from a client, a request from a partner, a call from someone who sounds right. At that point the only control left is the person reading it.
AI has made those messages far more convincing, as we describe in how AI changed phishing. The goal of training is no longer to teach people to spot bad spelling. It's to teach them which requests deserve a second look.
What works
Short and often. Five to ten minutes every month or two beats an hour once a year. People remember what they met recently.
About their real work. A bookkeeper needs to know about changed bank details. A paralegal needs to know about fake court notices and document links. Generic examples get ignored.
Practice, not only instruction. Simulated phishing sends staff realistic but harmless test emails. Someone who clicks sees a short explanation of what they missed, at the moment it means something.
A way to report. One click to say "this looks wrong." Reporting is the behavior you want most. A firm where people report quickly finds an attack while it's still one email.
No blame. If staff are embarrassed or punished for clicking, they stop telling you when they have. The person who says "I think I just clicked something" at 9:05 is worth far more than the one who hopes it's fine.
What to cover
A small firm needs a short list, repeated:
- Requests to move money or change payment details, and the call-back rule.
- Links that ask you to sign in.
- Voices and video can be faked.
- Approving a sign-in prompt you didn't trigger. See multi-factor authentication.
- What not to paste into AI tools. See a policy for staff using AI tools.
- What to do when something goes wrong, and who to tell.
Include the partners
Senior people are the most targeted and the most often excused. They have the most access, they authorize payments, and theirs are the names attackers use. A program that exempts them covers everyone except the people who matter most.
Keep the records
You'll be asked to prove it happened. Clients' security questionnaires and cyber insurers both want to know whether you train staff and test them. Keep:
- Who completed each session, and when.
- Results of simulated phishing over time.
- New starters' training dates.
That turns training from a cost into evidence. We cover what insurers look for in what cyber insurers ask.
How to tell it's working
Look at two numbers over a year:
- The share of staff who click on test emails should fall.
- The share who report them should rise.
The second matters more. A firm will never get clicks to zero, but a firm where half the staff report a suspicious email within minutes is hard to attack.
Phishing simulations and security training are included from our Business plan. See security awareness training, or price it in the plan builder.
