Home · Blog
Security Operations

Security awareness in an SME: why the annual training changes little

28 September 2026 · 8 min read · ODCUS
An employee at a desk pauses over a suspicious supplier email and reaches for the phone while a colleague nods in confirmation

The annual training was ticked off, the completion rate in the learning system was green, and six weeks later accounts payable paid a five-figure invoice into a new bank account. The supplier's email looked like an email from the supplier. This is the point where security awareness in an SME either changes behaviour or just produces a number.

Knowledge was not the problem. The employee knew that fraudulent emails exist. She did not know that she had one in front of her, she had no two minutes of slack in which to doubt it, and she had no route that would have made doubting it cheap. Awareness programmes train knowledge. What is needed is a reflex inside the flow of work, plus somebody who answers when the reflex fires.

TLDR

Security awareness in an SME rarely fails on what the workforce knows. It fails on the working day: time pressure, unclear processes and a reporting route that feels more expensive than a quick click. It starts working when two things are true. At the few points where money or data leave your company, doubt is allowed and costs nobody time or standing. And reporting is rewarded faster than a mistake is punished. The number that matters is the reporting rate, not the click rate.

Why the annual training changes so little

The mandatory module is not badly made. It is built for a different job. An e-learning course with a completion rate produces evidence, and that evidence is needed: in customer audits, in ISO 27001 certification, in the questionnaire from a large client. Many companies simply mistake the evidence for the effect.

In our experience the reasons rarely sit with the workforce. They sit in the design:

On top of that sits a quiet overload. The training is often the only thing a company does on the human side at all. It is then expected to compensate for process gaps, missing four-eyes rules and a culture in which mistakes are uncomfortable. No module can carry that.

What security awareness has to deliver to work

A programme that works builds three unspectacular capabilities into daily operations.

Recognition at the points that matter in your company. Not phishing in general, but the handful of situations in which money or access leaves your company: a changed bank account, a login prompt outside the usual route, pressure from above combined with urgency, a data request with no history. Anyone who can name those situations does not need a threat catalogue.

A reporting route that is cheaper than guessing. One address, no form, no justification, an answer on the same working day. As long as reporting means more effort and more risk to your own standing than a quick decision when in doubt, the decision gets made in doubt. That is not a question of character, it is the economics of work.

A response that rewards reporting. The first answer is a thank you, false alarms included. Especially false alarms. BACS, the Swiss Federal Office for Cybersecurity, lists caution with email among its baseline measures for companies and public bodies. Caution does not come from being told off. It comes from caution never having been embarrassing.

The reflex is the same one as with tooling: more protection does not come from more training hours, it comes from fewer and better placed ones. Two short, concrete interventions a year at the points where money moves in your company change more than a forty-minute module for everybody. And they cost less.

What does security awareness cost in an SME?

The licence is the small part. The large part is working time. At 250 employees and 45 minutes of mandatory training, that is roughly 190 working hours a year before anything else happens. Add the internal effort of collecting the last twenty people who have not finished. This line item appears in no security budget and the company pays it anyway.

That is why the sizing question here is a question of money rather than taste. A platform at a per-user annual price barely registers in an SME. The hours register as soon as somebody writes them down. Once they are on paper, the better question asks itself: which minutes change behaviour, and which only produce a record? How to make the cost of security visible at all is covered in our post on the security budget in an SME.

The comparison that lands in management meetings is a dry one. A callback to the number held in the ERP costs two minutes. A payment into a stranger's account costs the amount, the legal fees and weeks of nerves. Awareness at this point is a process decision with a security benefit.

When is a phishing simulation worth it?

A phishing simulation is worth running as soon as there is a reporting route and somebody who answers reports. Before that it produces a list of names and a bad feeling. The simulation does not measure how alert your people are. It measures whether your reporting process works and how long it takes.

The useful numbers are therefore different from the usual ones:

Instead ofBetterBecause
Click rateReporting rateClicking is hard to prevent. Reporting can be learned.
Training completion rateTime to first reportIn a real incident the first quarter of an hour decides, not course progress.
Names of those who clickedClustering by team and processRepeated hits in one team are usually a process problem, not a people problem.

The click rate also has a built-in flaw. It can be steered through the difficulty of the test email. Anyone who needs a good number gets a good number. The reporting rate cannot be dressed up, it hangs on behaviour and on the reporting route.

BACS received 27'128 voluntary reports in the first half of 2026, plus 200 cyber incidents under the mandatory reporting duty (BACS semi-annual report 2026/1). Voluntary reports exist because somebody noticed something and opened their mouth. That is exactly the capability an awareness programme is supposed to build inside your own company. Everything else is decoration.

One thing here is not up for negotiation: no lists of names to the management team, no leaderboard on the intranet. Anyone who has been shown up once reports nothing for a year, and everybody in the room noticed. That is the most expensive part of a badly run simulation.

What this looks like in practice

An industrial company with around 220 employees, three sites, two people in IT. Awareness consisted of an e-learning module during onboarding and an email from the head of IT after every incident. After the case with the changed account number we did not refresh the training. We changed this instead:

Six months later, considerably more suspected cases were coming in than before. On paper that looks like more problems, in operations it is the opposite. The cases are now seen while they are still harmless. Payment-related emails run through the callback. We never measured the click rate in that mandate.

Who owns awareness in the company?

IT alone cannot carry awareness. It can build the reporting route and assess suspected cases. It cannot decide that a payment may wait, and it cannot tell line managers how to react to mistakes. In practice awareness has more than one owner. The management team sets the tone and makes its own mistake the example. HR anchors the topic in onboarding and in the calendar. Security leadership owns the content, the reporting route and the measurement.

When the topic belongs to nobody, it ends up as the mandatory module. That is in the nature of the thing: you can commission a module, you cannot commission a change in behaviour. This is why awareness sits inside our scope of work rather than in an extra quote. What each package contains is set out in the overview of packages and fixed prices.

The evidence is still needed. Customer audits and ISO 27001 ask about training, attendance and how current it is. Both are achievable, they are simply not the same thing. A programme built only for the evidence passes the audit and changes nothing. A programme that only changes behaviour turns up to the audit empty-handed. Kept apart cleanly, both can be planned on purpose instead of hoping that one takes care of the other.

Frequently asked questions

How often should we run awareness training?

The question of frequency leads nowhere useful. For the evidence, most certifications are satisfied with one documented session a year plus onboarding. For the effect, what counts is that the relevant roles get short, concrete refreshers where they make decisions: finance, procurement, assistants, IT. Four targeted quarter-hours a year beat one long module that treats everybody the same.

Is a training platform enough, or does it take more?

A platform delivers content, assignment and evidence, and it does so reliably. It does not own the reporting route, it changes no approval processes, and it cannot make a line manager react calmly to a mistake. Those are the parts where awareness works or does not. The platform is the tool. The programme stays work inside the company.

What if somebody clicks anyway?

We assume they will. Sooner or later somebody clicks, even in an alert organisation. The useful question is how fast somebody notices and who then decides what. Those decisions belong before the incident, not inside it. What that looks like for an SME is covered in our post on an incident response plan for your SME.

If you are not sure whether your awareness programme changes behaviour or only produces evidence, there is one honest indicator: the number of suspected cases reported in the last three months. If it sits at zero, that does not mean nothing happened.

Not sure whether a fractional CISO fits your company?

In a free intro call we work out whether senior security leadership on a mandate makes sense for your company, and in what form. Honest answer included, even when it is "not yet".

Book a free intro call