Computer Support, Design, Print and Business Telecoms - ABC Service, Tavistock, Devon

How Often Do You Need to Train Employees on Cybersecurity Awareness?

Oct 11, 2023

You’ve completed your annual phishing training. This includes teaching employees how to spot phishing emails. You’re feeling good about it. That is until about 5-6 months later. Your company suffers a costly ransomware infection due to a click on a phishing link.

You wonder why you seem to need to train on the same information every year. But you still suffer from security incidents. The problem is that you’re not training your employees often enough.

People can’t change behaviors if training isn’t reinforced. They can also easily forget what they’ve learned after several months go by.

So, how often is often enough to improve your team’s cybersecurity awareness? It turns out that training every four months is the “sweet spot.” This is when you see more consistent results in your IT security.

Why Is Cybersecurity Awareness Training Each 4-Months Recommended?

So, where does this four-month recommendation come from? There was a study presented at the USENIX SOUPS security conference recently. It looked at users’ ability to detect phishing emails versus training frequency. It looked at training on phishing awareness and IT security.

Employees took phishing identification tests at several different time increments:

  • 4-months
  • 6-months
  • 8-months
  • 10-months
  • 12-months

 

The study found that four months after their training scores were good. Employees were still able to accurately identify and avoid clicking on phishing emails. But after 6-months, their scores started to get worse. Scores continued to decline the more months that passed after their initial training.

To keep employees well prepared, they need training and refreshers on security awareness. This will help them to act as a positive agent in your cybersecurity strategy.

Tips on What & How to Train Employees to Develop a Cybersecure Culture

The gold standard for security awareness training is to develop a cybersecure culture. This is one where everyone is cognizant of the need to protect sensitive data. As well as avoid phishing scams, and keep passwords secured.

This is not the case in most organizations, According to the 2021 Sophos Threat Report. One of the biggest threats to network security is a lack of good security practices.

The report states the following,

“A lack of attention to one or more aspects of basic security hygiene has been found to be at the root cause of many of the most damaging attacks we've investigated.”

Well-trained employees significantly reduce a company’s risk. They reduce the chance of falling victim to any number of different online attacks. To be well-trained doesn’t mean you have to conduct a long day of cybersecurity training. It’s better to mix up the delivery methods.

Here are some examples of engaging ways to train employees on cybersecurity. You can include these in your training plan:

  • Self-service videos that get emailed once per month
  • Team-based roundtable discussions
  • Security “Tip of the Week” in company newsletters or messaging channels
  • Training session given by an IT professional
  • Simulated phishing tests
  • Cybersecurity posters
  • Celebrate Cybersecurity Awareness Month in October

When conducting training, phishing is a big topic to cover, but it’s not the only one. Here are some important topics that you want to include in your mix of awareness training.

People also want to know about Rachael Leah Designs – Your Local Illustrator.

Phishing by Email, Text & Social Media

Email phishing is still the most prevalent form. But SMS phishing (“smishing”) and phishing over social media are both growing. Employees must know what these look like, so they can avoid falling for these sinister scams.

Credential & Password Security

Many businesses have moved most of their data and processes to cloud-based platforms. This has led to a steep increase in credential theft because it’s the easiest way to breach SaaS cloud tools.

Credential theft is now the #1 cause of data breaches globally. This makes it a topic that is critical to address with your team. Discuss the need to keep passwords secure and the use of strong passwords. Also, help them learn tools like a business password manager.

Mobile Device Security

Mobile devices are now used for a large part of the workload in a typical office. They’re handy for reading and replying to an email from anywhere. Most companies will not even consider using software these days if it doesn’t have a great mobile app.

Review security needs for employee devices that access business data and apps. Such as securing the phone with a passcode and keeping it properly updated.

Data Security

Data privacy regulations are something else that has been rising over the years. Most companies have more than one data privacy regulation requiring compliance.

Train employees on proper data handling and security procedures. This reduces the risk you'll fall victim to a data leak or breach that can end up in a costly compliance penalty.

Need Help Keeping Your Team Trained on Cybersecurity?

Take training off your plate and train your team with cybersecurity professionals. We can help you with an engaging training program. One that helps your team change their behaviors to improve cyber hygiene.

Article used with permission from The Technology Press.

OLDER POSTS

5 Hidden Dartmoor Walks for a Mental Reset

At ABC Service, we spend a lot of our time looking at screens. Whether we are fixing a broken laptop screen, managing a complex business network, or designing a new logo, our world is digital. We love what we do, and we love helping our local community in Tavistock...

The Great Scone Debate: Cream or Jam First?

If there is one thing we take as seriously as your IT security or your business broadband, it is the correct way to assemble a cream tea. Living and working in Tavistock, Devon, we find ourselves at the very epicentre of a culinary rivalry that has spanned centuries....

The Hidden Killers of Business Laptops: Thermal Throttling & Bloatware

A laptop does not have to be broken to be a problem. In many SMEs across Devon and Cornwall, the bigger issue isn't a dead screen or a snapped hinge: it’s a machine that still turns on but takes an age to boot, sounds like it’s about to take off, and slows to a...

From Pixels to Paper: Why Digital-First Brands are Flocking Back to Professional Print

It’s Sunday, 5th April 2026. If you’re like the average UK adult, you’ve probably spent a significant portion of today squinting at a screen. In fact, latest data suggests that Gen Z is now clocking nearly nine hours of screen time daily. We’ve reached "peak...

1991: The Year the World Wide Web Went Public

If you step into the ABC Service office and ask our Director, Brett, what his favourite year is, he might be a little biased. While some people remember 1991 for Nirvana’s Nevermind or the release of the Super Nintendo in the UK, Brett remembers it for a slightly more...

AI vs. Humanity: Can a Machine Ever Have a ‘Gut Feeling’?

We’ve all been there. You’re sitting in a meeting, the data in front of you looks perfect, the spreadsheets are glowing green, and every logic-driven part of your brain says "Yes." But then, there’s that little twitch in your stomach. A tiny, nagging whisper...

Agentic AI: Is Your Office Starting to Think for Itself?

If you feel like you’ve only just got your head around ChatGPT, we’ve got some news for you. The tech world has already moved on. While we were all busy teaching AI how to write polite emails or generate pictures of cats in space, a new player entered the office:...

Stand Out on the High Street: Essential Large-Format Printing for Retailers

Let’s be honest: the British high street is a battlefield. Between the drizzle, the smartphones, and the sheer volume of shops vying for attention, getting a customer to actually stop and look at your window is no small feat. You could stand outside in a giant...

The ‘Non-Corporate’ Guide to Professional Printing

Plenty of suppliers promise convenience. Fewer offer the kind of support that actually helps when something goes wrong. For growing businesses, that difference matters. When you need advice, a quick fix, or someone who genuinely understands the job in front of them,...

Why DMARC Matters: The Web Hosting Secret for UK Small Businesses to Beat Spam Filters

Have you ever sent a crucial invoice or a time-sensitive quote to a client, only to find out three days later that it’s been languishing in their spam folder? Or worse, that it was rejected by their server entirely? It’s an incredibly frustrating experience. You’ve...