An employee receives a message apparently from IT support. Her account needs an urgent check or it will be suspended. The link leads to a familiar-looking sign-in page. She hesitates: is the request genuine, and who can she ask for a quick answer?
This fictional example shows what security awareness needs to achieve. Employees need understandable criteria, an accessible contact and confidence that questions are welcome. Training is effective when it makes these everyday decisions easier.
A timely opportunity: Cybersecurity Month 2026
The European Cybersecurity Month in October is an opportunity to review your approach. In its statement of 30 September 2026, ENISA refers to an EU survey: 74 per cent of respondents reported receiving suspicious emails, text or voice messages, or links. Only 45 per cent said their organisation regularly sends cybersecurity information or awareness updates.
These self-reported figures describe experiences and perceptions, not the proportion of successful attacks. They do, however, show how often employees need to judge suspicious situations. This is a useful reason to consider training, reporting channels and practical support together.
1. Recognise suspicious situations and verify independently
Good exercises relate to real tasks: changed bank details in accounts, an unexpected file-sharing invitation in a project, or a call requesting account access. This makes clear which decisions deserve particular care in each role.
Time pressure, unusual payment arrangements, unexpected sign-in requests and requests for passwords or verification codes are reasons to pause. Correct spelling, a familiar logo or a known display name do not establish authenticity.
The key action should be easy: verify unusual requests through a known, independent contact method, such as the support number in your internal directory. A number or link in the suspicious message itself does not provide that independence. Changes to payment details should follow an agreed verification and approval procedure.
2. Make reporting as easy as possible
Someone with a concern should not need to search through a policy. A familiar reporting button, central contact or easy-to-find telephone number lowers the barrier. The channel needs a defined handling process: who receives reports, who provides cover and when is escalation needed?
Employees do not have to prove an attack. A short description is enough to start: what looked unusual, when did it happen, and was a link opened, a file run or information entered? Suspicious content should reach the responsible team through the agreed process rather than being forwarded around the organisation as a warning.
Feedback completes the process. Knowing that a report has arrived and is being reviewed helps employees understand what happens next. A message that proves harmless may still have been a reasonable cause for concern.
3. After a mistaken click, prompt support matters
Even attentive people make mistakes. Every training session should answer: “What should I do if I have already clicked?” The initial guidance is to stop the suspicious activity and promptly inform the responsible team through the agreed contact method.
An honest description helps: was a page merely opened, were credentials entered, or was a program started? This affects the IT response. Employees should follow the organisation’s procedures and specialist instructions rather than attempt their own clean-up.
Managers shape the culture through their response. Calm handling and practical help encourage early reporting. Blame and public embarrassment can lose valuable time. Subsequent review should identify technical and organisational improvements.
4. Connect short exercises to everyday work
Annual training can establish the foundations. Short learning activities can reinforce them: discussing an example, practising the reporting process or explaining a changed procedure. New employees should learn these arrangements during induction.
Content should suit the work. Accounts, executive support, HR and IT encounter different requests. Managers also need to understand which incident decisions are theirs and how to support the response.
Simulated phishing messages can create learning opportunities. They need clear objectives, agreed arrangements and helpful feedback. Personal rankings or unexpected public embarrassment are inappropriate. Technical safeguards, including secure authentication, restricted privileges and email filtering, remain necessary alongside awareness work.
5. Assess effectiveness through the response
Attendance records show who completed training. To understand its practical effect, also examine the process: do employees know whom to contact? Are reports timely and informative? Do cover arrangements and feedback work?
An increase in reports can initially be positive because concerns are being raised earlier. A single simulation click rate is difficult to interpret: difficulty, audience and design all influence it. Several observations over time, preferably at an aggregated level, provide a more useful picture.
Five questions about your awareness practice
- Do employees know an easy reporting channel and an alternative if it is unavailable?
- Do they know how to verify unusual requests independently?
- Is the response after a mistaken click clear and practised?
- Do training examples reflect the audience’s actual work?
- Are reports and exercises used to improve processes and safeguards?
A short review of these questions with IT, managers and employees can reveal concrete improvements. A useful first step is to rehearse the reporting channel and discuss a relevant everyday scenario.
SITsolutions helps organisations explain information security clearly and connect it to operational processes. Our training addresses typical decisions and leaves room for practical questions.
Source and context
Current context and survey figures: ENISA: “Cybersecurity Month @ work: Employees’ skills under the looking glass”, 30 September 2026. The recommendations are practical implementation guidance. The opening example is fictional.