Is Security Awareness Training Actually Worth It for a Small Business?

Is Security Awareness Training Actually Worth It for a Small Business?

· by IDE Solutions

Most owners assume they have this covered. Everyone watched a fifteen-minute video during onboarding, there was a quiz at the end, and IT ticked a box. That is not security awareness training, and the gap between what most small businesses do and what actually changes behavior is bigger than most owners realize.

The clearest evidence for that gap comes from KnowBe4's 2026 Phishing by Industry Benchmarking Report, built from 42 million simulated phishing tests across 64,000 organizations. Employees with no ongoing training clicked a simulated phishing link 33.2 percent of the time, roughly one in three. After twelve months of continuous, structured training, that fell to 4.2 percent, an 87 percent reduction. The one-off video is not what produced that number. Continuous, repeated exposure is, and that distinction is the entire question this article answers.

Why the annual video does not stick

People forget what they do not use. A training video watched once in January, with no follow-up, competes against a year of actual email traffic, and by the time a real phishing message arrives in October, the specific advice from that video is gone even if the general idea of "be careful" survives. This is not a discipline problem. It is how memory works for anything learned passively and never practiced again.

It also is not a technology problem your spam filter can fully solve. Verizon's 2026 Data Breach Investigations Report found the human element involved in 62 percent of breaches globally, meaning someone clicked, typed a password into the wrong page, or approved a request that should have raised a question. Filters, Microsoft 365 security hardening, and multi-factor authentication all reduce how much lands in front of a person. None of them reduce it to zero, and the remaining fraction is where training earns its cost.

What actually moves the click rate

The KnowBe4 data breaks down by cadence, and the pattern is consistent: training that repeats on a schedule, paired with simulated phishing sent throughout the year rather than a single test, produces the improvement. A single test with no follow-up barely moves the baseline. Monthly or quarterly simulations, each followed by short, specific feedback when someone clicks, does. The mechanism is closer to muscle memory than classroom learning. Staff get better at spotting a suspicious link because they see enough of them, close together, with immediate correction when they miss one.

This matters more for certain roles than others. Anyone who approves payments, changes bank details, or has access to payroll is a higher-value target, and campaigns exploiting exactly that access are active right now. We covered one such attack reading payroll mailboxes for weeks despite MFA being enabled. Training will not stop a technically sophisticated proxy attack on its own, but a finance employee who has practiced spotting the setup, an unexpected voicemail link, an urgent request to change a payment detail, is far less likely to be the entry point in the first place.

Comparing the three approaches a small business actually chooses between

Approach What it looks like Realistic effect
Annual video, no follow-upOne session at onboarding or once a year, quiz at the endClose to the 33 percent untrained baseline within a few months
Self-run monthly simulationsIT sends test phishing emails and tracks who clicks, in-houseMeaningful improvement, but needs someone accountable for running it every month without skipping
Managed security awareness programOngoing simulations, targeted follow-up training, and reporting handled by a providerConsistent cadence without relying on an internal owner remembering to send it

The failure mode in the middle row is common and predictable: someone in the office is nominally responsible for sending monthly test emails, it works well for two months, then a busy quarter arrives and it quietly stops. The value of training is almost entirely in the consistency, so a program that depends on one person remembering is fragile in exactly the way that matters.

The tool most Microsoft 365 businesses already have and are not using

If your business runs Microsoft 365 Business Premium or an E5 plan, Attack Simulation Training is included in Microsoft Defender for Office 365, and most small businesses paying for it have never turned it on. It lets an administrator send realistic phishing, credential harvest, and attachment simulations to staff, then automatically assigns short training modules to anyone who clicks, with reporting on who improved and who did not over time. It does not fully replace a dedicated awareness program, but for a 10 to 50 person company it is a genuinely useful starting point that is already paid for, not an extra line item.

The gap is usually not the license. It is that nobody in a small company has the time to configure the simulation schedule, write the follow-up content, and review who needs a second nudge, on top of everything else IT already handles. That is the part a managed cloud security arrangement is built to absorb: someone else owns the calendar, not just the license.

Where this intersects with compliance, not just risk

For businesses in scope for NIS2 or working under a customer's supply-chain security requirements, staff awareness is not optional best practice, it is an expected part of demonstrating basic cyber hygiene. An auditor or a customer's procurement team asking "how do you train staff on phishing" wants a specific, repeatable answer, not "we mention it when someone starts." That documentation burden is one more reason a structured, dated program is worth more than an informal one, and it is the kind of gap our governance and compliance work is built to close alongside the technical controls.

What it realistically costs a small company

For a 20-person business, a managed awareness program typically runs a few euros per user per month, well under the cost of a single afternoon lost to a compromised mailbox, let alone a wire transfer sent to the wrong account. The time cost to staff is small too: a well-run program keeps individual training modules under five minutes, triggered only for people who need the reminder rather than the whole company sitting through the same session on a fixed schedule. The real cost is not the training itself. It is the twenty minutes a month someone has to spend making sure it actually happened, which is exactly the piece that quietly stops happening without an owner.

A useful way to decide whether your business needs to change anything: if you cannot say when the last simulated phishing test went out, or who clicked it, the answer is close to certain. The fix does not require replacing what you have. It requires making the cadence someone's actual job, whether that person is internal or a provider.

What a first month actually looks like

Businesses that get this right usually start smaller than they expect to. A realistic first step is one baseline simulation to every employee, unannounced, to establish where the click rate actually sits today rather than where the owner assumes it sits. The result is often uncomfortable and always useful, because it turns "we should probably do something about phishing" into a specific number with names attached to who needs the follow-up training first.

From there, the cadence matters more than the content. A short simulation every three to four weeks, each one slightly different in theme, an invoice request, a shipping notification, a fake internal IT message, keeps the skill current instead of letting staff learn to recognize one specific template. Anyone who clicks gets a two-to-five-minute module assigned automatically, not a scolding email from a manager, which is both more effective and less likely to make people afraid to report a mistake later.

Common questions

Do we need this if we already have strong email filtering?

Filtering and Attack Simulation Training solve different halves of the same problem. A filter stops most malicious mail before anyone sees it, but nothing catches everything, and the messages that slip through are usually the ones built specifically to look legitimate. Training is what determines what happens in the moment one of those reaches an inbox.

How often should simulations actually go out?

Monthly is the pattern behind the strongest results in the KnowBe4 data. Quarterly is better than nothing but noticeably weaker, since the gap between tests gives the forgetting curve more room to work. Weekly tends to cause fatigue and lower engagement with the follow-up training, so more is not automatically better.

What size company is this worth setting up for?

The break-even point is low. Even a ten-person company has enough financial exposure from a single successful business email compromise to justify a program costing a few euros per user per month, and the administrative overhead of running it is the same whether five people or fifty are enrolled.

We run the training calendar so you do not have to

Our cloud security service sets up and runs ongoing phishing simulation and awareness training using the tools already included in your Microsoft 365 subscription where possible, with clear monthly reporting on who clicked and who improved.

If you also need this documented for NIS2 or a customer audit, our governance work covers that alongside the technical setup.

More Articles