What it means
An employee receives an invoice with changed bank details and a familiar-looking sender name, and training can prompt the employee to verify the change through an established contact route instead of replying to the email. The organisation also needs a process that makes the safe choice practical.
NIST describes building a cybersecurity and privacy learning program, while CISA gives phishing recognition and reporting guidance, but these are broad frameworks and local policy and the actual threats a team faces should shape the lessons. Begin with work tasks and likely risks, since finance, customer support and developers may face different attack patterns.
Teach people to verify sensitive requests using a known channel, because a display name or urgent tone does not establish identity, and show how to report a suspicious message, misplaced file or accidental click quickly and without blame. Explain what information may be shared, stored or entered into external tools, using examples from real workflows and accessible language so staff can apply the rule, not merely repeat a term from a slide.
Cover account security, such as strong unique passwords and approved multifactor authentication practices, and do not teach staff to enter one-time codes into an unexpected page or give them to a caller who claims to be support. Include physical and remote-work risks where relevant, such as lost devices, public networks and visible screens.
Keep lessons short and repeated at useful moments, because a long annual course can be forgotten before a real incident, and update examples and processes as attackers change tactics. Practice with examples that resemble the team's actual work without exposing private customer data in training material.
Simulated phishing can reveal where guidance needs work, but design it fairly because public shaming can discourage reporting, and if an exercise uses deception, review privacy and employment policies so the goal is learning, not catching people out. A click rate alone is a poor measure of security culture, so look at timely reporting and whether the response process works.
Give managers and executives relevant training too, since senior staff often approve high-value payments and sensitive access, and give new hires guidance before they receive broad access, with contractors and vendors covered under their agreements where suitable. Make reporting easy from the tools employees already use, because a complicated ticket process can delay a useful warning.
Tell staff what happens after they report, review false alarms positively and share anonymised lessons from real incidents without disclosing victim or customer details unnecessarily, since feedback builds confidence and helps people learn. Coordinate with technical safeguards, because email filtering, access limits and payment controls should not be replaced by advice to "be careful", and test whether procedures can be followed under time pressure, since a bank-change check that takes days may be ignored during urgent work.
Track course completion for coverage but assess behaviour and process outcomes separately, because 180 completed assignments among 200 assigned staff gives 90 percent completion, which says nothing by itself about incident readiness. Keep ownership clear, with security updating the programme, managers making time for it and staff knowing how to ask questions, and remember that a resilient organisation expects errors and limits their impact, so good training helps people pause, verify and report while the business supports them with workable controls.
In practice
Real-world examples.
Example
A finance employee receives an email asking to change a supplier's bank details. Instead of replying, she calls the vendor on the number already held in the accounts system and confirms the request is false. The payment is never changed, and she reports the message through the internal route.
Example
A new hire accidentally shares a customer file with the wrong external contact. Because her induction showed her exactly where to report, she tells the security team within minutes and is thanked for it. The business can recall the file and notify the customer before harm spreads.
Example
A company runs a simulated phishing exercise and finds that few staff report the message even though most do not click. It reviews the reporting route, shortens the process and gives feedback to staff who reported. The next exercise is judged on reporting time as well as clicks.
Formula
Calculation
Training completion = staff who completed assigned training / staff assigned training x 100. It measures coverage, not proof of secure behaviour.
Worked example: 180 of 200 assigned staff complete the course, so completion is 180 / 200 x 100 = 90%. A better companion measure is the share of simulated suspicious messages that staff report: if 60 of 200 staff report a test message within an hour, that is 60 / 200 x 100 = 30% reporting promptly. The two figures together show coverage and behaviour, and neither proves the organisation is secure.Case study
Seen in the real world.
In this fictional case, Willow Finance received several fake invoice messages. It made vendor-change verification clearer, trained staff with relevant examples and checked reporting speed alongside technical filters. The case is invented and does not claim attacks were eliminated. The company also gave its payment approvers a short monthly refresher built from real examples it had received.
Managers were told to protect time for the sessions, and staff were thanked when they reported a message that turned out to be harmless. After six months Willow compared reporting time and the number of unverified bank-change requests, not just course completion. The figures showed faster reports and fewer unchecked changes, while the team kept its email filtering and payment approvals in place.
Watch out
Common mistakes.
- Using quiz completion as proof the organisation is secure.
- Shaming staff after a simulation instead of improving the reporting route.
- Relying on training without access and payment controls.
Questions
People also ask.
Is one annual course enough?
Usually not; repeat role-relevant guidance and update it as risks change.
Should staff report a mistaken click?
Yes, promptly through the established internal route without hiding it.
Do phishing simulations prove readiness?
No. They are one learning signal alongside reporting and technical controls.
From the founder's library

Take it further with the book.
Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.
25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.
View the book and save 25%