Daniel Hyatt
TrainMeUK Founder
Introduction
Picture a Friday afternoon. A finance assistant opens an email from the managing director: a supplier needs paying today, invoice attached, sorry for the short notice. The tone is right. The signature is right. The invoice looks like every other invoice. She pays it.
It wasn't the MD. The supplier account belongs to someone she'll never meet, and by Monday the money is three transfers deep and gone.
Here's the part that should bother you: that assistant had done her annual security training. She passed the quiz. Her certificate was sitting in the system with a green tick next to it. None of it changed what she did when a convincing fake landed in a busy inbox on a day she had forty other things to do.
I've spent my career on the infrastructure side of this, and that scenario isn't rare or far-fetched. It's the most ordinary breach there is — and the numbers say it's happening constantly.
What the numbers say
According to the UK Government's Cyber Security Breaches Survey 2025, 43% of UK businesses reported a cyber breach or attack in the previous 12 months. For larger firms it was nearly 70%. And the weapon, overwhelmingly, was phishing — present in around 88% of the businesses that got hit (DSIT survey, education annex). Not zero-day exploits. Not Hollywood hackers. An email, a moment of trust, a click.
Which raises the obvious question: if nearly everyone runs security training, why does this keep working?
Training changes behaviour — just not the behaviour you think
The most honest answer comes from Verizon, who analysed over 22,000 incidents for their 2025 Data Breach Investigations Report. They measured whether security awareness training actually reduced the rate at which people click on phishing. Their finding, in their own words: the failure rate was unaffected by training. People who'd done the training clicked at roughly the same rate as people who hadn't.
That sounds like an argument for giving up on training. It isn't — and the same report shows why. People trained within the last 30 days were four times more likely to report a suspicious email. So training does change behaviour. The problem is what kind of behaviour the traditional model trains.
Why the dashboard goes green anyway
Because think about what annual, off-the-shelf compliance training actually is. A generic module, the same one sold to a law firm and a logistics depot and a primary school. Watched once a year. Ending in a handful of multiple-choice questions you can answer straight off the previous slide. It was built to be cheap to buy and easy to report — a tidy completion dashboard for the audit file. It was never built to rehearse the one moment that matters: a real person, under real pressure, deciding whether to trust a message that looks completely legitimate.
So the dashboard goes green. Everyone feels covered. And the actual skill — hesitating, checking, reporting — was never practised, because watching a slideshow and recognising the right answer in a quiz is a different thing entirely from spotting the real thing on a bad day.
That gap is quietly widening, too. Among UK businesses that suffered a breach, the share reporting lost revenue jumped from 2% to 5% in a single year, and reputational damage from 1% to 3% (DSIT, 2025/2026). The serious end of the curve is getting heavier. And generative AI now writes a flawless, personalised lure in seconds — the spelling mistakes and clumsy phrasing that used to give phishing away are gone.
What different training looks like
This is the problem I built our approach to solve. Not more training. Different training.
Compliance courses generated around your own policies, your own systems, the actual scams aimed at your sector — so it reads as made for your people, not background noise. Active scenario simulations, including a realistic mock inbox and a Teams-style CEO-fraud test, so your team practises spotting and reporting the real thing instead of recognising a slide. Short, focused modules people actually retain. The whole thing assigned, tracked and reported in one place, with audit-ready records and renewal reminders handled for you. And it's light enough for one person to manage across an entire organisation — you don't need an L&D department to do this properly.
None of this makes anyone un-phishable; the Verizon data is clear that no one is. But it moves the number that counts — it turns "clicked and said nothing" into "hesitated, checked, reported" — and that single shift is often the difference between a near-miss and a Friday-afternoon wire transfer you spend the next year explaining.
Final Takeaway
The certificate proves someone finished a module. It doesn't prove they'll stop when it counts. Those are different things, and only one of them survives a breach — or the conversation with your insurer afterwards.
If your training is a box that gets ticked once a year, it's worth twenty minutes to see what the alternative looks like.
See training built for the Friday-afternoon email
Book a 20-minute walkthrough: your policies, sector-specific threats, and active simulations — mock inbox and Teams-style CEO-fraud scenarios — so your team practises hesitating, checking, and reporting before it counts.
14-day free trial · No credit card · UK-based support
Sources: DSIT Cyber Security Breaches Survey 2025/2026; Verizon 2025 Data Breach Investigations Report.
Related Articles
Phishing Awareness Training for UK Employees
What good security awareness actually covers.
Read More →CEO Fraud Training for UK SMBs
The BEC scenario behind the Friday-afternoon wire transfer.
Read More →Why 100% Completion Still Fails Under Audit
When the green dashboard doesn't match what auditors actually test.
Read More →