TrainMeUK LogoTrainMeUK
Home
How It Works
Product
Reports
Pricing
Resources
Login

Summer sale

Limited time

15% off monthly · +20% annual

15%off monthly+20%off annual
Claim offer
HomeResourcesYour Team Passed the Training. The Money Still Left the Building.
Back to Resources
Insights
6 min read
18 June 2026

Your Team Passed the Training. The Money Still Left the Building.

43% of UK businesses reported a cyber breach or attack in the previous 12 months. Why compliance training rarely stops phishing — and what actually changes how your people behave.

In this guide7 sections
  • Introduction
  • What the numbers say
  • Training changes behaviour — just not the behaviour you think
  • Why the dashboard goes green anyway
  • What different training looks like
  • Final Takeaway
  • Related Articles

In this guide

Progress0%
  • Introduction
  • What the numbers say
  • Training changes behaviour — just not the behaviour you think
  • Why the dashboard goes green anyway
  • What different training looks like
  • Final Takeaway
  • Related Articles
Daniel Hyatt, Founder of TrainMeUK

Daniel Hyatt

TrainMeUK Founder

Your team passed the training. The money still left the building.

Introduction

Picture a Friday afternoon. A finance assistant opens an email from the managing director: a supplier needs paying today, invoice attached, sorry for the short notice. The tone is right. The signature is right. The invoice looks like every other invoice. She pays it.

It wasn't the MD. The supplier account belongs to someone she'll never meet, and by Monday the money is three transfers deep and gone.

Here's the part that should bother you: that assistant had done her annual security training. She passed the quiz. Her certificate was sitting in the system with a green tick next to it. None of it changed what she did when a convincing fake landed in a busy inbox on a day she had forty other things to do.

I've spent my career on the infrastructure side of this, and that scenario isn't rare or far-fetched. It's the most ordinary breach there is — and the numbers say it's happening constantly.

Office worker reviewing an email on a laptop — the ordinary moment when a convincing fake can slip through

What the numbers say

According to the UK Government's Cyber Security Breaches Survey 2025, 43% of UK businesses reported a cyber breach or attack in the previous 12 months. For larger firms it was nearly 70%. And the weapon, overwhelmingly, was phishing — present in around 88% of the businesses that got hit (DSIT survey, education annex). Not zero-day exploits. Not Hollywood hackers. An email, a moment of trust, a click.

Which raises the obvious question: if nearly everyone runs security training, why does this keep working?

Training changes behaviour — just not the behaviour you think

The most honest answer comes from Verizon, who analysed over 22,000 incidents for their 2025 Data Breach Investigations Report. They measured whether security awareness training actually reduced the rate at which people click on phishing. Their finding, in their own words: the failure rate was unaffected by training. People who'd done the training clicked at roughly the same rate as people who hadn't.

That sounds like an argument for giving up on training. It isn't — and the same report shows why. People trained within the last 30 days were four times more likely to report a suspicious email. So training does change behaviour. The problem is what kind of behaviour the traditional model trains.

Why the dashboard goes green anyway

Because think about what annual, off-the-shelf compliance training actually is. A generic module, the same one sold to a law firm and a logistics depot and a primary school. Watched once a year. Ending in a handful of multiple-choice questions you can answer straight off the previous slide. It was built to be cheap to buy and easy to report — a tidy completion dashboard for the audit file. It was never built to rehearse the one moment that matters: a real person, under real pressure, deciding whether to trust a message that looks completely legitimate.

So the dashboard goes green. Everyone feels covered. And the actual skill — hesitating, checking, reporting — was never practised, because watching a slideshow and recognising the right answer in a quiz is a different thing entirely from spotting the real thing on a bad day.

That gap is quietly widening, too. Among UK businesses that suffered a breach, the share reporting lost revenue jumped from 2% to 5% in a single year, and reputational damage from 1% to 3% (DSIT, 2025/2026). The serious end of the curve is getting heavier. And generative AI now writes a flawless, personalised lure in seconds — the spelling mistakes and clumsy phrasing that used to give phishing away are gone.

What different training looks like

This is the problem I built our approach to solve. Not more training. Different training.

Compliance courses generated around your own policies, your own systems, the actual scams aimed at your sector — so it reads as made for your people, not background noise. Active scenario simulations, including a realistic mock inbox and a Teams-style CEO-fraud test, so your team practises spotting and reporting the real thing instead of recognising a slide. Short, focused modules people actually retain. The whole thing assigned, tracked and reported in one place, with audit-ready records and renewal reminders handled for you. And it's light enough for one person to manage across an entire organisation — you don't need an L&D department to do this properly.

None of this makes anyone un-phishable; the Verizon data is clear that no one is. But it moves the number that counts — it turns "clicked and said nothing" into "hesitated, checked, reported" — and that single shift is often the difference between a near-miss and a Friday-afternoon wire transfer you spend the next year explaining.

Final Takeaway

The certificate proves someone finished a module. It doesn't prove they'll stop when it counts. Those are different things, and only one of them survives a breach — or the conversation with your insurer afterwards.

If your training is a box that gets ticked once a year, it's worth twenty minutes to see what the alternative looks like.

See training built for the Friday-afternoon email

Book a 20-minute walkthrough: your policies, sector-specific threats, and active simulations — mock inbox and Teams-style CEO-fraud scenarios — so your team practises hesitating, checking, and reporting before it counts.

Book a Free Demo Start Free Trial

14-day free trial · No credit card · UK-based support

Sources: DSIT Cyber Security Breaches Survey 2025/2026; Verizon 2025 Data Breach Investigations Report.

Related Articles

Phishing Awareness Training for UK Employees

What good security awareness actually covers.

Read More →

CEO Fraud Training for UK SMBs

The BEC scenario behind the Friday-afternoon wire transfer.

Read More →

Why 100% Completion Still Fails Under Audit

When the green dashboard doesn't match what auditors actually test.

Read More →

Want audit-ready reporting without spreadsheets?

Make your compliance evidence stand on its own - even under time pressure.

See how UK organisations approach this decision →
Previous Article

Why Words and Visuals Beat Words Alone (Dual Coding)

Dual coding explains why words and pictures together beat words alone — and why "just add an image" usually backfires. An evidence-based guide for workplace training.

Insights13 min read
Next Article

LMS vs LXP: What UK SMBs Actually Need in 2025

A straightforward guide for small businesses choosing between learning platforms. Understand the difference between LMS and LXP, and discover which system solves the problems UK SMBs actually face.

12 min readInsights
TrainMeUK LogoTrainMeUK Ltd

Connect Azure once. TrainMeUK handles reminders, Teams nudges, certificates, and audit-proof reports — automatically.

hello@trainmeuk.co.uk
+44 1252 929213
8 George Myers Close, Ash, Guildford, Surrey, GU12 6FW

Quick Links

  • Home
  • How It Works
  • Product
  • Reports
  • Pricing
  • Resources
  • Knowledge Base

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Data Processing Addendum
  • Subprocessors
  • Acceptable Use Policy
  • FAQ

Popular Resources

Mandatory Training Requirements for UK BusinessesHow Often GDPR Training Should Be Done in the UKHow Fast You Should Produce Training Records for Auditors

© 2026 TrainMeUK Ltd. All rights reserved.

CPD Accredited Provider