RUEN
Home/Materials/Employee cybersecurity training
Cybersecurity and continuity

Employee cybersecurity training: what works and what is missing

More than 80% of successful attacks start with a person: an email, a link, a call "from the bank". So companies train staff in cyber hygiene — and rightly so. Here is what works, which platforms exist, and why staff training covers only half of the risk.

Published: 24 July 2026 · Author: Evgeny Telenkov · ≈ 7 min read

Why train employees

Technical defences — antivirus, filters, network segmentation — stop mass threats, but the main attack vector is still human. A phishing email to an accountant, an "urgent" call to the finance team, an infected flash drive — all of it bypasses technology through trust. In cyberattack statistics, social engineering consistently leads among initial vectors. Staff training lowers the odds that an attack starts at all — the first, mandatory layer of cyber defence.

What to teach: the minimum programme

  • Phishing and social engineering. How to spot a fake email, link or call. When in doubt: do not click — report.
  • Passwords and access. A password manager, two-factor authentication, never sharing credentials.
  • Handling data. What must not be sent via messengers and personal email, how to treat personal data (see BCM and data protection).
  • Acting on an incident. The main rule: noticed something odd — report it immediately. A hidden incident costs more than a loud one.

Security awareness platforms: how it is done in practice

For regular staff training the market offers dedicated platforms — Kaspersky ASAP, StopPhish, Phishman, Secure-T, Start X and others. The logic is similar everywhere: short lessons, automated phishing simulations (employees receive "training" phishing emails), and reports for the manager — who clicked, who reported, what the trend looks like. It works: regular simulations cut the share of "clickers" several times over. With 30-50+ employees, a platform almost certainly pays off.

Why it is not enough

Staff training answers the question "how to lower the probability of an attack". But cyber risk has a second half — "what happens when the attack succeeds anyway". And it does: one click by one employee, a fresh zero-day, or an attack through a contractor is enough. At that point staff awareness no longer helps — and the IT department alone does not save the business either.

In a real ransomware case at a large insurer, the company stood still for 7 days. The questions decided in the first hours had nothing to do with staff cyber hygiene: who has the authority to shut systems down? Do we pay the ransom? What do we tell clients and the regulator? How fast can we restore from backups — and do they exist? These are executive-team questions, and they must be answered before the attack, not during it.

The second layer: executive-team readiness

A complete cyber-training scheme looks like this:

  1. Staff — cyber hygiene via an awareness platform: lower the odds of a way in.
  2. The executive team — crisis readiness testing: rehearse the incident itself. Roles, authority, an action plan for a cyberattack, communications, recovery, the cost of a day of downtime.
In practice: for the second layer we run a two-day business continuity stress test — a diagnostic plus a strategic session with a ransomware stress simulation for the management team, ending with a CEO report. An awareness platform teaches staff not to open the door; the stress test prepares the company for the day the door gets opened anyway.

FAQ

Where should employee cybersecurity training start?

With basic cyber hygiene and regular phishing simulations through a security awareness platform. This covers the most common staff mistakes.

Is a security awareness platform enough to protect the business?

No. It lowers the probability of a successful attack through staff, but does not prepare the company for the attack itself. The executive team must know who decides, what to tell clients and how to recover.

How do you test a company's readiness for a cyberattack?

Run readiness testing: a tabletop exercise or a ransomware stress simulation with the management team.

Is your team ready for the first hour of a crisis

Plans are tested by scenarios, not by reading. The assessment shows the gaps, the corporate format works them through with your team on your processes.

Evgeny Telenkov
Evgeny Telenkov
Director, business continuity practice · PhD in Economics · Academic Director & Chief Examiner
Risk Manager of the Year in Russia 2020 (RusRisk). Built business continuity from scratch at Nornickel, more than 20 plans; led risk functions at Beeline, Rosneft and EY. Chief risk officer of a 20 billion dollar petrochemical megaproject. Deputy chair of Rosstandart technical committee 010 "Risk management", co-author of six national standards. Author of the ERGP and SAFE programmes.