Cybersecurity and continuity

Employee cybersecurity training: what works and what is missing

More than 80% of successful attacks start with a person: an email, a link, a call "from the bank". So companies train staff in cyber hygiene — and rightly so. Here is what works, which platforms exist, and why staff training covers only half of the risk.

Published: 24 July 2026 · Author: Evgeny Telenkov · ≈ 7 min read

Why train employees

Technical defences — antivirus, filters, network segmentation — stop mass threats, but the main attack vector is still human. A phishing email to an accountant, an "urgent" call to the finance team, an infected flash drive — all of it bypasses technology through trust. In cyberattack statistics, social engineering consistently leads among initial vectors. Staff training lowers the odds that an attack starts at all — the first, mandatory layer of cyber defence.

What to teach: the minimum programme

Security awareness platforms: how it is done in practice

For regular staff training the market offers dedicated platforms — Kaspersky ASAP, StopPhish, Phishman, Secure-T, Start X and others. The logic is similar everywhere: short lessons, automated phishing simulations (employees receive "training" phishing emails), and reports for the manager — who clicked, who reported, what the trend looks like. It works: regular simulations cut the share of "clickers" several times over. With 30-50+ employees, a platform almost certainly pays off.

Why it is not enough

Staff training answers the question "how to lower the probability of an attack". But cyber risk has a second half — "what happens when the attack succeeds anyway". And it does: one click by one employee, a fresh zero-day, or an attack through a contractor is enough. At that point staff awareness no longer helps — and the IT department alone does not save the business either.

In a real ransomware case at a large insurer, the company stood still for 7 days. The questions decided in the first hours had nothing to do with staff cyber hygiene: who has the authority to shut systems down? Do we pay the ransom? What do we tell clients and the regulator? How fast can we restore from backups — and do they exist? These are executive-team questions, and they must be answered before the attack, not during it.

The second layer: executive-team readiness

A complete cyber-training scheme looks like this:

  1. Staff — cyber hygiene via an awareness platform: lower the odds of a way in.
  2. The executive team — crisis readiness testing: rehearse the incident itself. Roles, authority, an action plan for a cyberattack, communications, recovery, the cost of a day of downtime.
In practice: for the second layer we run a two-day business continuity stress test — a diagnostic plus a strategic session with a ransomware stress simulation for the management team, ending with a CEO report. An awareness platform teaches staff not to open the door; the stress test prepares the company for the day the door gets opened anyway.

Train your executive team in cyber resilience

Corporate BCM/BCP course: 6 modules, 16 hours, 2 days — on-site or online, with drills and a certificate. Includes the module "Cyber resilience: the first 24 hours after an attack".

FAQ

Where should employee cybersecurity training start?

With basic cyber hygiene and regular phishing simulations through a security awareness platform. This covers the most common staff mistakes.

Is a security awareness platform enough to protect the business?

No. It lowers the probability of a successful attack through staff, but does not prepare the company for the attack itself. The executive team must know who decides, what to tell clients and how to recover.

How do you test a company's readiness for a cyberattack?

Run readiness testing: a tabletop exercise or a ransomware stress simulation with the management team.

Evgeny Telenkov
Evgeny Telenkov
Chief Risk Officer · PhD in Economics · "Best Risk Manager of Russia 2020"
20 years in risk management. Led risk management at Beeline, Nornickel, Rosneft and EY. Built business continuity plans for Nornickel, Rostec, NSD and DIA. Trained 300+ risk and BCM specialists.
All courses and services at risk-place.ru →