Cyber security does not sit entirely with the IT or security team.
Every day, employees open emails, share files, sign into systems, approve payments, work remotely and handle sensitive information. Most of the time, those actions are routine. But they are also opportunities attackers can exploit.
That is where cyber security awareness comes in.
Cyber security awareness helps people understand the cyber risks they are likely to encounter at work, recognise when something does not look right and know what to do next.
For UK businesses, that matters. The UK Government's Cyber Security Breaches Survey 2025/2026 found that 43% of businesses identified a cyber security breach or attack in the previous 12 months. Phishing remained the most common type of attack, affecting 38% of businesses.
Yet only 19% of UK businesses reported providing cyber security training or awareness activity during the same period.
So what should cyber security awareness actually involve, how often should businesses be doing it and where does it fit into a wider cyber security strategy?
Cyber security awareness is the process of helping employees understand the cyber threats they could encounter and the role they play in protecting the organisation.
That includes knowing how to recognise suspicious activity, follow secure working practices and report something quickly when it goes wrong.
A good cyber security awareness programme should help employees understand things such as:
The goal is not to turn every employee into a cyber security expert.
It is to make secure behaviour part of normal working behaviour.
Attackers do not always need to find a sophisticated technical vulnerability.
Sometimes, it is easier to convince someone to hand over a password, open an attachment, approve a payment or provide information that should have remained private.
Phishing is a good example.
According to the latest UK Government Cyber Security Breaches Survey, phishing was identified by 38% of UK businesses, considerably more than any other type of breach or attack. Among businesses that experienced a breach or attack, phishing was also the type most commonly considered the most disruptive.
And phishing attacks are no longer limited to obviously suspicious emails full of spelling mistakes.
They can imitate colleagues, suppliers, senior executives and trusted brands. An attacker may use publicly available information about an organisation or employee to make a request look far more believable.
The NCSC warns that targeted phishing campaigns can use information about a company or its employees to make messages more persuasive.
Cyber awareness gives employees the context they need to question those requests before taking action.
The exact programme will depend on the organisation, but there are several areas most UK businesses should cover.
Employees should understand the different ways attackers may try to manipulate them.
That can include:
Training should also make it clear what employees should do when they receive something suspicious.
Recognising an attack is only half the job. Reporting it quickly can allow the security team to investigate whether other people have received the same message and take action before the incident spreads.
Employees should understand why compromised credentials create such a significant risk.
That means covering secure password practices, password managers and the importance of not reusing credentials between personal and business accounts.
Businesses should also use technical controls such as MFA wherever possible.
The NCSC recommends MFA as one of the measures organisations can use to make accounts more resistant to phishing, because a stolen password alone may then be insufficient for an attacker to access the account.
Employees should understand their responsibilities when using laptops, mobiles and other company devices.
That could include:
The technical team should still be responsible for putting controls around those devices. Awareness should support those controls, rather than replace them.
Security awareness should also cover the information employees work with every day.
That includes customer information, employee data, financial records, credentials, intellectual property and other commercially sensitive information.
Employees should know where that information can be stored, who it can be shared with and which systems should be used to send it.
This is also relevant to data protection. The ICO's guidance places emphasis on staff receiving appropriate training and support to handle personal information securely.
Working away from the office introduces its own security considerations.
Employees may be connecting from home networks, travelling with company equipment, using shared spaces or accessing cloud systems from different locations.
Cyber awareness should therefore cover your organisation's approach to remote access, device security, public Wi-Fi, confidential conversations and reporting lost equipment.
This part is easy to overlook.
Employees need to know exactly what to do when they think something has gone wrong.
Who do they contact?
How do they report a phishing email?
What happens if they clicked a suspicious link?
What should they do if they accidentally shared information with the wrong person?
There should be an obvious answer.
The NCSC recommends creating an environment where employees can report suspicious activity quickly and without fear of punishment. It warns that a blame-focused culture can discourage employees from reporting mistakes, potentially delaying the organisation's response.
The sooner an incident is reported, the sooner it can be investigated and contained.
The terms are often used interchangeably, but there is a useful difference.
Cyber security training is usually a defined learning activity. That might be an online course during employee onboarding, a workshop or a phishing exercise.
Cyber security awareness is broader.
It is about keeping cyber security visible throughout the year and helping secure behaviour become part of the organisation's culture.
That could involve:
The NCSC offers its own free Top Tips for Staff training, covering passwords, devices, phishing and incident reporting. The course takes less than 30 minutes and is designed to be accessible to employees without a technical background.
But completing a course once should not be the end of the conversation.
There is no single frequency that will suit every business.
An annual training module may form part of the programme, but awareness should continue throughout the year.
New employees should receive relevant security guidance when they join. Existing employees should receive refreshers, particularly when threats, technology or company processes change.
Employees with higher-risk responsibilities may also need additional training.
For example:
The ICO recommends organisations periodically assess staff training needs and provide refresher training at appropriate intervals rather than allowing security knowledge to become outdated.
The important thing is that cyber awareness remains relevant to the risks people actually encounter.
Throwing another mandatory training module onto everyone's task list is unlikely to transform security behaviour by itself.
Businesses should think about how awareness works in practice.
Make it relevant
Use examples employees could realistically encounter. A suspicious invoice will mean more to somebody in finance than a highly technical explanation of malware behaviour.
Keep it regular
Short, useful reminders throughout the year are often easier to absorb than one large annual training session. Cyber threats and working practices change. Awareness needs to move with them.
Make reporting easy
Employees should not have to search through an intranet to work out how to report a suspicious email. Make the process obvious, quick and easy to access.
Avoid creating a blame culture
People will make mistakes.
If employees think reporting one could get them into trouble, they may stay quiet. The NCSC specifically advises organisations against reprimanding employees who struggle to recognise phishing emails and recommends measuring positive security behaviours, such as how many suspicious messages employees report.
Give higher-risk teams additional support
Not every employee faces exactly the same threats. Training should reflect the person's access, responsibilities and the information they handle.
Get leadership involved
Security awareness is much harder to embed if cyber security is treated as somebody else's problem. Leadership should reinforce secure working practices and demonstrate that reporting security concerns is encouraged.
Course completion is easy to measure.
It does not necessarily tell you whether the organisation is becoming more secure.
Businesses should consider a wider set of indicators, such as:
Phishing simulations can form part of this, but they need to be used carefully.
The NCSC warns against relying too heavily on phishing simulations or treating click rates as the main measure of success. No training can teach somebody to recognise every phishing attempt, and overly punitive exercises can damage trust between employees and security teams.
A more useful question is whether employees know what to do when something suspicious happens.
No.
People are one part of cyber security, but they should never be expected to act as the organisation's only defence.
Even well-trained employees can click convincing phishing emails.
That is why the NCSC recommends a layered approach combining people, processes and technical security controls.
Those controls may include:
Good security should assume that something will eventually get through.
The organisation then needs the visibility and response capability to identify what happened, contain it and address the underlying risk.
Cyber awareness is one part of a much wider picture.
An employee might correctly identify a suspicious login request. But your organisation still needs the controls to detect malicious activity that employees never see.
It needs to know which vulnerabilities exist, which devices are exposed, whether security controls are configured correctly and what needs fixing first.
That is why businesses should look at cyber awareness alongside areas such as:
The NCSC's 10 Steps to Cyber Security follows a similar principle, treating user education and awareness as one component of a broader approach to managing organisational cyber risk.
At CybaVerse, that broader view of security posture is built into CybaOps. Its Security Assessment allows organisations to assess themselves across the NCSC's 10 Steps to Cyber Security and combine that information with live security data to build a clearer picture of where improvements are needed.
Because knowing that employees have completed their cyber awareness training is useful.
Knowing how that fits into the rest of your security position is even more useful.
Cyber security awareness should be treated as part of your wider security strategy, not as a standalone training exercise.
Employees need to understand the risks they are likely to face and know what to do when something does not look right. But that needs to sit alongside the right technical controls, clear reporting processes and a team that can respond when an incident occurs.
The aim is not simply to record that everyone has completed an annual training course. It is to reduce avoidable risk, improve how quickly suspicious activity is reported and make sure the business is better prepared to deal with an attack if one happens.