To build a cyber security awareness training programme, assess your current risk with a baseline phishing simulation, set clear objectives, choose role relevant content aligned to NCSC guidance, run regular simulations, reinforce the lessons over time and measure the results. Treat it as a continuous cycle, not a one off annual course, so behaviour genuinely changes.
A security awareness programme only works if it is built deliberately. Buying a content library and assigning an annual module to everyone is the version that fails, because it does not target real risk, does not reinforce the message and produces nothing you can show to leadership. This guide walks through the six steps that turn awareness training into a measurable reduction in human risk, using the four stage method Boxphish has refined since 2018: Assess, Educate, Reinforce, Measure.
What is a cyber security awareness training programme?
A programme is the structured, ongoing system that educates your workforce about cyber threats and changes how they behave. It is more than a course. It combines a baseline assessment, role relevant training, realistic phishing simulations and continuous measurement, all running on a repeating cycle. The goal is a workforce that protects its accounts and data, recognises threats and reports anything suspicious quickly. You can see the full picture on the cyber security awareness training page, but the steps below show how to build one from scratch.
What you need before you start
Three things make the difference between a programme that launches smoothly and one that stalls. First, a clear owner, usually in IT or security, who is accountable for the outcome. Second, visible support from leadership, because a programme that the executive team is seen to take seriously is one that staff take seriously too. Third, a way to sync your users and deliver training without manual effort. Boxphish integrates with Microsoft 365 for user syncing and single sign-on, which removes most of the administrative burden before you begin.
Step 1: Assess your current risk
Start by measuring where you are, since a baseline phishing simulation, combined with a short knowledge check, reveals how many people would click, which teams are most exposed and which threats need the most attention. This is the Assess stage, and it matters because you cannot improve what you have not measured. The numbers also give you a powerful before and after story for leadership later. Boxphish analysis of more than 400,000 platform users found that untrained users are 8.8 times more likely to click a phishing email than trained users, so expect that first baseline to be sobering and use it as your starting line.
Step 2: Set clear objectives and get buy-in
Decide what success looks like before you choose any content. Good objectives are specific and measurable, for example reducing the phishing click rate below a target percentage, lifting the reporting rate or achieving full completion across every department within a quarter. Tie these objectives to outcomes leadership cares about, such as compliance, cyber insurance requirements and protection from financial fraud. Securing visible executive sponsorship at this stage is what carries the programme through the inevitable competing priorities later.
Step 3: Choose the right training content
With a baseline and objectives in place, choose content that targets your real gaps. Prioritise the threats your assessment exposed, keep modules short so they fit around the working day and make them role relevant so finance, IT and front line staff each get the emphasis that fits their risk. Ensure the content aligns to recognised guidance such as NCSC and is kept current, because stale material teaches people to spot last year's attacks. For the highest risk area, dedicated anti-phishing training turns email threat awareness into a practised skill, while data security awareness training covers handling of sensitive information.
Step 4: Run phishing simulations
Training tells people what to do, while simulations let them practise and show you who is still at risk. Run realistic phishing simulations regularly, varying the scenarios so people cannot simply learn to spot one template. Crucially, treat a click as a teaching moment, not a disciplinary one. The aim is a culture where people feel safe reporting mistakes, because fear of blame is the enemy of fast reporting. Over time the simulation results become one of your clearest measures of progress.
Step 5: Reinforce the lessons over time
This is the Reinforce stage, and it is what separates a programme that changes behaviour from one forgotten within a fortnight. Habits fade, staff turn over and threats evolve, so a single training push is never enough. Use regular refresher modules, timely nudges after a simulation and varied scenarios to keep awareness high. Reinforcement is also where awareness training matures into human risk, treating the human layer as a risk to be managed continuously rather than trained once a year.
Step 6: Measure results and report to leadership
Close the loop by measuring what matters and reporting it clearly. Track phishing click rates, reporting rates and module completion, then compare them against the baseline from step one. Present the trend to leadership in plain numbers that show risk falling over time. This is the Measure stage, and it does double duty: it proves the programme's value to the board and to insurers, and it feeds the next cycle by showing where to focus the following round of training. For wider rollouts, the cyber security training for employees approach scales this across the whole workforce.
How long does it take to build a programme?
You can launch a basic programme in a few weeks: A baseline simulation, a first set of modules and a reporting rhythm. The behaviour change, though, is a longer game measured in quarters, not days. Expect to see click rates fall over the first few cycles and a security culture take shape over the first year. The organisations that succeed are the ones that treat the programme as permanent infrastructure, reviewed and refreshed continually, rather than a project with an end date.
What mistakes should you avoid when building a programme?
The most common failure is launching with content but no baseline, which leaves you unable to prove the programme worked because you never measured where you started. The second is making training an annual, one off event, since behaviour built in a single session fades within weeks. The third is the same module for everyone regardless of role, which wastes the time of teams who face very different threats. The fourth is treating a phishing simulation click as a disciplinary matter, which teaches people to hide mistakes instead of reporting them and quietly destroys your reporting rate. The fifth is forgetting leadership, because a programme with no executive sponsor slips down the priority list the moment something more urgent appears.
Each of these mistakes has a simple counter: measure before you train, make the programme continuous rather than annual, tailor content by role and treat every click as a chance to teach rather than to punish. Keeping leadership visibly involved matters too, so the whole organisation understands that the programme is a priority. Build around these principles from the start and you avoid the rework that catches out teams who launch first and plan later.
It also helps to document the programme so it survives staff changes. A short written plan covering objectives, the training calendar, who owns each stage and how success is measured means the programme does not depend on a single person and makes it far easier to demonstrate diligence to auditors, regulators and cyber insurers.
Frequently asked questions
How do I start a cyber security awareness training programme?
Begin with a baseline phishing simulation to measure your current risk, then set clear objectives, choose role relevant content aligned to NCSC guidance and run training and simulations on a continuous cycle. Measuring first gives you both a target and a story to show leadership.
What should a security awareness training programme include?
A complete programme includes a risk assessment, role relevant training content, regular phishing simulations, ongoing reinforcement and clear measurement against a baseline. The four stages of Assess, Educate, Reinforce and Measure provide a simple structure to follow.
How often should the programme run?
Training should run continuously rather than as a one off project. Short modules and simulations on a rolling monthly or quarterly basis are far more effective than a single annual course, because habits fade and threats change.
How do I prove the programme is working?
Compare phishing click rates, reporting rates and completion against your starting baseline and show the trend over time. A falling click rate and a rising reporting rate are the clearest evidence that behaviour is changing, and exactly what leadership and insurers want to see.
Build your programme with Boxphish
Boxphish gives you everything the six steps require in one platform: baseline phishing simulations, NCSC aligned training content, reinforcement and clear reporting, all built on the Assess, Educate, Reinforce and Measure method and integrated with Microsoft 365. It is designed for busy IT and security teams who need results without heavy administration.
To build your programme on solid foundations, book a Boxphish demo and start with a baseline simulation. You will know within one exercise exactly where your risk sits and where to begin.


