Generated by Rank Math SEO, this is an llms.txt file designed to help LLMs better understand and index this website. # Boxphish: Boxphish is a low touch cyber security awareness training platform that arms organisations and their people, with the tools and knowledge needed to reduce the risk of cyber attacks. This is achieved by combining real world phishing simulations, quality training content and actionable analytics into a single platform. The platform is simple to deploy, easy to manage and proven to boost organisation wide cyber awareness, fast. ## Sitemaps [XML Sitemap](https://www.boxphish.com/sitemap_index.xml): Includes all crawlable and indexable pages. ## Posts - [How to get employees to engage with security training](https://www.boxphish.com/blog/employee-engagement-security-training/): Employees engage with security training when it is short, relevant to their actual role, delivered regularly rather than annually and free of blame. Engagement improves further when leadership takes part visibly, when feedback arrives at the moment of a mistake and when the content is useful in their personal life as well as at work. - [What is a security behaviour and culture programme (SBCP)? A complete guide](https://www.boxphish.com/blog/what-is-a-security-behaviour-and-culture-programme/): A security behaviour and culture programme (SBCP) is an enterprise wide approach to reducing the cyber security risk created by human behaviour. Coined by Gartner, it moves beyond annual awareness training using behavioural science, data and continuous reinforcement to change how people act every day to build a measurable security culture, rather than simply recording who completed a course. - [Review of the 2026 Cyber Security Breaches Survey](https://www.boxphish.com/blog/review-of-the-2026-cyber-security-breaches-survey/): Boxphish's review of the 2026 Cyber Security Breaches Survey has landed. Last years survey felt like a warning and that feeling has certainly developed with this years release.   - [Why most cyber security awareness training fails (and how to fix it)](https://www.boxphish.com/blog/why-cyber-security-awareness-training-fails/): Most cyber security awareness training fails because it is annual, generic and measured by completion rather than behaviour. It teaches without letting people practise, punishes mistakes so reporting dries up and goes stale as threats change. The fix is continuous, role relevant training paired with realistic simulations and measured by falling click rates. - [How to measure the effectiveness of security awareness training (metrics and KPIs)](https://www.boxphish.com/blog/measure-security-awareness-training-effectiveness/): Measure security awareness training by tracking behaviour, not completion. The core metrics are the phishing click rate, which should fall, and the reporting rate, which should rise, both measured against a baseline. Add time to report, repeat clickers and module completion, then show the trend over time to prove falling risk and return on investment. - [Cyber security awareness training for employees: Best practices that actually work](https://www.boxphish.com/blog/security-awareness-training-employees-best-practices/): The best cyber security awareness training for employees is continuous, short and role relevant, combines lessons with realistic phishing simulations and measures behaviour rather than completion. It works because it builds genuine habits and a no blame reporting culture, turning staff from an organisation's biggest vulnerability into an active line of defence. - [BYOD security risks: Why bring your own device could be your biggest threat](https://www.boxphish.com/blog/byod-security-risks-why-bring-your-own-device-could-be-your-biggest-threat/): Bring your own device, or BYOD, policies boost flexibility and productivity but they also expand your attack surface in ways many organisations underestimate. When personal phones, laptops and tablets connect to corporate systems, unsecured devices and home networks can dramatically increase exposure to malware and data loss. For many businesses, the convenience of letting staff use their own kit quietly becomes one of the largest and least visible sources of cyber risk. This guide explains the key BYOD security risks and, more importantly, how to manage them without sacrificing the benefits that made BYOD attractive in the first place. - [Phishing awareness training: How to stop employees clicking malicious emails](https://www.boxphish.com/blog/phishing-awareness-training-stop-clicking/): Phishing awareness training teaches employees to recognise and report malicious emails before they click. It combines short, practical lessons on the signs of a phishing email with realistic simulations that let staff practise safely. Delivered continuously, it sharply reduces click rates and turns the workforce into an early warning system against attacks. - [How often should you run cyber security awareness training?](https://www.boxphish.com/blog/how-often-cyber-security-awareness-training/): Cyber security awareness training should be continuous, not annual. The most effective approach delivers short training modules and phishing simulations every month or quarter, with a full content refresh at least once a year. Frequent, bite-sized reinforcement changes behaviour far more reliably than a single long session that employees quickly forget. - [Business email compromise examples: Real BEC attacks and lessons learned](https://www.boxphish.com/blog/business-email-compromise-examples-real-bec-attacks-and-lessons-learned/): Business email compromise examples are some of the most useful learning tools a security team has, because they show in plain terms how a few convincing words in an email can lead to enormous financial loss. BEC is now one of the costliest forms of cyber attack facing organisations of every size, and unlike malware it leaves almost no technical trace. By studying real world style examples of how these scams unfold, employees can recognise the warning signs and respond correctly before money or data leaves the business. This article walks through three common BEC scenarios, the lessons each one teaches and how to turn those lessons into lasting defences. - [How to build a cyber security awareness training programme: A step-by-step guide](https://www.boxphish.com/blog/build-cyber-security-awareness-training-programme/): To build a cyber security awareness training programme, assess your current risk with a baseline phishing simulation, set clear objectives, choose role relevant content aligned to NCSC guidance, run regular simulations, reinforce the lessons over time and measure the results. Treat it as a continuous cycle, not a one off annual course, so behaviour genuinely changes. - [Security awareness training topics: What to cover in 2026](https://www.boxphish.com/blog/security-awareness-training-topics/): Knowing which topics to include is the difference between training that changes behaviour and training that ticks a box. Cover too little and you leave gaps that attackers will find. Cover everything at once and you overwhelm people who already have a full day job. This guide sets out the security awareness training topics that matter most in 2026, how to prioritise them, and how to deliver them so the lessons actually stick. - [Business email compromise (BEC) vs phishing: Key differences every employee must know](https://www.boxphish.com/blog/business-email-compromise-bec-vs-phishing-key-differences-every-employee-must-know/): Business email compromise vs phishing is a comparison every employee should understand, because the two terms are often used interchangeably when in fact they describe very different threats. Both arrive in your inbox, both rely on deception and both can cause serious harm, but the way they work, the way they are detected and the way staff should respond are not the same. Understanding the difference helps employees react appropriately and helps security teams build the right defences. This article breaks down how business email compromise (BEC) and phishing differ, where they overlap and exactly what every member of staff should watch for. - [How to build an effective security awareness & training programme from scratch](https://www.boxphish.com/blog/how-to-build-an-effective-security-awareness-training-programme-from-scratch/): Building a security awareness training programme from scratch can feel daunting. Where do you start, what should you teach and how do you know whether any of it is actually working? The good news is that an effective programme does not require a huge budget or a dedicated team. What it needs is a clear, structured approach that builds knowledge, changes behaviour and proves its value over time. This guide sets out a practical six-step process for creating a programme that genuinely reduces your organisation's human cyber risk. - [Security awareness training ROI: How to measure and prove the value to leadership](https://www.boxphish.com/blog/security-awareness-training-roi-how-to-measure-and-prove-the-value-to-leadership/): Security awareness training ROI is one of the hardest things for a security leader to prove, yet it is one of the most important. Security teams are increasingly asked to justify every line of their budget and awareness training is no exception. The trouble is that the value of training shows up as incidents that never happen, breaches that are avoided and behaviours that quietly improve over time. None of that is obvious on a spreadsheet unless you measure it deliberately. This guide explains how to quantify the return on investment of your awareness programme, which metrics genuinely matter and how to present the numbers convincingly to leadership so that your funding is protected and ideally increased. - [What is business email compromise (BEC)? A complete 2026 guide for businesses](https://www.boxphish.com/blog/what-is-business-email-compromise-bec-a-complete-2026-guide-for-businesses/): Business email compromise (BEC), has quietly become one of the most expensive cyber threats facing organisations today. Unlike noisy ransomware outbreaks, BEC attacks rely on deception, social engineering and a single convincing email to trick employees into transferring money or sensitive data. There is often no malware to detect and no malicious link to block, which is precisely what makes this threat so dangerous and so costly. This guide explains exactly what BEC is, how these attacks work and the practical steps your business can take in 2026 to defend against them. - [Security awareness training: Why every employee is your first line of defence](https://www.boxphish.com/blog/security-awareness-training-why-every-employee-is-your-first-line-of-defence/): Security awareness training is one of the most powerful defences an organisation has, yet it is also one of the most overlooked. Firewalls, endpoint protection and email filters are all vital, but the most decisive layer of cyber defence is often your people. Attackers know that the fastest way into an organisation is rarely through a technical exploit, it is through a single distracted employee. Security awareness training transforms staff from a potential weakness into a confident first line of defence, giving them the knowledge and instincts to stop attacks that technology alone cannot. - [Top 10 security awareness training topics every workplace should cover in 2026](https://www.boxphish.com/blog/top-10-security-awareness-training-topics-every-workplace-should-cover-in-2026/): Security awareness training topics are the foundation of any effective programme, because a curriculum is only as strong as the subjects it chooses to cover. As threats evolve so should your training and the topics that mattered a few years ago no longer reflect the full range of risks employees face today. The most resilient organisations treat their syllabus as a living document, refreshing it to match how attackers actually operate. Here are the ten essential security awareness training topics every workplace should prioritise in 2026 to build genuine, lasting resilience. - [What is cyber security awareness training? A complete guide (2026)](https://www.boxphish.com/blog/what-is-cyber-security-awareness-training/): Cyber security awareness training (C-SAT) teaches employees to recognise and respond to threats such as phishing, weak passwords and social engineering. It turns staff from an organisation's biggest vulnerability into its strongest line of defence, combining short, regular lessons with simulated attacks and measuring behaviour over time to make the change stick. - [Signs of a DDoS attack: How to detect and respond before it’s too late](https://www.boxphish.com/blog/signs-of-a-ddos-attack-how-to-detect-and-respond-before-its-too-late/): How to recognise the signs of a DDoS attack, detect early warnings, and respond before downtime damages your business. - [DDoS attack examples: The biggest distributed denial of service attacks in history](https://www.boxphish.com/blog/ddos-attack-examples-the-biggest-distributed-denial-of-service-attacks-in-history/): A quick guide to the biggest DDoS attack examples in history, what happened, and how to reduce risk with layered defence, cyber security awareness training, and phishing simulations. - [What is a DDoS attack? A beginner’s guide to distributed denial of service](https://www.boxphish.com/blog/what-is-a-ddos-attack/): Learn what a DDoS attack is, how it works, common attack types, real examples, and how businesses can prevent distributed denial of service attacks. - [What is data threat awareness and action (DTAA) in cyber security?](https://www.boxphish.com/blog/what-is-data-threat-awareness-and-action-dtaa-in-cyber-security/): Data threat awareness and action (DTAA) is an emerging concept in cyber security that focuses on not just recognising threats, but actively responding to them in real time. - [Cyber governance in action: Strengthening your people against risk (webinar)](https://www.boxphish.com/blog/cyber-governance-in-action-webinar/): In this video, Nick Deacon Elliott - CEO of Boxphish, explores alignment with the UK Government’s Cyber Governance Code of Practice, a six-pillar voluntary framework guiding boards to embed effective cyber security. - [How often should you run data security awareness training for employees?](https://www.boxphish.com/blog/how-often-should-you-run-data-security-awareness-training-for-employees/): If you are only running data security awareness training once a year, you are already behind. - [The complete guide to data security awareness training in 2026](https://www.boxphish.com/blog/the-complete-guide-to-data-security-awareness-training-in-2026/): Data security awareness training is no longer a “nice to have”. In 2026, it is one of the most critical layers of defence against modern cyber threats. - [Seamless access to dark web monitoring (DWM)](https://www.boxphish.com/blog/seamless-access-to-dark-web-monitoring/): We’ve made it easier than ever to stay on top of exposed credentials and dark web risks. With our latest update, DWM shared login, our customers can now access dark web monitoring (DWM) directly from the Boxphish platform, without needing to log in again.  - [What’s new at Boxphish: Your quarterly platform and business update (Q3)](https://www.boxphish.com/blog/whats-new-at-boxphish-q3-2025/): Welcome to your latest Boxphish product update! We’ve been busy enhancing the platform and launching new training content. Here’s everything you need to know from the last quarter. - [How AI is transforming human risk management in 2026](https://www.boxphish.com/blog/how-ai-is-transforming-human-risk-management-in-2026/): Human risk has become one of the most significant drivers of cyber incidents, and traditional approaches to managing it are struggling to keep pace. How AI is transforming human risk management in 2026 is now central to the conversation. Artificial intelligence is fundamentally reshaping how organisations understand, measure, and reduce human-driven cyber risk. Rather than treating employees as a static risk factor, AI enables continuous, adaptive insight into behaviour, allowing security teams to intervene earlier and more effectively. This shift is redefining what effective human risk management looks like. - [Gamifying cyber security: How to make awareness stick](https://www.boxphish.com/blog/gamifying-cyber-security-how-to-make-awareness-stick/): Cyber security awareness has a retention problem. How to make awareness stick is now the question most organisations are asking. Most employees can recall very little from traditional training sessions, even when those sessions are well produced and technically accurate. Slides, videos, and policy documents rarely translate into real-world behaviour change. In 2026, organisations are increasingly turning to gamification to make cyber security awareness engaging, memorable, and effective. When designed properly, gamified security programmes do more than entertain. They build instinctive responses that reduce risk. - [NIS2 and cyber awareness: Turning compliance into practical training](https://www.boxphish.com/blog/nis2-and-cyber-awareness-training/): In today’s interconnected digital landscape, cyber security isn’t just an IT concern, it’s foundational to business resilience. The Network and Information Security Directive 2 (NIS2) is the European Union’s latest legislative framework aimed at strengthening cyber security across critical sectors. It replaces the original NIS Directive, expanding both the number of organisations covered and the expectations placed upon them. - [The human factor: Why employees are your strongest asset](https://www.boxphish.com/blog/the-human-factor-why-employees-are-your-strongest-asset/): For years, cyber security strategies have focused heavily on technology. Firewalls, endpoint protection, and detection tools dominate boardroom conversations, yet most successful attacks still begin with a human interaction. Clicking a link, sharing credentials, or responding to a seemingly legitimate request remains the easiest way into an organisation. This is exactly why employees are your strongest asset. In 2026, the most resilient organisations recognise a fundamental truth. Employees are not the weakest link in cyber security. When supported correctly, they are the strongest asset. - [Top human-centric strategies to reduce cyber risk in 2026](https://www.boxphish.com/blog/top-human-centric-strategies-to-reduce-cyber-risk-in-2026/): As cyber threats evolve in sophistication, organisations face a stark reality: the human element remains the most targeted and exploited factor in their security posture. The top human-centric strategies to reduce cyber risk in 2026 recognise that people, not technology alone, sit at the centre of modern attack paths. Human-centric cyber security focuses on how people think, behave and respond under pressure, acknowledging that reducing cyber risk depends on mitigating human vulnerabilities. By 2026, attackers will increasingly exploit trust through phishing, social engineering and deepfake fraud. Organisations that invest in human risk management, behavioural cyber security and cyber security culture will consistently outperform those that rely solely on technical controls. - [Did you know Boxphish runs directly inside Microsoft Teams?](https://www.boxphish.com/blog/boxphish-microsoft-teams-integration/): With the Boxphish Microsoft Teams Integration, users can access and complete their training natively inside Microsoft Teams. - [Why phishing simulation training is essential for managing human risk](https://www.boxphish.com/blog/why-phishing-simulation-training-is-essential-for-managing-human-risk/): This is exactly why phishing simulation training has become an essential component of modern cyber security strategies. By exposing real behavioural weaknesses in a controlled environment, phishing simulation training provides insight that traditional awareness programmes simply cannot deliver. - [Reducing human cyber risk with smarter training](https://www.boxphish.com/blog/reducing-human-cyber-risk-with-smarter-training/): Human error remains the leading cause of cyber incidents across every sector. From phishing attacks to data mishandling, most breaches originate from a decision, action or simple oversight made by an employee. This is why organisations are increasingly focused on smarter, behaviour led training as a practical way of reducing human cyber risk rather than simply raising awareness. - [Festive fiends manual](https://www.boxphish.com/blog/festive-fiends-manual/): This Christmas, meet the festive fiends that lurk in your inbox and networks, from gift hoarding Gonks to mischievous Gingerbread. Our Christmas manual is your visual guide to the yuletide cyber creatures of today’s threat landscape.​ - [Human cyber risk metrics that matter for modern security teams](https://www.boxphish.com/blog/human-cyber-risk-metrics-that-matter-for-modern-security-teams/): This is where human cyber risk metrics become essential. By measuring the right indicators, organisations gain visibility into the human layer, uncover behavioural vulnerabilities and track meaningful improvement driven by smarter training and phishing simulations. As security strategies shift towards a people first approach, understanding human cyber risk metrics is critical to building an effective human risk management framework. - [How to safely send virtual Christmas cards](https://www.boxphish.com/blog/safely-send-virtual-christmas-cards/): The festive season is a time for sending warm wishes to friends, family, and colleagues. With the rise of digital communication, virtual Christmas cards have become increasingly popular. They’re quick, eco-friendly, and can be beautifully personalised. - [The complete guide to human risk management in cyber security](https://www.boxphish.com/blog/the-complete-guide-to-human-risk-management-in-cyber-security/): This guide explores what human risk management cyber security really means, why it matters and how organisations are using modern tools such as phishing simulation training, behaviour led security awareness training and human risk analytics to reduce human related cyber risk at scale. - [5 Christmas traps to watch out for](https://www.boxphish.com/blog/5-christmas-traps-to-watch-out-for/): 2. Flashy “one-day only” offersThe excitement of limited time Christmas offers or deals can make shoppers act impulsively. Fraudsters exploit this sense of urgency with "flash sales", "only X amount left" and "last chance" offers that push you to enter personal information or card details. Remember, if an offer feels rushed or too good to be true, it probably is. Take a moment to verify it before acting. - [Outsmarting cyber attacks: Building human resilience against phishing and social engineering](https://www.boxphish.com/blog/outsmarting-cyber-attacks-building-human-resilience-against-phishing-and-social-engineering/): When it comes to cyber security, humans remain both the greatest strength and the biggest target. Most attacks today don’t start with a system exploit, they start with a well-crafted email, message, or phone call designed to manipulate human trust. - [What’s new at Boxphish: Your quarterly platform and business update (Q2)](https://www.boxphish.com/blog/whats-new-at-boxphish-q2-2025/): Welcome to your latest Boxphish product update! We’ve been busy enhancing the platform and launching new training content. Here’s everything you need to know from the last quarter. - [Beyond the surface: Dark web scanning and data awareness for your organisation ](https://www.boxphish.com/blog/beyond-the-surface-dark-web-scanning-and-data-awareness-for-your-organisation/): The dark web is full of stolen credentials, leaked databases, and sensitive corporate information, often appearing long before an organisation realises it’s been compromised. Leaders play a crucial role in shaping how their teams understand and respond to these hidden risks, building a culture that values proactive detection and informed action. - [Top 5 Black Friday dangers hiding in your inbox](https://www.boxphish.com/blog/black-friday-dangers/): Black Friday is prime time for snagging a bargain and unfortunately, it’s also prime time for cyber criminals. With inboxes overflowing and adverts flying in from every direction, it’s all too easy to click before you think. Here are the top five Black Friday dangers to watch out for, and how to help your team steer clear of them.  - [How organisations can drive secure cyber security behaviours](https://www.boxphish.com/blog/how-organisations-can-drive-secure-cyber-security-behaviours/): When it comes to cyber security, humans are often the most vulnerable link. Despite sophisticated tools and defences, a single click on a phishing email or the reuse of a weak password can undermine even the strongest systems. - [Building a security culture through cyber awareness training](https://www.boxphish.com/blog/building-a-security-culture-through-cyber-awareness-training/): Cyber threats are no longer confined to IT departments, they’re a business wide concern. As organisations increasingly rely on digital tools and remote collaboration, the need for a strong security culture has never been greater. - [Phishing protection gets easier with Boxphish’s new Microsoft Defender integration ](https://www.boxphish.com/blog/phishing-protection-integration/): Phishing attacks continue to pose a serious threat to organisations worldwide, targeting employees and sensitive data alike. In response, Boxphish has launched a new integration with Microsoft Defender, making it faster and simpler for users to report suspicious emails and for organisations to strengthen their email security.  - [When awareness becomes resilience: Lessons from the NCSC Annual Review 2025](https://www.boxphish.com/blog/awareness-from-ncsc-annual-review-2025/): The NCSC’s Annual Review 2025 paints a clear picture of where the UK stands on cyber awareness and resilience and it’s a wake-up call. Serious cyber incidents have more than doubled in just one year, with 429 handled between September 2024 and August 2025. Of those, nearly half were classed as ‘nationally significant'.  - [What are the common signs of a phishing email?](https://www.boxphish.com/blog/what-are-the-common-signs-of-a-phishing-email/): Phishing emails remain one of the most widespread and costly cyber threats facing businesses today. According to industry reports, phishing is responsible for the majority of successful cyber attacks, often leading to data breaches, financial loss and reputational damage. - [Common phishing emails to look out for in 2026](https://www.boxphish.com/blog/common-phishing-emails-to-look-out-for-in-2026/): Phishing remains one of the most prevalent cyber threats in the world, and it shows no signs of slowing down. As technology evolves, so too do the methods that attackers use to trick unsuspecting victims. In 2026, phishing emails are expected to become even more convincing, thanks to artificial intelligence, automation, and a global increase in remote working. For organisations of all sizes, staying informed about the latest tactics is the first step to keeping employees and data safe. - [Building a strong cyber culture: Secure behaviours that protect](https://www.boxphish.com/blog/cyber-culture-phishing-best-practices/): Many organisations still rely on a familiar formula for cyber security - annual training sessions, a strong IT department, and heavy investment in technical controls. While these efforts provide a foundation, they aren’t enough to protect against today’s evolving threats. - [What is dark web monitoring & scanning](https://www.boxphish.com/blog/what-is-dark-web-monitoring-scanning/): The phrase “dark web” often sparks images of hidden corners of the internet where illegal activity thrives. While this isn’t an exaggeration, the reality is that the dark web is more accessible than most people realise. For businesses, the real danger lies in sensitive company or employee information ending up there without anyone noticing. - [What’s new at Boxphish: Your quarterly platform and business update (Q1)](https://www.boxphish.com/blog/whats-new-at-boxphish-q1-2025/): We’ve been busy enhancing the platform, launching new training for students, and moving into a bigger home (still in Leeds City Centre). Here’s everything you need to know from the last quarter (and a little bit of August). - [How are ransomware and phishing attacks related?](https://www.boxphish.com/blog/how-are-ransomware-and-phishing-attacks-related/): How are ransomware and phishing attacks related in practice? The answer lies in the initial compromise. - [Transforming your cyber culture: Enhancing security behaviours and reducing cyber risks](https://www.boxphish.com/blog/transforming-your-cyber-culture-enhancing-security-behaviours-and-reducing-cyber-risks/): Cyber criminals increasingly leverage sophisticated techniques, such as phishing schemes and AI-driven attacks, to exploit vulnerabilities in systems and networks. - [What is anti-phishing? Empower your team to outsmart threats with expert guidance](https://www.boxphish.com/blog/what-is-anti-phishing/): Phishing is still one of the most effective tactics cybercriminals use—and understanding what is anti-phishing has never been more critical. - [What we know about the upcoming UK Cyber Security and Resilience (CSR) Bill](https://www.boxphish.com/blog/what-we-know-about-the-upcoming-uk-cyber-security-and-resilience-csr-bill/): Why this legislation marks a turning point for UK cyber security and what your organisation needs to do next. - [The human factor in cyber security: How cyber criminals exploit people to breach organisations](https://www.boxphish.com/blog/the-human-factor-in-cybersecurity/): The human factor in cyber security is now the most exploited attack vector in modern business. As cyber defences become increasingly sophisticated, attackers are shifting their focus, from breaking code to breaking people. - [What’s new at Boxphish: Your quarterly platform and business update](https://www.boxphish.com/blog/whats-new-at-boxphish-your-quarterly-platform-and-business-update/): We’ve been hard at work enhancing the Boxphish experience, and we’re excited to share what’s new. From advanced customisation features to new training content and NCSC recognition, here’s everything you need to know. - [How generative AI is enhancing phishing attacks and how to defend against them](https://www.boxphish.com/blog/how-generative-ai-is-enhancing-phishing-attacks-and-how-to-defend-against-them/): Phishing attacks have become alarmingly sophisticated with the advent of generative AI, capable of producing highly realistic emails, audio, and video content that can easily deceive even the most cautious individuals. This article delves into the role of generative AI in enhancing phishing tactics, exploring the technological foundations behind these advancements and highlighting the evolving nature of such threats. By understanding these new dynamics, you'll learn how to better protect yourself and your organisation against these advanced cyber threats. - [Effective cyber security awareness training doesn’t have to be complicated](https://www.boxphish.com/blog/effective-cyber-security-awareness-training-doesnt-have-to-be-complicated/): Cyber security awareness training, or cyber-SAT, has been on the radar for some time now, yet uptake of technologies to support cyber-SAT efforts—although increasing—are still relatively low.   - [How to increase your cyber security awareness](https://www.boxphish.com/blog/how-to-increase-your-cyber-security-awareness/): Here are are top tips on how to increase your cyber security awareness: - [Vishing: What is it and how to protect yourself](https://www.boxphish.com/blog/vishing-what-is-it-and-how-to-protect-yourself/): Vishing, also known as “voice phishing” or “phone phishing”, is a type of social engineering scam where an attacker uses a phone call or voice message to trick their victim into divulging sensitive information or performing an action that can harm them or their organisation. This is an increasingly prevalent scam that individuals and businesses need to be aware of to stay safe. - [Identifying a spam email vs. a phishing email](https://www.boxphish.com/blog/identifying-a-spam-email-vs-a-phishing-email/): In today's world of digital communication, emails have become an essential part of our everyday lives. Whether personal or professional, these emails contain important information that needs to be protected from spammers and scammers. However, given the increasing sophistication of these scammers, it is often difficult to identify the difference between spam emails and phishing emails. In this blog, we will discuss some of the ways you can identify and protect yourself from these fraudulent emails. - [How to protect your employees from shoulder surfing](https://www.boxphish.com/blog/how-to-protect-your-employees-from-shoulder-surfing/): Shoulder surfing sounds a bit odd. Funny almost. But unfortunately for us all, it's not a joke. Shoulder surfing is a form of visual hacking, where a malicious individual secretly observes the activities of someone else on their computer, mobile phone or other electronic device. - [How artificial intelligence is leaving us more vulnerable to cyber attacks](https://www.boxphish.com/blog/how-artificial-intelligence-is-leaving-us-more-vulnerable-to-cyber-attacks/): The introduction of AI into our daily lives has been talked about for years, but with the launch of ChatGPT and other forms of artificial intelligence over the last twelve months, it’s become less of a ‘what if’ and more of a reality. - [How to establish a successful learning culture within your organisation](https://www.boxphish.com/blog/how-to-establish-a-successful-learning-culture-within-your-organisation/): A “learning culture” is a term that is thrown about a lot these days, often without people fully understanding what it means. Firstly, before you grasp what a learning culture is – and a good one at that – you need to understand what a learning culture is and why you should establish one within your organisation. - [What are the benefits of using phishing simulations?](https://www.boxphish.com/blog/what-are-the-benefits-of-using-phishing-simulations/): Phishing is the most common type of cyber-attack, with an estimated 3.4 billion phishing emails sent every day. Based on that, you’re guaranteed to come across a phishing email almost every day of your life and so you need to be prepared to identify and avoid these threats. - [Smishing: What is it and how can you stay safe?](https://www.boxphish.com/blog/what-is-smishing/): In the world of cyber security, smishing is one of those words you tend to look at and think it’s a typo. But as scammers get more and more advanced, so do their methods and, believe it or not, smishing is one of them. - [The most common social engineering attacks and how to avoid them](https://www.boxphish.com/blog/the-most-common-social-engineering-attacks-and-how-to-avoid-them/): Social engineering is a type of cyber-attack that deliberately targets the victim’s emotions. It uses psychological manipulation to trick users into making security mistakes or giving away sensitive information. - [How to protect your organisation from cyber security threats in 2023](https://www.boxphish.com/blog/how-to-protect-your-organisation-from-cyber-security-threats-in-2023/): Cyber security is growing year on year as both a threat and an industry, with the need to protect yourself increasing too. There are hundreds of different ways a cybercriminal might try to attack you, your device, or your organisation, making the right protection a vital thing to your success. - [Top 10 email scams to be aware of in 2023](https://www.boxphish.com/blog/top-ten-email-scams-to-be-aware-of-in-2023/): Over the last twelve months, we have encountered any number of new email scams. Cybercriminals have become bolder, trying out new methods in an attempt to trick us into revealing our sensitive information. - [Phishing & blagging: What’s the difference?](https://www.boxphish.com/blog/phishing-vs-blagging/): Phishing? Blagging? What do these words mean? The cyber landscape is awash these days with new and complicated terminology, each new method of attack developed by cybercriminals earning itself a new name for us to learn and try to avoid. But what are they, and what’s the difference between them? - [Think before you click: What is it?](https://www.boxphish.com/blog/think-before-you-click/): The Think Before You Click campaign is designed to get you to do exactly that – slow down, consider what or who you’re interacting with online and think about what you’re about to do before you do it. - [1618503835: Should I trust this number?](https://www.boxphish.com/blog/1618503835-should-i-trust-this-number/): 1618503835 is a scam caller so you should not trust this number. - [What does a cyber security awareness organisation do?](https://www.boxphish.com/blog/what-does-a-cyber-security-awareness-organisation-do/): The odds are, if you’re reading this, you’ve recently heard of a cyber security awareness organisation, or been offered cyber security awareness training. But that doesn’t mean you necessarily know what you’ve been offered, or indeed what a cyber security awareness organisation even does. - [How do I train my employees to spot a cyber-attack?](https://www.boxphish.com/blog/train-my-employees-to-spot-a-cyber-attack/): When it comes to the security of your organisation, no matter how much money you invest or time you spend implementing new processes, unfortunately, nothing works if the people behind it all aren’t trained up. This begs the question: how do I train my employees to spot a cyber-attack? - [How to stay safe on social media](https://www.boxphish.com/blog/how-to-stay-safe-on-social-media/): Social media is a constant source of knowledge for cyber criminals, which is why managing it is key for protecting yourself and your organisation. There are many simple things you can do, like ensuring your accounts have the highest privacy settings, using complex and unique passwords and being careful not to share too much information online. But, social media is constantly advancing, which means your protection needs to as well. - [How to protect your identity from cyber criminals](https://www.boxphish.com/blog/how-to-protect-your-identity-online/): Identity theft is on the rise. With so much information available about everyone online, it’s become incredibly easy for someone to steal your identity. In fact, over a quarter of all social media users admit that they have created a fake account at least once, and that’s just those who admit to it… - [The most impersonated brands in phishing emails](https://www.boxphish.com/blog/the-most-impersonated-brands-in-phishing-emails/): Phishing attacks are consistently on the rise, with over 3.4 billion phishing emails delivered each day. Cyber criminals are becoming more and more sophisticated, not only using spear phishing tactics, but designing their emails so meticulously that it’s almost impossible to spot a phishing email from the real thing – unless you know how. - [What is a data breach and how can you avoid one?](https://www.boxphish.com/blog/what-is-a-data-breach/): A “data breach” is now a term that is used in the cyber security industry to mean any one of a number of things. In its simplest term however, a data breach is a security violation, where sensitive or protected data is copied, transmitted, viewed, or stolen by someone without the required permissions. You may sometimes hear data breaches referred to as “leaks” or even “data spills” but these all cover the blanket term for someone accessing information that they shouldn’t be. - [The five types of credit card fraud and how to protect yourself](https://www.boxphish.com/blog/the-five-types-of-credit-card-fraud-and-how-to-protect-yourself/): Credit card fraud has been a threat to our security for almost as long as credit cards have been in production. The nature of using a tiny piece of plastic to carry out large monetary transactions has evolved from unique, to regular and mundane. In fact, it is now the people who choose to avoid using credit cards that sometimes find themselves at a disadvantage, which unfortunately, works in favour of the bad guys. - [Password security: How to choose the safest password](https://www.boxphish.com/blog/how-to-choose-the-safest-password/): So, what should you do to remain safe and ensure your passwords are never compromised? We'll show you how to choose the safest password. - [What is a cyber attack and how can it affect my business?](https://www.boxphish.com/blog/what-is-a-cyber-attack-and-how-can-it-effect-my-business/): Cyber attacks are an ever-present threat in our digital landscape. They are occurring more and more frequently, targeting organisations from start-ups to global conglomerates alike. On average, a cyber attack takes place every 39 seconds, meaning there are over two thousand attacks every day. So what is a Cyber Security Attack and how can it affect my business? - [Phishing attacks: How to spot a fake or scam NHS email](https://www.boxphish.com/blog/how-to-spot-a-fake-nhs-email/): Fake emails, known as phishing emails are consistently on the rise. In fact, it’s now estimated that 3.4 billion phishing emails are sent out each day and, with that rate of delivery, it’s no wonder that people are clicking on them. In this article, we'll help you to spot a fake NHS email and prevent any malicious activity through your accounts. - [Sleeper malware: The trojan horse of cybercrime](https://www.boxphish.com/blog/sleeper-malware-the-trojan-horse-of-cybercrime/): Sadly, that is no longer always the case. Recently, more and more cyber-attacks are becoming increasingly difficult to identify. Malware attacks – caused by malicious software being downloaded and infecting a device – could be linked back to a certain website or email. It was still a threat, but one that could be overcome if identified quickly.   - [Cyber crime country: Imagine the property prices…](https://www.boxphish.com/blog/cybercrime-country/): Recently, we stumbled upon an extremely frightening figure. A report published by US-based CyberSecurity Ventures, found that if the cybercrime industry was a country, its economy would be the third largest in the world.   - [Common phishing emails to look out for in 2022](https://www.boxphish.com/blog/common-phishing-emails-to-look-out-for-in-2022/): Cyber security training experts, Boxphish, take you through the common Phishing emails to look out for in 2022. - [How to run a successful cyber awareness campaign](https://www.boxphish.com/blog/how-to-run-a-successful-cyber-awareness-campaign/): The recent Covid 19 pandemic has changed the way many of us work, bringing many of us from the office to our homes. While adjusting to this major change, new threats have emerged from cyber criminals seeking to exploit employees’ fear and curiosity. This means that the mitigation of human error is now, more than ever, essential to business cyber security. End users without information security awareness are proven more likely to fall for cybercriminal’s trickery through phishing emails, leading to issues, such as ransomware. ## Pages - [Request a quote – BGF Scale platform](https://www.boxphish.com/request-a-quote-bgf-scale-platform/) - [Why partner with Boxphish?](https://www.boxphish.com/why-partner-with-boxphish/) - [Microsoft Team Integration](https://www.boxphish.com/microsoft-team-integration/) - [Human Risk Management](https://www.boxphish.com/human-risk-management/) - [NCSC Annual Review 2025](https://www.boxphish.com/ncsc-annual-review-2025/) - [Boxphish on-demand demo video](https://www.boxphish.com/boxphish-on-demand-demo-video/) - [Student Cyber Awareness Training](https://www.boxphish.com/student-cyber-awareness-training/) - [Transform your cyber culture this cyber awareness month](https://www.boxphish.com/transforming-cyber-cultures/) - [Speak to us about student training](https://www.boxphish.com/speak-to-us-about-student-training/) - [Thank you student training](https://www.boxphish.com/thank-you-student-training/) - [Reports](https://www.boxphish.com/reports/) - [Insights](https://www.boxphish.com/insights/) - [Data Security Awareness Training](https://www.boxphish.com/data-security-awareness-training/) - [Report Thank You Page](https://www.boxphish.com/thank-you-report/) - [Dark web scanning](https://www.boxphish.com/dark-web-scanning/) - [Partner Deal Registration](https://www.boxphish.com/partner-deal-registration-form/) - [On-demand product demonstration](https://www.boxphish.com/on-demand-product-demonstration/) - [Pricing](https://www.boxphish.com/pricing/) - [Sitemap](https://www.boxphish.com/sitemap/) - [Data security awareness](https://www.boxphish.com/data-security-awareness/) - [Resources](https://www.boxphish.com/resources/) - [Podcasts](https://www.boxphish.com/podcasts/) - [Success stories](https://www.boxphish.com/success-stories/) - [Analytics](https://www.boxphish.com/analytics/) - [Request a quote](https://www.boxphish.com/request-a-quote/) - [FAQ](https://www.boxphish.com/faq/) - [Contact](https://www.boxphish.com/contact/) - [Legal](https://www.boxphish.com/legal/) - [Cyber security awareness Training](https://www.boxphish.com/cyber-security-awareness-training/) - [Online security awareness training](https://www.boxphish.com/online-security-awareness-training/) - [Phishing Simulations](https://www.boxphish.com/phishing-simulations/) - [Cyber security training for employees](https://www.boxphish.com/cyber-security-training-for-employees/) - [Arabic training content](https://www.boxphish.com/arabic-training-content/) - [Anti phishing training](https://www.boxphish.com/anti-phishing-training/) - [Custom content](https://www.boxphish.com/custom-content/) - [Careers](https://www.boxphish.com/careers/) - [About us](https://www.boxphish.com/company/) - [Documents & webinars](https://www.boxphish.com/guides-webinars/) - [Product](https://www.boxphish.com/product/) - [Book a demo](https://www.boxphish.com/book-a-demo/) - [Blog](https://www.boxphish.com/blog/) - [News](https://www.boxphish.com/news/) - [Home](https://www.boxphish.com/) - [Privacy policy](https://www.boxphish.com/privacy-policy/) ## Insights & Reports - [Your checklist for the 2026 Cyber Security Breaches Survey](https://www.boxphish.com/guide-webinar/your-checklist-for-the-2026-cyber-security-breaches-survey/) - [Your guide to the 2026 Cyber Security Breaches Survey](https://www.boxphish.com/guide-webinar/your-guide-to-the-2026-cyber-security-breaches-survey/) - [Local Authority data breaches report: Q3 2025 (Nov 25 – Jan 26)](https://www.boxphish.com/guide-webinar/q3-local-authority-data-breaches-report-from-boxphish/) - [Retail data breaches report: Q3 2025 (Nov 25 – Jan 26)](https://www.boxphish.com/guide-webinar/q3-retail-data-breaches-report-from-boxphish/) - [Education data breaches report: Q3 2025 (Nov 25 – Jan 26)](https://www.boxphish.com/guide-webinar/q3-education-data-breaches-report-from-boxphish/) - [How Boxphish supports the Cyber Governance Code of Practice](https://www.boxphish.com/guide-webinar/how-boxphish-supports-the-cyber-governance-code-of-practice/) - [Retail data breaches report: Q2 2025 (Aug to Oct 2025)](https://www.boxphish.com/guide-webinar/retail-data-breaches-report-q2-2025-aug-to-oct-2025/) - [Local authorities data breaches report: Q2 2025 (Aug to Oct 2025)](https://www.boxphish.com/guide-webinar/local-authorities-data-breaches-report-q2-2025-aug-to-oct-2025/) - [Education data breaches report: Q2 2025 (Aug to Oct 2025)](https://www.boxphish.com/guide-webinar/education-data-breaches-report-q2-2025-aug-to-oct-2025/) - [Empowering your human firewall: How Boxphish is redefining cyber resilience for SMBs](https://www.boxphish.com/guide-webinar/empowering-your-human-firewall-how-boxphish-is-redefining-cyber-resilience-for-smbs/) - [Cyber awareness month 2025](https://www.boxphish.com/guide-webinar/infographic-pack-cyber-awareness-month-2025/): Keep cyber advice front of mind with our latest infographic pack. Ideal for notice boards, intranets and digital signage around your organisation. - [Local authorities data breaches report: Q1 2025 (May to July 2025)](https://www.boxphish.com/guide-webinar/local-authorities-data-breach-report-q1-2025/) - [Retail data breaches report: Q1 2025 (June & July 2025)](https://www.boxphish.com/guide-webinar/retail-data-breaches-report-june-july-2025/) - [Education data breaches report: Q1 2025 (June & July 2025)](https://www.boxphish.com/guide-webinar/education-data-breach-report-june-july-2025/) - [Education data breaches report: Q1 2025 (May 2025)](https://www.boxphish.com/guide-webinar/education-data-breaches-report-may-2025/) - [Education data breaches report: Q4 2024 (April 2025)](https://www.boxphish.com/guide-webinar/education-data-breaches-report-april-2025/): A comprehensive overview of data leak incidents impacting the UK education sector during the month of April, along with security recommendations to help mitigate the risk of similar attacks. - [Transform your cyber culture: Enhancing security behaviours and reducing human risk](https://www.boxphish.com/guide-webinar/transforming-your-cyber-culture/): In our latest report, we explore the strategies and best practices necessary to enhance security behaviours, mitigate cyber risks, and build a resilient, positive cyber culture. - [Boxphish service overview](https://www.boxphish.com/guide-webinar/boxphish-service-overview/): Get a complete overview of the Boxphish platform. Our service overview explores the key areas of our platform, along with our top phishing simulations, training courses and reports. - [6 steps to spot a phishing email](https://www.boxphish.com/guide-webinar/phishing-prevention/): Keep cyber awareness and phishing front of mind with our 6-steps infographic. Ideal for staff rooms, intranets and digital signage around your organisation. ## News - [Boxphish continues growth journey with new VP appointment as team nears 50](https://www.boxphish.com/news/boxphish-continues-growth-journey-with-new-vp-appointment-as-team-nears-50/): It’s been another exciting period of growth at Boxphish, with our team now approaching 50 employees as we continue expanding our training portal, phishing simulations and human risk management platform to support organisations across the UK and beyond. - [Boxphish ranked in the top 25 of ‘Fastest Growing Tech Companies’ in the North](https://www.boxphish.com/news/boxphish-ranked-in-top-25/): Boxphish is proud to announce that we have been ranked in the top 25 of the fastest growing northern tech companies. We came in at number 21 in the GP Bullhound Northern Tech Awards Top 100.  - [Boxphish achieves Cyber Essentials Plus certification](https://www.boxphish.com/news/boxphish-achieves-cyber-essentials-plus-certification/): Boxphish is proud to announce that we have successfully achieved Cyber Essentials Plus certification, further reinforcing our commitment to maintaining robust cyber security standards across our business, systems and customer platform. - [TD SYNNEX partners with Boxphish to enhance cyber security offerings for partners](https://www.boxphish.com/news/td-synnex-partners-with-boxphish-to-enhance-cyber-security-offerings-for-partners/): TD SYNNEX has announced a strategic alliance with Boxphish, enabling partners to deliver greater value to their customers through Boxphish’s subscription-based cyber security offerings. - [Safeguard your students: Boxphish launches student training ahead of the new term](https://www.boxphish.com/news/back-to-school-boosting-cyber-awareness-with-free-posters/): As students return to school this autumn, one thing is clearer than ever, cyber security education is crucial. With schools being prime targets for cyber attacks, it’s vital to equip students with the knowledge they need to stay safe online. To help, we’re offering free, downloadable posters designed to raise awareness and promote cyber security best practices in schools. These posters, aimed staff and both primary and secondary students, cover key topics that can protect them and the school from online threats.  - [Boxphish launch new licensing agreement with Jisc, strengthening cyber protection across UK education](https://www.boxphish.com/news/boxphish-launch-new-licensing-agreement-with-jisc-strengthening-cyber-protection-across-uk-education/): Boxphish, the UK-based cyber security awareness training provider, is proud to announce its collaboration with Jisc to make its high impact, manageable cyber awareness training tailored for education institutions more accessible. - [Boxphish cements commitment to Yorkshire with office move](https://www.boxphish.com/news/boxphish-cements-commitment-to-yorkshire-with-office-move/): Boxphish – a Leeds-headquartered human risk management platform – has cemented its commitment to the region, after signing a long-term lease on new city centre office space. - [BGF-backed Boxphish goes for growth after year of expansion](https://www.boxphish.com/news/bgf-backed-boxphish-goes-for-growth-after-year-of-expansion/): BGF-backed human risk management platform Boxphish is targeting continued growth, following a year of expansion post-investment. - [Boxphish achieves NCSC Assured Training status for cyber security training content](https://www.boxphish.com/news/boxphish-achieves-ncsc-assured-training-status-for-cyber-security-training-content/): Boxphish, a leading provider of cyber security awareness training, is proud to announce that its training content has been officially accredited by the National Cyber Security Centre (NCSC). - [Boxphish acquires dark web threat intelligence platform](https://www.boxphish.com/news/boxphish-acquires-dark-web-threat-intelligence-platform/): Boxphish – a Leeds-headquartered human risk management platform – has announced its acquisition of Trillion, an advanced threat intelligence service which tracks credentials shared on the dark web. - [Boxphish makes The Yorkshire Tech Climbers 2024 list](https://www.boxphish.com/news/tech-climbers-award/): Boxphish has been named as one of the region’s tech stars in this year’s Tech Climbers List. - [Boxphish secures BGF backing to accelerate growth](https://www.boxphish.com/news/boxphish-secures-bgf-backing-to-accelerate-growth/): Boxphish, a Leeds-headquartered human risk management business, has announced a £3.25 million investment from BGF. - [Boxphish celebrates impressive growth alongside launch of new academy and recruitment drive](https://www.boxphish.com/news/boxphish-celebrates-impressive-growth-alongside-launch-of-new-academy-and-recruitment-drive/): Boxphish, the Leeds-based cyber security training company, has announced growth plans following a strong year.   - [Boxphish acquires backing for international expansion](https://www.boxphish.com/news/boxphish-acquires-backing-for-international-expansion/): Following an investment of six-figures from Mercia Asset Management, part of the Northern Powerhouse Investment Fund (NPIF), Boxphish is set to expand across organisations in Europe and the Middle East, alongside increasing their UK reach throughout 2023. ## Podcasts - [Ep. 1: Everything changes but nothing does](https://www.boxphish.com/podcast/episode-one-everything-changes-but-nothing-does/): Nick Deacon Elliot and Andy Dancer discuss all things cyber; from data protection laws written for filing cabinets through to medieval history and running away from tigers in the jungle. We promise it’s relevant… ## - [Preston City Council](https://www.boxphish.com/?p=243491) - [Unmind](https://www.boxphish.com/?p=243485) - [University College School](https://www.boxphish.com/?p=243479) - [Spark Education Trust](https://www.boxphish.com/?p=243473) - [Hales Valley Trust](https://www.boxphish.com/?p=243467) - [North Lincolnshire Council](https://www.boxphish.com/?p=243461) - [Star Multi-Academy Trust](https://www.boxphish.com/?p=243455) - [Anthony Nolan](https://www.boxphish.com/?p=243449) - [Swim England](https://www.boxphish.com/?p=243436) ## Success Stories - [Housing 21 success story](https://www.boxphish.com/success-story/housing-21/) - [Hepworth Wakefield](https://www.boxphish.com/success-story/hepworth-wakefield/) - [Schofield Sweeney](https://www.boxphish.com/success-story/schofield-sweeney/) - [Morgan Sindall](https://www.boxphish.com/success-story/morgan-sindall/) - [Camfed](https://www.boxphish.com/success-story/camfed/) - [Marks & Clerk](https://www.boxphish.com/success-story/marks-clerk/) - [University College School](https://www.boxphish.com/success-story/university-college-school/) - [FM Conway](https://www.boxphish.com/success-story/fm-conway/) - [Pembroke College](https://www.boxphish.com/success-story/pembroke-college/) - [M&S Logistics](https://www.boxphish.com/success-story/ms-logistics/) - [Hales Valley Trust](https://www.boxphish.com/success-story/hales-valley-trust/) - [North Lincolnshire Council](https://www.boxphish.com/success-story/north-lincolnshire-council/) - [Preston City Council](https://www.boxphish.com/success-story/preston-city-council/) - [Star Multi-Academy Trust](https://www.boxphish.com/success-story/star-multi-academy-trust/) - [Swim England](https://www.boxphish.com/success-story/swim-england/) - [Unmind](https://www.boxphish.com/success-story/unmind/) - [Spark Education Trust](https://www.boxphish.com/success-story/spark-education-trust/) - [Coltella IT](https://www.boxphish.com/success-story/coltella-enhances-msp-offering/) - [Queen’s College Cambridge](https://www.boxphish.com/success-story/queens-college-cambridge/) - [Anthony Nolan](https://www.boxphish.com/success-story/anthony-nolan/)