Security training

Cyber Security Awareness Training

Reduce the risk your people carry. Phishing simulation through Microsoft Attack Simulation Training, role-based content, and measurement that shows behaviour change over time, not a one-off video nobody remembers.

Microsoft Defender for Office 365Phishing simulationMeasurable

Why it matters

Your people are the control most attackers target first

The majority of breaches start with a person, not a firewall: a convincing phishing email, a spoofed invoice, a multifactor prompt approved out of habit. Technical controls keep getting stronger, so attackers keep moving toward the human layer. The organisations that hold up are the ones that treat awareness as a measured, ongoing programme: realistic simulations, training that lands when someone slips, and a click-rate that falls quarter on quarter. A single annual training video does none of that.

An awareness programme you cannot measure is a compliance artefact, not a control. We run it so the click-rate trend is visible to leadership, because that trend is the point.

What it covers

Five parts of the awareness programme

Education paired with realistic simulation and measurement. Each part is calibrated to your sector and the way your people are actually targeted.

Phishing and social engineering

The threats that actually breach organisations: credential phishing, business email compromise, and the human pretexts behind them.

  • Recognising credential-harvesting and payload phishing
  • Business email compromise and invoice fraud patterns
  • Voice and message-based social engineering
  • Reporting a suspected message the right way

Microsoft Attack Simulation Training

Realistic phishing simulations run through Attack Simulation Training in Microsoft Defender for Office 365, not a third-party bolt-on.

  • Simulated phishing campaigns against real inbox conditions
  • Automatic training assignment for users who click
  • Payload library mapped to current attacker techniques
  • No extra platform where Defender for Office 365 is already licensed

Identity and everyday safe practice

The habits that close the most common gaps: strong authentication, device care and data handling.

  • Multifactor authentication and resisting MFA fatigue attacks
  • Password and passkey practice
  • Safe handling of sensitive information
  • Device, removable media and remote-work hygiene

Role-based and leadership content

Awareness calibrated to risk: finance, executives and privileged users get content matched to how they are targeted.

  • Finance and accounts payable fraud awareness
  • Executive and high-value-target briefings
  • Privileged and IT administrator practice
  • New-starter onboarding induction

Measurement and ongoing programme

Awareness is a programme, not a once-a-year video. Track behaviour change over time and report it to leadership.

  • Baseline simulation to measure starting risk
  • Repeat campaigns to track click-rate and report-rate trend
  • Leadership reporting on human risk posture
  • Cadence designed to sustain behaviour, not tick a box

The programme

How the training runs

Microsoft-native

Built on Attack Simulation Training in Microsoft Defender for Office 365 Plan 2, included with Microsoft 365 E5 and Office 365 E5. No separate awareness platform to license where you already hold the entitlement.

Flexible delivery

Live instructor-led sessions, online modules, and automated simulation campaigns. Combined into a programme that fits the audience and the risk profile.

Tailored to your risk

Content and simulation difficulty mapped to your sector, your roles and the threats your organisation actually faces, rather than a generic library.

Reportable outcomes

Click-rate, report-rate and training-completion tracked over time, so the programme produces a defensible measure of human risk for leadership and audit.

Selected engagements

The shape of work we deliver

Anonymised examples of typical Microsoft engagements. Named case studies are available under NDA on request.

Request a named case study

FAQs

Frequently asked questions: security awareness training

What is cyber security awareness training?

It is structured training that reduces the risk created by people: recognising phishing and social engineering, authenticating safely, handling sensitive data correctly, and reporting suspected attacks. Effective awareness training is an ongoing programme combining education with realistic phishing simulation and measurement, not a single annual video.

How does the phishing simulation work?

We use Attack Simulation Training in Microsoft Defender for Office 365 to run realistic simulated phishing campaigns against your own environment. Users who interact with a simulation are automatically assigned short, targeted training. Over repeated campaigns you can see click-rate fall and report-rate rise, which is the behaviour change that actually reduces risk.

Do we need a separate platform to run this?

Usually not. Attack Simulation Training is part of Microsoft Defender for Office 365 Plan 2, which is included with Microsoft 365 E5 and Office 365 E5. If you already hold that entitlement, you can run a full simulation and training programme without licensing a third-party awareness tool. We confirm your licensing position before recommending an approach.

How does awareness training fit into our wider security posture?

People are a primary attack surface, so awareness sits alongside technical controls rather than replacing them. It complements identity hardening, email protection and the broader control set. Our Microsoft Security page covers the technical controls, and the Essential Eight page covers the maturity model many organisations align to; awareness training addresses the human layer across all of them.

Can the training be tailored to specific roles?

Yes. Finance teams, executives, privileged administrators and new starters are targeted differently by attackers, so they receive content matched to their risk. Simulation difficulty is also calibrated by role rather than sending everyone the same generic email.

How do you measure whether the training is working?

We baseline with an initial simulation, then track click-rate, report-rate and training-completion across repeat campaigns. The trend over time is the measure that matters, and it gives leadership and auditors a defensible picture of human risk rather than an attendance record.

Request a security awareness programme

Tell us your size, sector and licensing position and we will recommend a programme shape, a simulation cadence, and the reporting leadership will want to see. One business day.

UHS Logic · Microsoft Solutions Partner