Pillar 04 ยท Develop

Cyber Security Training and Staff Development

You can spend a fortune on technology and still be undone by one person having a bad Tuesday.

This is not a criticism of your staff. It is how modern attacks work. Phishing was the most common attack type reported by UK businesses in the government's 2025/26 Cyber Security Breaches Survey, hitting 38% of them, which is more than three times the next most common category. Attackers target people because people are reachable, and because a convincing email costs nothing to send.

Fourarmed's cyber security awareness training treats your staff as a security control, which is what they are. Get it right and they become the layer that catches what the technology missed. We deliver training across the UK from our base in Bristol.

Format
Interactive in-person workshops, online on request
Tailoring
Examples drawn from your sector and your business
Measurement
Click rate, reporting rate, time to report, credential submission
Simulation policy
Aggregated for management. We do not name individuals.
Also covers
Role-specific sessions, inductions, tabletop exercises
Evidence
Attendance and simulation records for renewal and certification

The Human Factor in Cyber Security

The control with the most room for improvement

Here is the uncomfortable thing about people as a control. They are the only factor that can be improved without buying anything, and the one most organisations invest in least.

The typical approach is an annual e-learning module. Everyone clicks through it, some people watch it, and the completion report goes in a folder to show an auditor. It changes almost nothing, because it was designed purely to provide evidence that training happened.

What shifts behaviour is more specific and more awkward. Show someone a phishing email naming their own supplier, their own finance system and their own managing director, and it lands in a way that a stock example never will. Walk them through the invoice fraud that nearly worked at a business like theirs. Finally, make it completely safe for them to say: "I think I've clicked something".

In most breaches involving a person, the damage is done in the gap between the click and the report.

Often, someone realises something is wrong, feels stupid, and waits an hour, a morning or a weekend before telling anyone. Closing that gap is often the single highest-value thing that training achieves, and it is a cultural change more than a knowledge one.

Cyber Awareness Training Workshops

Working sessions, not lectures

Our core offering is interactive, in-person workshops. These are working sessions, not lectures. People look at real examples, argue about which ones are fake, and get things wrong in a room where it costs nothing. A typical workshop covers:

How attacks arrive

Phishing, spear phishing, business email compromise, malicious attachments, fake login pages, and the increasing use of AI to write convincing English. Also the ones people forget, such as text messages, phone calls, QR codes, and someone walking in wearing a hi-vis.

Reading an email properly

Sender domains, display-name spoofing, reply-to mismatches, urgency as a tactic, and the specific pressure signature of a request pretending to come from a director.

Invoice and payment fraud

How changed bank details work, why "the finance director asked me to do it quickly" is the whole attack, and what a verification step should look like.

Passwords and MFA

Why reuse is the real problem, how password managers work, and what to do when an MFA prompt arrives that you did not trigger, which is a genuine attack in progress and widely ignored.

Data handling

Where company data is allowed to live, the risks of personal devices and shadow IT, and what to do with a lost laptop or phone.

Reporting

Who to tell, how fast, and the firm commitment that nobody gets in trouble for reporting.

We tailor the examples to your business. A session for a firm of solicitors or accountants uses conveyancing and payment fraud, one for a manufacturer uses supplier impersonation, and one for a defence supplier covers the targeting that comes with being part of a sensitive supply chain.

Phishing Simulation and Testing

Two rules we abide by

Training tells people what to look for. Simulation tells you whether it worked.

We send controlled, realistic phishing emails to your staff and measure what happens. Who clicks, who enters credentials, who reports it, and how quickly. Then we do it again later with different bait.

Simulation also produces something useful for the board: a number that moves.

  • Simulations are never used to catch people out or to build a case against anyone. The data is aggregated for management and the individual coaching is supportive, because programmes that feel like traps destroy the reporting culture you are trying to build.
  • The reporting rate matters as much as the click rate. An organisation where 30% of people click but 60% report is in better shape than one where nobody does either, because the second one is quietly blind.

Customised Training Programmes

One workshop raises awareness, a programme changes behaviour

For clients who want more than a one-off, we build a rolling schedule. Typically this involves an initial all-staff workshop, then quarterly simulations with short follow-up sessions, plus targeted content for the people at highest risk. This last group is usually finance, HR, executive assistants and anyone whose email address is on the website.

Role-specific sessions

Finance teams get payment fraud in depth. Senior leaders get whaling and the specific ways they are targeted. IT staff get the operational side of response. Shop-floor and operational staff get the physical and removable-media angles that office-based training skips.

New starter induction

A short module in week one, when habits are being formed and nobody has learned to ignore the intranet yet.

Incident scenario exercises

A tabletop walkthrough of a realistic breach: who decides what, who calls the insurer, what you tell customers, and who is authorised to take systems offline at 9pm on a Friday. Tabletop exercises reliably surface gaps that a written plan does not.

Policy people can follow

Acceptable use policies tend to be written for auditors and are too long to be used by anyone else. We will help you produce something shorter.

Training works best alongside the technical picture. If we have run a cyber security audit or risk assessment for you, we build the programme around what it found. There is no point spending a session on removable media if nobody uses it.

Measuring Results

Five numbers we report

Training that cannot be measured is impossible to justify at budget time, so we measure:

  • Phishing click rate, tracked over successive simulations. We would expect a meaningful drop between the first round and the third.
  • Reporting rate, and time to report. The number we care about most.
  • Credential submission rate, meaning how many people went past clicking and typed a password. This is the one that turns into an incident.
  • Repeat clickers, so support goes where it is needed most rather than everywhere equally.
  • Completion and engagement across sessions, for the audit trail and for certification evidence.

You get a short report after each round, including what we sent, what happened, how it compares to last time, and what we would focus on next.

One caution about the numbers. A click rate that falls to zero usually means the simulations have become too easy or too familiar, and not that the risk has gone. We vary the difficulty deliberately, and a well-run programme should keep catching a few people. This is the sign it is still testing something real. What you want is a workforce that reports quickly, not one that has learned to identify our test emails.

Keep these reports. Since Fourarmed came out of an insurance broker, we know how much weight an underwriter puts on evidence of staff training at renewal. A year of simulation results and attendance records answers a question most applicants can only assert an answer to. The same records support the awareness expectations that come with Cyber Essentials certification. More on our cyber insurance page.

Common questions

Five questions
How long is a training workshop?
Our core offering is an interactive, in-person workshop run as a working session rather than a lecture. The usual starting point for an organisation is a single all-staff workshop with a baseline phishing simulation.
Do you deliver training online?
Training is delivered in person by default, because the interactive format is what shifts behaviour. Online delivery is available on request.
How many people can attend?
Sessions are built around your business and your team, so numbers are agreed as part of scoping. Where a workforce is large or shift-based we build a rolling schedule instead of one session.
How often should staff be retrained?
For clients who want more than a one-off we build a rolling schedule: an initial all-staff workshop, then quarterly simulations with short follow-up sessions, plus targeted content for the people at highest risk.
Will you tell us who clicked?
No. Simulation data is aggregated for management and individual coaching is supportive. Programmes that feel like traps destroy the reporting culture you are trying to build, which is the thing that actually reduces harm.
Book a training session

Start with one workshop and a baseline

Smaller organisations often get the most benefit from this, because training is the one control that scales down without losing its value. The usual starting point is a single all-staff workshop with a baseline phishing simulation. It is a low-commitment way to find out where you stand, and the results tend to make the case for whatever comes next.