Employee Cyber Security Training Plan for UK SMEs

By: Ben Fielding | Estimated Reading Time: 4 minutes

Small businesses in the UK face the same cyber risks as large firms. Your team is your first line of defence. This guide shows you how to set up a simple training plan that works. It fits real life. It is easy to run. It links to your policies and Cyber Essentials goals.

Who this guide is for

Owners. Office managers. HR leads. Anyone who needs a plain English plan that staff can follow.


Does everyone need training?

Yes. Every team needs cyber security training. Start small, keep it regular and make it part of onboarding. Run short refreshers across the year and test with phishing simulations. Track the results and improve.


Objectives for your training

  1. Help staff spot and report phishing and social engineering.
  2. Build safe habits for passwords, MFA, device lock, and updates.
  3. Reduce risky actions in email, Teams, and the web.
  4. Make incident reporting fast and simple.
  5. Show that your business follows UK best practice and supports Cyber Essentials.

Minimum viable training plan (works for teams of 5 to 100)

Format: short sessions that fit the working week.

  • On day 1 for new starters 30 minutes. Intro to threats, passwords and MFA. How to report an incident. Your Acceptable Use and Email use rules. Top it off with a quick quiz.
  • Monthly microโ€‘learning 10 to 15 minutes. One topic per month.
  • Phishing simulations at least once per month. Send 1 to 3 test emails to each user. Coach anyone who clicks through.
  • Quarterly refresher 30 minutes. Review real incidents. Share the top 5 risky behaviours to avoid and run a quick quiz.
  • Annual summary 45 minutes. Review results. Set targets for next year.

Target outcomes

  • Fewer clicks on phishing tests over time.
  • Everyone passes the short quizzes.
  • Staff report suspicious emails fast.

Onboarding checklist for new starters

Use this as a simple list for IT and HR.

  • Add the user to your password manager and MFA.
  • Enrol their device in management. Apply baseline security settings.
  • Share the Acceptable Use Policy and Email and Communications Policy.
  • Show how to report a suspected incident. Give the support email and phone number.
  • Book the first phishing simulation within 30 days.
  • Assign the first two microโ€‘learning modules.

90โ€‘day starter plan

Week 1 Welcome session. Passwords. MFA. Safe email use.Quiz. Score target 80 percent or more.

Week 2 Microโ€‘learning video. How to spot a phishing link.

Week 3 First phishing simulation.

Week 4 Debrief for anyone who clicked. 1 to 1 coaching. 10 minutes.

Weeks 5 to 8 Modules on safe browsing, Teams and SharePoint sharing, and secure file transfer.

Weeks 9 to 12 Second phishing simulation. Then a short refresher session.


Annual cadence for the whole team

  • January Passwords and MFA. Reset weak passwords.
  • February Phishing and smishing.
  • March Data handling and sharing.
  • April Device security on the move.
  • May Teams and meeting invites.
  • June Backups and ransomware basics.
  • July Social engineering in the office and by phone.
  • August Cloud file permissions.
  • September Patch and update habits.
  • October Cyber Security Awareness Month. Run a miniโ€‘campaign.
  • November Fraud awareness for finance teams.
  • December Year in review. Lessons learned.

Add a short phishing simulation every month.


Roleโ€‘based modules

  • Finance invoice fraud, supplier bank change scams, and approval rules.
  • Sales safe sharing of proposals, CRM hygiene, and link safety.
  • HR data privacy, right to work and ID checks, and handling CVs.
  • Leadership incident response basics and how to set a good tone.
  • IT champions how to help peers and collect feedback.

Make it policyโ€‘backed

Training works best when it matches your policies. Tie modules to these documents.

  • Acceptable Use Policy.
  • Password and MFA Policy.
  • Email and Communications Policy.
  • Incident Response Plan.
  • Data Protection and Retention Policy.

Show staff where these live. Keep them easy to read. Review them once per year.


How to measure success

Pick simple KPIs.

  • Phishing simulation click rate. Aim to reduce it each quarter.
  • Report rate. Count how many suspicious emails staff report.
  • Quiz pass rate. Aim for 90 percent or more on short quizzes.
  • Completion rate. Track who finished each module.

Share a one page dashboard with the team every month. Celebrate wins.


Tools that help

  • Managed email security that tags external senders and risky links.
  • Phishing simulations with targeted coaching.
  • Short videos and biteโ€‘size modules that staff can watch on any device.
  • Device management that keeps laptops and mobiles up to date.

Tip. Bundle training with your helpdesk and onboarding process. This keeps it alive.


Simple staff checklist

  • I can spot a phishing email and report it.
  • I use a password manager and MFA.
  • I lock my device when I leave my desk.
  • I know how to share files safely inside and outside the company.
  • I know how to report a suspected incident.

Print this and keep it near the desk.


When to refresh the plan

Update your content when any of these change.

  • New risks or scams that hit your industry.
  • Changes to your policies or tools.
  • New staff join the team.

FAQs

How often should staff do cyber security training?

Short sessions every month work well. Run at least one phishing simulation every month. Add a 30 minute quarterly refresher.

Is training required for Cyber Essentials?

Cyber Essentials focuses on technical controls. Training supports those controls and helps your team follow them. Most UK firms use training to prove staff awareness and support their audit.

What is a good pass mark for quizzes?

Aim for 80 percent or more for new starters. Aim for 90 percent on short refreshers after three months.

Do I need different training for leaders?

Yes. Leaders need a simple view of risk and the plan for incidents. Give them a short session on roles and responsibilities

How do I handle people who fail tests?

Coach in a friendly way. Show what to look for next time. Send a follow up test a week later.


Nxt steps

If you want help, we can set your Cyber Security Training Plan up for you. We run the content. We run the phishing tests. We report results each month. Your team gets better over time.

Talk to us