Small businesses in the UK face the same cyber risks as large firms. Your team is your first line of defence. This guide shows you how to set up a simple training plan that works. It fits real life. It is easy to run. It links to your policies and Cyber Essentials goals.
Who this guide is for
Owners. Office managers. HR leads. Anyone who needs a plain English plan that staff can follow.
Does everyone need training?
Yes. Every team needs cyber security training. Start small, keep it regular and make it part of onboarding. Run short refreshers across the year and test with phishing simulations. Track the results and improve.
Objectives for your training
- Help staff spot and report phishing and social engineering.
- Build safe habits for passwords, MFA, device lock, and updates.
- Reduce risky actions in email, Teams, and the web.
- Make incident reporting fast and simple.
- Show that your business follows UK best practice and supports Cyber Essentials.
Minimum viable training plan (works for teams of 5 to 100)
Format: short sessions that fit the working week.
- On day 1 for new starters 30 minutes. Intro to threats, passwords and MFA. How to report an incident. Your Acceptable Use and Email use rules. Top it off with a quick quiz.
- Monthly microโlearning 10 to 15 minutes. One topic per month.
- Phishing simulations at least once per month. Send 1 to 3 test emails to each user. Coach anyone who clicks through.
- Quarterly refresher 30 minutes. Review real incidents. Share the top 5 risky behaviours to avoid and run a quick quiz.
- Annual summary 45 minutes. Review results. Set targets for next year.
Target outcomes
- Fewer clicks on phishing tests over time.
- Everyone passes the short quizzes.
- Staff report suspicious emails fast.
Onboarding checklist for new starters
Use this as a simple list for IT and HR.
- Add the user to your password manager and MFA.
- Enrol their device in management. Apply baseline security settings.
- Share the Acceptable Use Policy and Email and Communications Policy.
- Show how to report a suspected incident. Give the support email and phone number.
- Book the first phishing simulation within 30 days.
- Assign the first two microโlearning modules.
90โday starter plan
Week 1 Welcome session. Passwords. MFA. Safe email use.Quiz. Score target 80 percent or more.
Week 2 Microโlearning video. How to spot a phishing link.
Week 3 First phishing simulation.
Week 4 Debrief for anyone who clicked. 1 to 1 coaching. 10 minutes.
Weeks 5 to 8 Modules on safe browsing, Teams and SharePoint sharing, and secure file transfer.
Weeks 9 to 12 Second phishing simulation. Then a short refresher session.
Annual cadence for the whole team
- January Passwords and MFA. Reset weak passwords.
- February Phishing and smishing.
- March Data handling and sharing.
- April Device security on the move.
- May Teams and meeting invites.
- June Backups and ransomware basics.
- July Social engineering in the office and by phone.
- August Cloud file permissions.
- September Patch and update habits.
- October Cyber Security Awareness Month. Run a miniโcampaign.
- November Fraud awareness for finance teams.
- December Year in review. Lessons learned.
Add a short phishing simulation every month.
Roleโbased modules
- Finance invoice fraud, supplier bank change scams, and approval rules.
- Sales safe sharing of proposals, CRM hygiene, and link safety.
- HR data privacy, right to work and ID checks, and handling CVs.
- Leadership incident response basics and how to set a good tone.
- IT champions how to help peers and collect feedback.
Make it policyโbacked
Training works best when it matches your policies. Tie modules to these documents.
- Acceptable Use Policy.
- Password and MFA Policy.
- Email and Communications Policy.
- Incident Response Plan.
- Data Protection and Retention Policy.
Show staff where these live. Keep them easy to read. Review them once per year.
How to measure success
Pick simple KPIs.
- Phishing simulation click rate. Aim to reduce it each quarter.
- Report rate. Count how many suspicious emails staff report.
- Quiz pass rate. Aim for 90 percent or more on short quizzes.
- Completion rate. Track who finished each module.
Share a one page dashboard with the team every month. Celebrate wins.
Tools that help
- Managed email security that tags external senders and risky links.
- Phishing simulations with targeted coaching.
- Short videos and biteโsize modules that staff can watch on any device.
- Device management that keeps laptops and mobiles up to date.
Tip. Bundle training with your helpdesk and onboarding process. This keeps it alive.
Simple staff checklist
- I can spot a phishing email and report it.
- I use a password manager and MFA.
- I lock my device when I leave my desk.
- I know how to share files safely inside and outside the company.
- I know how to report a suspected incident.
Print this and keep it near the desk.
When to refresh the plan
Update your content when any of these change.
- New risks or scams that hit your industry.
- Changes to your policies or tools.
- New staff join the team.
FAQs
Short sessions every month work well. Run at least one phishing simulation every month. Add a 30 minute quarterly refresher.
Cyber Essentials focuses on technical controls. Training supports those controls and helps your team follow them. Most UK firms use training to prove staff awareness and support their audit.
Aim for 80 percent or more for new starters. Aim for 90 percent on short refreshers after three months.
Yes. Leaders need a simple view of risk and the plan for incidents. Give them a short session on roles and responsibilities
Coach in a friendly way. Show what to look for next time. Send a follow up test a week later.
Nxt steps
If you want help, we can set your Cyber Security Training Plan up for you. We run the content. We run the phishing tests. We report results each month. Your team gets better over time.
Talk to us
- Cyber Awareness Training service page
- Phishing Simulations service page
- Cyber Essentials support page
Ben helps growing businesses turn technology into a driver of performance instead of a barrier. At Nxt Gen IT he works with SME leaders, recruiters, and fast-scaling teams to design solutions that improve reliability, strengthen security, and unlock growth.
With a background in email deliverability and cloud systems, Ben specialises in making sure businesses communicate effectively, keep data safe, and get the most from Microsoft 365. His experience spans solution design, managed IT services, and virtual CIO support, always with a focus on practical outcomes that reduce headaches for business owners.
Ben has supported organisations across the UK, from recruitment agencies struggling with inbox placement to SaaS firms scaling fast, and SMEs needing a trusted partner for their IT. He believes tech is never the end goal: growth is. His role is to make sure technology never gets in the way of it.
