Hybrid work models are popular in today’s workforce, with approximately 48% of companies operating in a hybrid model. Due to this shift, email and collaboration tools are essential in the modern workplace. However, these technologies can also create serious risks for businesses — ultimately impacting the bottom line. Cybersecurity solutions are key to protecting a company’s data, customer base and reputation; but it doesn’t start and end with technology. A cybersecurity system is only as strong as its weakest link, and in this case, the weakest link is human error. In other words, the workplace’s largest cyber risk can be your employees. Without regular training, your greatest asset can become your greatest risk.
According to Mimecast’s 2023 State of Email Security Report, over 90% of security breaches involve some degree of human error. Mimecast’s e-book, “Collaboration Security: Risks & Realities of the Modern Work Surface,” indicates that all cybersecurity leaders claim that their organization offers dedicated cybersecurity training for collaboration tools; however, only 10% of employees say they’ve received such training, and nearly 2 in 5 claim they’ve not received any training on collaboration tools whatsoever.
And according to Mimecast’s research: Nearly all workers (97%) can’t identify even a crude phishing email when they receive one. Lastly, while many employees report that they’ve become more cautious about their behaviors on hybrid work platforms, their actions show just the opposite. While many employees report that they’ve become more cautious about their behaviors on hybrid work platforms, their actions show just the opposite.
The two key takeaways are:
- Proper cyber awareness can make or break the effectiveness of a cybersecurity program.
- A vast majority of current cyber awareness trainings are insufficiently effective.
The path forward is effective cyber awareness training and fostering a culture of cybersecurity. With the right training, companies have the opportunity to transform workers from their weakest link into an active part of the firewall.
How to Create Effective Cyber Awareness Training
The first step of effective cyber awareness training is ensuring your learning and development (L&D) strategy covers all the important security risks. Trainings should span topics such as:
- Creating strong passwords.
- Protecting personal information.
- Recognizing phishing attacks.
- Recognizing social engineering attacks, and ensuring payment card industry (PCI) compliance.
- Complying with Health Insurance Portability and Accountability Act (HIPAA) guidelines.
- Evading ransomware attacks.
- Recognizing CEO fraud.
- Securing paper, desks and screens within the office.
- Understanding employee data privacy rights.
However, effective training is not only about delivering the right content and insights. In order to drive meaningful behavioral change, cyber awareness training must be engaging, persistent and nonintrusive. An effective cyber awareness training should reinforce cybersecurity principles on a continual basis while offering employees an entertaining break in their day. These training courses are dramatically more impactful than longer and less frequent trainings that employees race to finish. To ensure employees not only join sessions but actually retain the information and embed better practices into their daily lives, it’s essential that business leaders take a new approach.
- Empower employees with engaging training videos. When it comes to cybersecurity trainings, it’s common for sessions to focus on the mistakes employees make, instead of creating a welcoming environment where employees feel encouraged to learn and do better. Take the time to make employees feel like they’re an important part of the mission-critical process of defending the business against cyberattacks. An effective way to do this is through engaging, video-based training modules. Videos can cover various threats, how to react and potential consequences for the company or individual.
- Monitor and incentivize attendance. To understand the efficacy of training programs, leaders must get a sense of employee participation in sessions. This includes how quickly they’re to accept and complete a training, whether they need some kind of follow-up to take the next step, and in some cases, identifying ways to motivate employees to join. By offering something as simple as free lunch or gift cards, you can drive up employee participation and excitement.
- Create benchmarks for success. Setting goals is essential for measuring the progress of any initiative, and training is no different. Leaders should take the time to understand the desired outcome of training — such as the obvious objective of lowering incident rates year-over-year — to understand what’s working and areas to improve.
- Measure performance against benchmarks. Asking questions before employees receive any kind of training can help to gauge an employee’s baseline knowledge on security threats. Asking the same questions can reveal immediate knowledge they’ve gained from the training. Both an employee’s role at a company and how well they perform on security testing can determine the level of risk they bring to the company, and risk scores can be used to direct additional training resources to employees that would benefit from it. Organizations should also take the testing one step further, not just based on the content, but actual security tests like sending de-weaponized phishing attacks the company faced to make sure they’re not getting clicked on.
Collaboration tools are not going anywhere as hybrid workforce models become more common. The impact of ineffective cyber awareness training is far-reaching and detrimental to a business. In addition to financial losses, Mimecast’s research found that cyberattacks result in a loss of company data (54%), potential customers (36%), current customers (32%) and a damaged reputation (30%).
The stakes have never been higher to mitigate cyber risks and this starts with better training.

