Most SMEs that train their teams do so once a year, over half a day, with an external speaker and plenty of good will. Three months later, almost nothing remains. This is not a problem of motivation or of the speaker’s quality. It is a problem of format.
An effective awareness programme requires neither a training department nor a large budget. It requires regularity, one topic at a time, and an honest way of checking that it produces something.
Why doesn’t the single annual session work?
Information received only once fades quickly. This is true of any kind of learning, and particularly true of instructions that are not applied every day. A few weeks after the session, the employee remembers that they should “watch out for strange e-mails”, but no longer remembers the concrete signals that distinguish a legitimate message from a phishing attempt.
The format itself makes the problem worse. Three hours in a row on a dozen topics produce saturation. People remember the beginning, a little of the end, and nothing from the middle.
For the same total time, five twenty-minute sessions spread across the year produce a markedly more lasting effect than a single two-hour session. It is not the volume of information that matters, it is the number of times the topic comes back. Each reminder reactivates what was starting to fade.
There is a second, more strategic reason. Attack methods evolve throughout the year. An annual training session describes the landscape as it stood eleven months ago. A programme that comes back regularly makes it possible to include what is circulating right now, including attempts your own company has received.
What format is realistic for an SME?
The format that holds up over time is deliberately modest: fifteen to thirty minutes, four to six times a year, on a single topic each time.
Three principles make it workable without a training department.
One topic per session. Covering phishing and passwords on the same day dilutes both. One session, one message, one action to remember.
An existing moment. Attach the session to a team meeting, a monthly catch-up or a briefing. Creating a new slot in the calendar is the surest way to see it cancelled during the first busy quarter.
Examples that come from your own company. The most effective message is a real attempt received by the company, anonymised and shown on screen. It carries the names of your suppliers, your vocabulary, your amounts. No generic example has that strength.
Also plan an induction session for every new person. A ten-minute awareness session on arrival is worth more than waiting eight months for the next group session.
A ready-to-use annual programme
The order of the topics is not indifferent. Start with the most frequent entry point, then move up towards what protects accounts, then towards attacks that target money directly.
| Period | Topic | Message to convey | Material |
|---|---|---|---|
| January | Phishing | Recognising a message that tries to make you click under pressure | Real attempts received by the company |
| March | Passwords and two-factor authentication | One unique password per service, and a second proof for sensitive access | Demonstration of the internal password manager |
| May | CEO fraud | Any request for payment or a change of bank details is checked through another channel | Scenario acted out aloud in the meeting |
| September | Personal data | What is confidential, where it is stored, what should not be sent by e-mail | Examples of internal documents |
| November | The reflex of doubt | Who to notify, how, and why reporting carries no penalty | Reminder of the procedure, on a single page |
This calendar is a starting point, not a standard. A company that handles a lot of payments will move the CEO fraud session forward. A company that has just experienced a phishing attempt will address the topic the following week, while it is still concrete for everyone.
Each topic corresponds to a threat detailed elsewhere on this site, which gives you material to prepare the session: phishing, CEO fraud and social engineering.
Adapt to the job, or half the effect is lost
An identical session for the whole company starts from a laudable intention and produces an average result. Employees are not exposed to the same attacks depending on their role.
Accounting receives urgent payment requests, changes to suppliers’ bank details, altered invoices. It is the function most directly targeted by CEO fraud.
Sales staff and management publicly expose their address, their role and their movements. They receive personalised messages, built from real information found online.
Production or workshop teams often use shared workstations, site tablets, sometimes connected equipment. Their risk lies more in shared access and USB drives than in targeted e-mails.
Typical scenario. A twenty-person SME keeps its five shared sessions, and adds twenty minutes reserved for accounting: an exercise where the manager reads aloud a fake supplier e-mail announcing a new IBAN number. The team describes what they would do. The rule that comes out of it fits in one sentence, and it is written down and displayed: any change of bank details is confirmed by phone, on the number we already had.
What should actually be measured?
This is where most programmes go wrong. People measure the number of people trained, because it is easy to count. This indicator says nothing: it measures presence, not behaviour.
Three indicators are far more telling.
The number of reports, which should increase. A rise in suspicious messages reported internally is a good sign, not a bad one. It means employees are noticing and daring to speak up. A company where no one ever reports anything is not a company that has been spared, it is a company that is blind.
The reporting delay. Between the moment someone clicks and the moment they say so, hours or days go by. This delay directly determines the scale of the damage. Seeing it shrink from a week to an hour is worth more than any participation rate.
The proportion of false positives. Employees who sometimes report perfectly legitimate messages are not a problem, it is a sign of active vigilance. The opposite deserves attention.
To obtain these three figures without waiting for a real attack, there is a tool: phishing simulations, useful provided you measure the reporting rate as much as the click rate, and never publish named results.
A simple shared table, with the date, the type of message and the delay between receipt and report, is enough to track progress over a year. It is the cheapest measurement tool there is, and the only one that tells you whether your programme is changing anything rather than whether it was followed.
What free resources should you use?
You do not need to produce everything yourself.
The national S-U-P-E-R campaign, run by the Confederation and its prevention partners, offers materials structured around four actions: update, back up, protect access and stay alert to messages. The format is short and can be projected directly in a meeting.
The Federal SME portal brings together fact sheets for businesses, and the National Cyber Security Centre regularly publishes examples of ongoing attacks in Switzerland, which make excellent session material because they are current. iBarry offers ready-to-use general-public awareness content.
These materials still need to be assembled and delivered by someone. For companies that prefer an already-built course, we are preparing online training courses for French-speaking Swiss SMEs.
Without management, the message does not get through
This is the factor that makes the difference between a programme that is followed and a programme that is endured. If the head of the company does not attend the sessions, everyone understands that the topic is secondary, and behaves accordingly.
Management’s participation sends three messages at once: the topic matters, the rules apply to everyone, and reporting a mistake will not be punished. This last point is decisive. CEO fraud works precisely because an employee does not dare contradict a request that appears to come from above. A manager who says publicly “if you receive an urgent request from me, check it, even if it really is me” removes the essential lever the attacker relies on. What this message produces over time, and the management reflexes that unwittingly cancel it out, are detailed in creating a security culture without blame.
Finally, make sure management announces the programme at the start of the year, and communicates the reporting indicators once a year. A team that sees its reports being put to use keeps reporting.
Where what you can do alone stops
Everything above is within your reach without a budget or a training department. A programme built this way already rules out a large share of automated attempts, and above all it turns your employees into a detection system.
Two limits remain. The first concerns adaptation: knowing which attacks genuinely target your company requires knowing your financial flows, your suppliers and your sensitive data, which no generic programme can guess. The second concerns measurement: honestly judging whether a programme changes behaviour is difficult when you designed it yourself, since you spontaneously measure what confirms what you hope for.
This programme forms a solid foundation. It does not replace an outside view of your specific risks and of the real effect of your sessions. To gauge your current level, the cyber check-up devotes several questions to team training. The other components are brought together in the Training your teams pillar, and the technical measures that go alongside awareness-raising in the 10 essential measures.