Which attacks should an employee recognise?
Start with phishing: a message pushes someone to open an attachment, enter credentials or act urgently. A familiar logo, tone or displayed sender does not prove identity. Employees should slow down, inspect a link's destination and return to the service or contact through a known route.
Business email compromise (BEC) impersonates an executive, supplier or colleague to request a payment, change bank details or obtain sensitive data. The reliable response is a process, not intuition: verify every unusual financial request through a second, previously known channel, never the number supplied in the message.
Which habits matter most?
- Turn on MFA. Use multi-factor authentication wherever offered and never approve a prompt you did not initiate.
- Use a password manager. A long, unique password for every service stops one breach opening several accounts. Use the manager approved by the company.
- Install updates. Restart when asked and do not postpone operating-system, browser and application patches indefinitely.
- Protect data. Do not bypass approved sharing tools, and check recipients and permissions before sending.
These controls work together: MFA does not repair an outdated device, and a strong password cannot stop a payment that someone authorises under pressure. The French cybersecurity agency's cyber hygiene guide provides a broader organisational baseline.
What should remote workers know about devices?
A work computer remains the employee's responsibility away from the office. Lock the screen when stepping away, prevent household access, use approved remote-access methods and avoid personal devices unless the company has authorised and secured them.
Avoid sensitive tasks on public networks when the company's secure access is unavailable. Never connect an unknown USB drive. Report a lost or stolen device immediately: looking for it “a little longer” can delay access revocation.
How do you get incidents reported quickly?
Provide one visible, simple channel: an address, reporting button or internal number. Explain what to include — original message, time and action taken — and what not to do, such as forwarding a suspicious attachment to colleagues. Someone who clicked must be able to say so immediately rather than hide the mistake.
Explain what happens next: disconnect if instructed, change a secret from a clean device and let the responsible team preserve useful evidence. Awareness training connects employees to the incident-response plan; it does not replace that plan.
How should you build the training programme?
Start with the company's real tools and situations. A short baseline can cover phishing and BEC, MFA and passwords, updates, devices and remote work, then reporting. Add local procedures: whom to call, which password manager to use and which requests need two-person approval.
A quiz can reveal misunderstanding and offer another attempt. It cannot predict future behaviour. Refresh the material when tools, procedures or threats change, after an instructive incident and for new starters.
What evidence should you retain?
Keep the invited audience, participation, course version and topics, date and, where a quiz is used, the result. A dated attestation records that a named person completed a particular version; the training register keeps the campaign alongside other awareness measures.
Limit retained data to what is useful, control access and set a retention period consistent with internal policy. Evidence should improve prevention, not create permanent employee surveillance.