Back to blog
Guides

Cybersecurity Training for Employees: A Complete SME Guide

NAIT-YOUCEF KaciNAIT-YOUCEF Kaci
July 21, 202614 min read
Cybersecurity Training for Employees: A Complete SME Guide

43% of corporate cybersecurity incidents are caused by human error (IBM Cost of a Data Breach 2025). Training employees in cybersecurity rests on 5 complementary pillars: initial assessment, theoretical training, regular simulation, targeted remediation, and results measurement. This guide provides a month-by-month schedule over 12 months, 7 precise KPIs to track, and an ROI calculation to convince your management team.

Most French SMEs face the same dilemma: they know they need to train their teams but don't know how to structure a program that actually works. Annual training is forgotten within two weeks. E-learning modules get skimmed. One-off simulations aren't enough without follow-through.

Whether you're starting from scratch or want to structure an existing program, this guide covers everything an SME with 50 to 500 employees needs to significantly reduce the risk of staff clicking on phishing emails.

Why Has Cybersecurity Training Become Mandatory?

The Regulatory Context Leaves No Choice

The European NIS2 directive, which came into force in October 2024, requires companies in essential and important sectors to implement cybersecurity awareness measures. Article 21 explicitly requires employee training and regular security testing. Fines can reach €10 million or 2% of global turnover.

But NIS2 isn't the only framework mandating training. The GDPR requires appropriate technical and organizational measures, and data protection authorities consider employee awareness a fundamental organizational measure. SOC 2 audits systematically verify the existence of a security training program. The DORA directive, applying to the financial sector, mandates operational resilience testing including staff training.

82% of data breaches involve the human element (Verizon DBIR 2025): whether phishing, compromised credentials, configuration errors, or social engineering. Phishing alone accounts for 36% of all breaches, making it the number one attack vector. SMEs are prime targets: they often hold sensitive data but have limited protective resources.

The conclusion is clear: firewalls and antivirus software aren't enough. Without employee training, your security infrastructure has a gaping hole, and attackers know it.

Cyber Insurers Demand Proof

A more recent phenomenon is accelerating awareness: cyber insurance companies now condition their policies on the existence of an awareness program. According to a Deloitte study, 73% of cyber insurers require proof of regular employee training before granting coverage or maintaining acceptable rates.

If your SME has or wants cyber insurance, the question is no longer "should we train?" but "how do we prove we're training?" That means activity reports, documented completion rates, and a history of simulations.

The 5 Pillars of an Effective Training Program

A cybersecurity training program that produces measurable results rests on five complementary pillars. Omitting any one of them creates a blind spot that attackers will exploit.

Pillar 1: Initial Assessment — Measuring Your Starting Point

What: before any training, launch a "baseline" phishing simulation campaign to measure your teams' initial click rate. Complement it with a short questionnaire (10 to 15 questions) assessing basic cybersecurity knowledge.

Why: without a baseline, you'll never be able to demonstrate the program's effectiveness. "We trained our teams" convinces no one. "We reduced the click rate from 16% to 2% in 3 months" speaks to a board of directors.

How: send a realistic phishing simulation (email imitating a common service: Microsoft 365, parcel delivery, expense report) to all employees, without warning anyone. Measure the click rate, reporting rate, and response time.

Success metric: baseline is established, with initial click rate documented by department. According to Proofpoint, the average click rate without prior training is 27% to 35% depending on industry.

Pillar 2: Theoretical Training — Cybersecurity Fundamentals

What: e-learning modules covering the main threats: email phishing, business email compromise (BEC), social engineering, smishing, vishing, passwords, and multi-factor authentication.

Why: employees must understand attack mechanisms to detect them. Training can't be limited to "don't click suspicious links" — you need to explain how to recognize a malicious email, what the warning signals are, and what to do when in doubt.

How: favor short modules of 5 to 10 minutes maximum. Cognitive science research shows retention drops dramatically beyond 15 minutes. Spread initial training over 3 to 4 weeks rather than a single session.

Success metric: completion rate above 90%, average final quiz score above 80%. If your modules achieve less than 60% completion, they're probably too long or poorly designed.

Pillar 3: Regular Simulation — Testing Reflexes Under Real Conditions

What: simulated phishing campaigns sent at regular intervals, ideally monthly, with scenarios of increasing difficulty.

Why: theory alone doesn't change behavior. It's repeated exposure to realistic situations that anchors reflexes. According to SANS Institute data, a monthly simulation program reduces the click rate by 70% in 6 months.

How: vary scenarios (generic phishing, targeted spear phishing, BEC, fake QR codes, urgent notifications) and use your own sending domains for maximum realism. Simulations sent from generic domains are spotted immediately and have no educational value. Explore our phishing simulation.

Success metric: click rate consistently declining month after month, reporting rate increasing. Target: click rate below 5% after 12 months.

Pillar 4: Targeted Remediation — Train Those Who Need It

What: automatic, targeted training triggered immediately after a simulation failure. An employee who clicks a phishing link receives a 3 to 5 minute micro-course adapted to the type of attack they failed to detect.

Why: bombarding all employees with the same training is inefficient and frustrating for those who perform well. Targeted remediation concentrates resources where they're needed, at the precise moment the employee is most receptive.

How: configure automatic remediation paths. An employee who clicks on a BEC simulation receives a CEO fraud module; an employee who enters their credentials on a fake page receives a module on malicious login pages. Increase simulation frequency for repeat offenders.

Success metric: recidivism rate below 15%. An employee who fails the same type of simulation twice in a row requires human intervention (meeting with their manager or CISO).

Pillar 5: Measurement and Reporting — Proving Effectiveness

What: consolidated dashboard tracking program KPIs and periodic reports for management, auditors, and insurers.

Why: an unmeasured program is an unmanaged program. Reports serve three purposes: piloting the program, proving compliance, and justifying budget.

How: generate automated monthly reports with click rates, reporting rates, progress by department, overall risk score, and training completion rates. Present a quarterly report to management.

Success metric: compliance report generatable in one click, complete history of simulations and training accessible for audit.

How to Structure Your Program Month by Month

Here's an actionable 12-month calendar for an SME starting from scratch. Adapt the timing to your context, but respect the sequence.

Month 1: Initial Assessment

  1. Weeks 1–2: launch a baseline phishing simulation (medium difficulty scenario, e.g., "Microsoft 365 password update"), without any prior communication.
  2. Week 3: analyze results. Document click rate by department, identify the most vulnerable groups.
  3. Week 4: send a cybersecurity knowledge questionnaire (10 to 15 questions) and communicate the program launch to the whole company.

Deliverable: baseline report with initial click rate by department. This will be your reference for measuring all future progress.

Months 2–3: Foundational Training

Deploy core e-learning modules to all employees:

  1. Recognizing a phishing email (5 min)
  2. Password best practices and MFA (5 min)
  3. Social engineering and CEO fraud (5 min)
  4. What to do when you receive a suspicious email (3 min)

Schedule one module per week with automatic reminders, and set a 90% completion target within 3 weeks per module.

Deliverable: documented completion rate, average quiz scores, identification of employees who haven't completed modules.

Months 4–6: Regular Simulations and Remediation

Launch one phishing simulation per month, progressively increasing difficulty:

  1. Month 4: generic phishing (parcel notification, invoice)
  2. Month 5: targeted phishing (executive's name, reference to an internal project)
  3. Month 6: multi-vector (email and QR code)

Activate automatic remediation and send a monthly report to management.

Deliverable: click rate progression curve over 3 months, first consolidated quarterly report.

Months 7–9: Increasing Difficulty

  1. Introduce personalized spear phishing scenarios (employee name, their department, real internal references).
  2. Launch a BEC-type simulation targeting finance and HR functions.
  3. Organize a 30-minute "phishing workshop" for the highest-risk teams.
  4. Start measuring the reporting rate in addition to the click rate.

Deliverable: six-month progress report, comparison with the month 1 baseline.

Months 10–12: Consolidation and Benchmarking

  1. Maintain the monthly simulation cadence.
  2. Conduct a sector benchmark: compare your KPIs against your industry averages.
  3. Generate the annual compliance report (NIS2, SOC 2, cyber insurance).
  4. Set objectives for next year and plan the renewal of e-learning modules.

Deliverable: complete annual report with 12-month progression, calculated ROI, and action plan for the following year.

7 KPIs to Track for Measuring Effectiveness

Without measurable indicators, it's impossible to know if your program is working. Here are the 7 essential metrics to track.

  1. Click rate. The percentage of employees who click a link in a phishing simulation. Typical baseline without training: 27–35%. Target at 6 months: below 5%. Target at 12 months: below 2%.
  2. Reporting rate. The percentage of employees who report a suspicious email. This is the most important KPI: an employee who reports a threat protects the whole company. Typical baseline: 5–10%. Target at 6 months: above 40%. Target at 12 months: above 60%.
  3. Reporting time. The average delay between receiving a simulated phishing email and reporting it. Target: under 5 minutes for first reports.
  4. Training completion rate. The percentage of employees who completed assigned modules. A rate below 80% signals an engagement or internal communication problem. Target: above 90%.
  5. Risk score by department. Identify the most vulnerable departments to focus efforts. Finance, HR, and management are typically the most targeted — and often the most vulnerable.
  6. Recidivism rate. The percentage of employees who fail multiple consecutive simulations. These repeat offenders need particular attention: reinforced training, individual meetings, or in extreme cases, access restrictions. Target: less than 5% recidivists after 6 months.
  7. Monthly trend. The progression or regression of each KPI month after month. It's the trend that matters, not the absolute value. A click rate of 8% in steady decline is better than a 4% rate that's rising.

What Budget and ROI for Cybersecurity Training?

How Much to Invest?

The cost of a cybersecurity training program varies by company size and desired sophistication level. Here are realistic ranges for French SMEs:

Size Estimated annual budget Cost per employee/month
50 employees €6,000–€12,000 €10–€20
100 employees €10,000–€20,000 €8–€17
200 employees €15,000–€30,000 €6–€13
500 employees €25,000–€50,000 €4–€8

These budgets include the simulation platform, training modules, program management time, and compliance reporting. The larger the company, the lower the cost per employee thanks to economies of scale.

How to Calculate ROI?

The ROI of cybersecurity training is calculated by comparing the program cost to the cost of an avoided incident.

Simplified formula: ROI = (risk reduction × average incident cost) / program cost.

According to IBM, the average cost of a data breach for a French SME is €120,000. According to industry estimates, the annual probability of a successful phishing incident for an untrained SME is around 25%.

Example for a 200-employee SME:

  1. Program cost: €20,000/year
  2. Risk reduction (from 25% to 5%): 80% reduction
  3. Avoided cost: 25% × €120,000 × 80% = €24,000
  4. ROI = 24,000 / 20,000 = 1.2x, or 120% return

This calculation is conservative: it doesn't account for indirect costs (loss of customer trust, reputational damage, GDPR fines, cyber insurance impact). For a detailed calculation tailored to your company size, see our cybersecurity awareness ROI guide.

The return is positive from the first year. Start your free 14-day trial.

The Most Common Mistakes (and How to Avoid Them)

Mistake 1: The single annual training. The classic approach — one 2-hour session per year — is the least effective. According to cognitive psychology research, knowledge gained in a one-off training session is forgotten by 60% after 6 months. Solution: replace annual training with a continuous program — monthly micro-modules, regular simulations, and ongoing remediation.

Mistake 2: Simulations that are too easy. Basic simulations (obvious spelling mistakes, absurd domains, amateur design) don't prepare your teams for real attacks. Cybercriminals use increasingly sophisticated techniques: lookalike domains, perfectly formatted emails, credible contexts. Solution: progressively increase difficulty, use your own sending domains, personalize scenarios with internal elements. The goal is to test reflexes, not to trap people.

Mistake 3: Name and shame. Publishing the list of employees who clicked a simulation, ridiculing them in front of colleagues, or sanctioning them destroys the reporting culture. A humiliated employee will never report another suspicious email — even a real phishing attempt. Solution: adopt a supportive approach. Communicate results in aggregate (by department), never individually. Employees who click receive training, not punishment.

Mistake 4: Ignoring executives. Senior executives are prime targets for whaling and BEC attacks, but they're often the last to complete training. Solution: executives must be included in the program just like other employees — and ideally lead by example. A message from the CEO announcing they've completed the training themselves has a considerable impact on company-wide engagement.

Mistake 5: No baseline. Launching a program without measuring the starting point makes it impossible to demonstrate progress. Solution: always start with a baseline simulation before the first training session. That initial figure is your most valuable asset for justifying and piloting the program.

Mistake 6: Generic content. Modules that talk about "general cyber threats" with American examples in English don't engage French employees. Content must be contextualized: local examples, relevant regulatory references (NIS2, GDPR, ANSSI), the appropriate language, and scenarios adapted to the industry. Solution: prioritize platforms offering localized content, adaptable to your business context. Test our phishing simulation.

Recognize yourself in these mistakes? Launch a free diagnostic — first campaign in 15 minutes.

Frequently Asked Questions

How often should phishing simulations be run?

The optimal frequency is one simulation per month. This is the cadence recommended by ANSSI and validated by academic research. Less than once per quarter is insufficient to anchor reflexes. More than once per week creates fatigue and suspicion toward all emails.

Is cybersecurity training legally required?

In France, the answer is yes for many companies. The NIS2 directive explicitly mandates it for essential and important entities, which includes many SMEs in sectors like healthcare, energy, transport, finance, digital services, and public administration. The GDPR implicitly requires it as an organizational measure. And regardless of the law, most cyber insurers make it a condition of coverage.

How do you engage employees who don't take this seriously?

The most effective methods: gamification (team leaderboards, badges, challenges), management involvement (the CEO communicates the program's importance), and relevance (realistic, contextualized scenarios that show the threat is real). Avoid punishments: they create rejection, not engagement.

How long should a training session last?

3 to 5 minutes for remediation micro-modules, 5 to 10 minutes for standard e-learning modules. Completion rates drop sharply beyond 10 minutes. A short, repeated module anchors knowledge better than a long session.

How do you choose between in-house training and a SaaS platform?

For an SME with 50 to 500 employees, a SaaS platform is almost always the better choice. Building an in-house program requires a dedicated cybersecurity expert, content creation skills, a simulation sending infrastructure, a reporting tool, and ongoing scenario maintenance. The total cost far exceeds that of a specialized platform, typically with worse results. A SaaS platform like NovaShield aims to provide these elements ready to use, with scenarios updated monthly against new threats.

Five Pillars, One Goal

Training your employees in cybersecurity is a continuous process built on five complementary axes: assess your starting point with a baseline simulation, train with short and engaging modules, simulate monthly with progressively challenging scenarios, remediate automatically and in a targeted way, and measure every KPI to report to your management.

The most important thing is to start — even imperfectly. Every simulation launched, every module completed, every report filed strengthens your company's security posture. Launch your first simulation today.

About the Author

Kaci is the founder of NovaShield, holding a Master's in Cybersecurity & Cloud from IPSSI. NovaShield is a listed provider on the Cybermalveillance.gouv.fr platform.

Find Kaci on LinkedIn

Available inFRENESDEITAR

La plateforme est gratuite.

Recevez votre invitation dès l'ouverture.

Soyez notifié dès l'ouverture. En attendant, chaque semaine dans votre boîte : des guides pratiques pour sensibiliser vos équipes sans budget ni équipe IT, une veille sur les nouvelles menaces qui ciblent les PME en ce moment, et l'actu réglementaire concrète (NIS2, ANSSI) qui vous concerne.

Gratuit. Zéro spam. Désabonnement en un clic.

Découvrir la plateformeSans créer de compte