Security awareness training: turning click risk into reporting behaviour
Security awareness training is a measurable behavioural process, beyond a mandatory e-learning module. The target is not a zero click rate but a reporting rate for suspicious mail in the 40 to 50 percent target band before the SOC escalates. ANOMAL combines short role-specific modules, realistic phishing simulations and a reporting interface in Microsoft 365 so awareness becomes a detection source. The 'Regular security awareness training with phishing simulations' requirement of most Swiss cyber insurers is documented in the process.
Why awareness is the cheapest control layer
Most successful attacks on Swiss SMEs still start with email: phishing, business email compromise, MFA fatigue. Technical filters catch the majority but never everything. Whoever clicks is a stepping stone; whoever reports is a detection source. A good awareness programme moves exactly that ratio.
Regular security awareness training with phishing simulations is a common cyber-insurance requirement in the Swiss market. Without evidence, insurers apply surcharges or sub-limits, see [Cyber insurance](/en/soc/soc-and-cyber-insurance-switzerland).
Programme structure
- Annual baseline training for all employees: mandatory module with a knowledge test, completion documented per person.
- Department modules supplement the baseline training. Finance and HR cover BEC and invoice fraud; IT covers MFA fatigue and console access; executives cover whaling and deepfake voice. We provide custom content to meet customer requirements.
- Knowledge test per module: results support assessment of each employee and guide follow-up training.
- Onboarding gate: completing the initial training is a prerequisite for system access. We reconcile status against the customer's HR onboarding process.
- Quarterly phishing campaigns over the contract term, with gradually rising difficulty and DE plus EN variants for Swiss mixed-language workforces.
- Report button in Outlook and Teams: one click sends the message to the SOC, the user gets immediate feedback (real / simulated / suspicious).
- Quarterly report to the CISO: training status, test results, phishing results (click rate, data entry, report rate) and risk-score trend; evidence for insurer and regulator.
- Operations: ANOMAL plans, coordinates, delivers and manages the programme on an ongoing basis.
The programme runs on an awareness platform, and the choice of platform is not part of the positioning. Examples are KnowBe4, Proofpoint Security Awareness, SoSafe, Hoxhunt or Microsoft Attack Simulation Training. We take over an existing platform; if none exists, we recommend one based on languages, seat count and Microsoft 365 integration.
The managed service covers programme design, modules, campaigns, reporting and steering. The per-seat platform licence is not part of the managed fee; it is listed separately and transparently. Because seat count, languages, module scope and term differ per environment, there is no list price: every customer receives a dedicated quote.
Phishing simulation as part of the programme
The simulations in this programme send controlled but realistic mails and measure two values: who clicks, and who reports. Both are evaluated by role and business unit. Only the reporting rate via the report button turns the simulation into a detection exercise.
- Baseline: one unannounced wave at medium difficulty, click and report rate per business unit as the starting point.
- Role segments: finance and HR receive BEC and invoice lures, IT gets MFA fatigue and console access, executives get whaling and deepfake-voice pre-warnings.
- Cadence: a wave every four to six weeks, difficulty rising in steps, DE and EN variants.
- Immediate feedback: whoever clicks sees a short explainer with the concrete signals in the lure.
Generic EN templates lose value fast. Effective campaigns use QR-invoice, eBill, SwissID prompts, ISO-20022 phrasing, cantonal and health-insurer context, plus DE and EN variants for mixed workforces.
Metrics that matter
| Metric | Why it matters | Realistic target band |
|---|---|---|
| Simulation click rate | Coarse indicator, drops fast and then plateaus; not meaningful in isolation. | Under 5 percent after twelve months of programme. |
| Report-button reporting rate | The actual detection value for the SOC. | 40 to 50 percent for well-crafted simulations. |
| Time to first report | Determines how fast the SOC stops a real wave. | Under 15 minutes after send-out. |
| Repeat-clicker share | Shows whether the programme reaches risk groups. | Under 2 percent of the workforce. |
The under-5-percent click rate matches the published 12-month industry benchmark (KnowBe4 Phishing by Industry Benchmarking Report 2025: 4.1 percent global, 5.0 percent Europe). Report rate, time to first report and repeat-clicker share are ANOMAL target bands from live programmes, not published market data.
The report button connects awareness and SOC operations. The SOC treats reported emails as detection signals and incorporates them into the MTTD chain. See MTTD and MTTR in a SOC.
How this compares to plain e-learning or phishing-simulation only
| Approach | What it delivers | Where it falls short |
|---|---|---|
| Mandatory once-a-year e-learning | Compliance tick for audits. | Behaviour does not measurably change. |
| Phishing simulation without training | Click rate becomes visible. | Without feedback and reporting interface no detection uplift. |
| Awareness programme with report button | Behaviour measurable and steerable, SOC gains a detection source. | Does not replace technical filters (email sandboxing remains mandatory). |
Awareness contributes to the detection stack and cannot replace it. See SOC as a Service Switzerland for the framework and its interaction with SOC operations.
Frequently asked questions
Do we announce campaigns?
The baseline is not announced, otherwise it is not a baseline. Afterwards management communicates transparently that there is an ongoing programme, without leaking dates or lures.
What happens to those who click?
A short explainer page with the concrete signals in the lure, no sanctions. Repeat clickers get an additional short module, no naming and shaming in open reports.
How often do phishing campaigns run?
A wave every four to six weeks across the entire contract term, with varying difficulty and themes. We can agree additional ad-hoc campaigns in the scope, for example after a real incident.
Is the platform licence included in the price?
The managed fee excludes the platform licence and covers programme design, modules, campaigns, reporting and steering. We list the per-seat licence separately so you can see the service and licence costs. Both appear in the same quote.
Which languages are standard?
Training content is available in every language our training platform offers.
Who owns the onboarding gate?
The customer's HR onboarding process requires employees to complete the initial training before gaining system access. We provide assignment, reminders and completion status; you enforce the rule in your access process.
Does this programme satisfy the insurance requirement?
Yes, provided you document frequency, role coverage and reporting. The quarterly report supports this documentation. On request, we share it directly with the broker or insurer.
What happens to simulation results and personal data?
Management receives analytics aggregated by business unit, with no individual-level results. We store personal data about who clicked or reported in accordance with revFADP (revised Federal Act on Data Protection). We use it only for follow-up training and delete it after a defined retention period.
Related terms
- Phishing Phishing is an attack that uses fake emails and messages to trick people into taking an action.
- BEC Business Email Compromise is a type of corporate fraud where attackers trick staff into making payments to accounts controlled by the attackers.
- MFA Multi-Factor Authentication requires a second form of verification in addition to a password during login.
- Credential Stuffing Credential stuffing automatically tests stolen username and password combinations across many online services.