Security awareness training a 20-person company will actually complete
The annual 45-minute security slideshow fails because it is designed for auditors, not employees. Short monthly training and blame-free phishing simulations work better and cost less than most owners expect.
· Jake Schaaf, Founder of Atticus Rowan
Every December, the same ritual: a 45-minute security training video assigned to all staff, due by year end. Half the company plays it muted in a background tab. 3 people finish it in the last hour of the last day. The completion report says 100%, the actual knowledge transfer is close to 0, and everyone repeats the exercise 12 months later.
If that describes your company’s security training, the problem is not your employees. The annual-slideshow format exists to produce a compliance artifact, a report that says training happened. It was never designed to change what someone does at 4:45 pm when an email that looks like it came from the owner asks them to buy gift cards.
For a 10 to 30 person company, where 1 wrong click can reach everything, training that actually works looks different. The good news is that it is also cheaper and less annoying than the ritual it replaces.
Why the human layer is worth training at all
Tools matter. We have written about what EDR does that antivirus does not and why properly configured email authentication shuts down domain spoofing. But nearly every incident we see at small businesses starts the same way: a person was convinced to do something, click a link, approve an MFA prompt, change a payment detail, share a code.
Verizon’s Data Breach Investigations Report has for years attributed a substantial majority of breaches to a human element, social engineering, error or misuse. At a 20-person company there is no security operations center standing between a convincing email and the person reading it. The person is the control. Training is how you maintain it.
What actually works: short and frequent
The format that produces behavior change is close to the opposite of the annual video:
- 3 to 5 minute modules, monthly. 1 topic at a time: invoice fraud this month, MFA prompt bombing next month. Short enough to complete on a phone between meetings, frequent enough that security stays visible
- Current material. The scam formats rotate constantly. Training from 2022 does not mention QR code phishing or AI-written pretexts. A live subscription service keeps content matched to what is actually arriving in inboxes
- Completion tracked, gently. Monthly modules make stragglers visible early. A manager nudge in week 2 beats an ultimatum in December
The time cost per employee is under 1 hour per year, less than the annual video, spread into doses small enough that nobody builds resentment toward it.
Phishing simulations without the gotcha culture
Simulated phishing emails are the other half, and they are widely misused. Run as a trap, “who clicked, name and shame,” simulations teach employees that IT is the adversary. People stop reporting real phishing because they fear looking foolish. That outcome is worse than running no simulations at all.
Run correctly, the rules are:
- Measure the report rate, not just the click rate. The goal is not 0 clicks, it is fast reporting. A company where someone clicks but 3 others report the same message within 10 minutes is in good shape, because real attacks get flagged while they are still in progress
- No public shaming, ever. A click triggers a private 2-minute refresher for that person and nothing else
- Make reporting effortless. A report button in the mail client, 1 click, with a thank-you response. If reporting a suspicious email takes more effort than deleting it, it will be deleted
- Vary difficulty honestly. Obvious fakes teach nothing. Simulations should look like the invoice fraud and delivery notices employees actually receive
Watch the trend over 2 to 3 quarters: click rates typically fall meaningfully from their starting point, but the report rate rising is the number that predicts how the company handles a real attack.
What it costs and where it shows up
Standalone security awareness platforms for a company under 50 seats typically run $2 to $5 per user per month, and the capability is often bundled into managed IT agreements at no separate line item. For a 20-person company that is roughly the cost of 1 lunch per month against the most common attack path there is.
The spend also shows up somewhere concrete: cyber insurance applications. Renewal questionnaires now routinely ask whether the organization runs security awareness training and phishing simulations, alongside the MFA, EDR and backup questions that have become standard. “Yes, monthly, with simulations” is an answer that supports both coverage and premium. A blank is a flag.
Be careful, though, not to buy training as a checkbox and stop there. As we argued in security marketing versus evidence, the value is in the practiced behavior, not the certificate. A completion report proves attendance. A rising report rate proves the training took.
Give the finance seat extra reps
General training covers everyone, but the person who pays invoices deserves a heavier dose, because that is where the money moves. Business email compromise does not target companies at random. It targets whoever can change a vendor’s banking details or release a wire.
For that seat, usually 1 or 2 people at a 10 to 30 person company, add:
- A standing callback rule. Any change to payment details gets verified by phone using a number already on file, never a number from the email requesting the change
- A shared understanding with leadership that urgency in email is a red flag, not a reason to skip the callback. Owners have to mean this, because the scam impersonates them
- A brief walkthrough of real invoice fraud examples once or twice a year, 15 minutes over coffee, not a formal course
The callback rule alone defeats the majority of payment fraud attempts, and it costs nothing. Training is what keeps it from eroding under deadline pressure.
Getting it running in 2 weeks
The rollout is genuinely simple:
- Pick a platform, or ask your IT provider what is already included in your agreement
- Announce it honestly: short monthly lessons, occasional test emails, no shaming, and a real request to report anything suspicious
- Enroll everyone, owners included. When leadership skips training, everyone notices, and executives are the most impersonated people in the company
- Fold the starter module into new hire onboarding so day-1 employees learn what normal looks like before fraudsters teach them otherwise
- Review the numbers quarterly, watching report rate first
Atticus Rowan runs security awareness programs, simulations included, as part of managed IT and security for small businesses. If your current training is an annual video nobody watches, contact us and we will help you replace it with something your team will actually complete.
Related insights
More on Security tools →July 20, 2026
Is Microsoft 365 Business Premium worth it for a 15-person office?
What the roughly $10 per user per month jump from Business Standard to Business Premium actually buys, and when Standard is genuinely enough.
July 8, 2026
DMARC, SPF and DKIM: the 3 DNS records protecting your company's name
Criminals can send email that looks exactly like it came from your domain unless 3 DNS records say otherwise. Here is what SPF, DKIM and DMARC do and how to roll them out without breaking your own mail.
July 1, 2026
Shadow IT discovery and the SaaS inventory conversation nobody wants to start
A practical guide to shadow IT discovery for small businesses, covering how to find ungoverned SaaS apps and unreviewed OAuth grants, triage them by data sensitivity and build a request path so it does not just recur.