Knowledge base › Phishing training

Phishing training for employees: how it works

Last updated

Phishing training for employees is the most direct way to reduce the chance of a successful cyber attack. This article explains how it works, what it costs and what results you can expect.

Why are employees the primary target?

Phishing is the most common initial attack vector in data breaches (IBM 2026). Technical defences catch most automated attacks, but targeted phishing - spear phishing, CEO fraud, clone phishing - regularly slips through. At that point, the employee is the only filter remaining.

Without training, a share of employees clicks a phishing message in a first simulation. After targeted training that number drops noticeably. That is the difference phishing training for employees makes.

How does phishing training for employees work?

  1. Baseline measurement (phishing simulation): Before training begins, CoBoo runs a phishing simulation. This establishes what percentage of employees would currently click, which departments are most vulnerable and which scenarios work best.
  2. Training (Lumyo e-learning): Based on the simulation results, relevant e-learning modules are offered. Employees complete these at their own pace, on any device, without downloads. Modules take 10 to 15 minutes.
  3. Repeat measurement: After three to six months, a new simulation follows. The difference in click rate demonstrates concrete improvement - for employees, management, auditors and insurers alike.

What do employees learn in the training?

Recognition

How a phishing email looks: deceptive senders, suspicious links, urgency language and unexpected attachments.

Assessment

A step-by-step process to quickly assess whether a message is trustworthy - even if it appears to come from a known name.

Response

What to do with a suspicious message: don't click, don't forward, do report. Practised through real scenarios.

Types of phishing

Mass phishing, spear phishing, CEO fraud, smishing and vishing - each with its own characteristics to recognise.

What does phishing training cost?

Costs vary considerably by provider and approach. Lumyo works on a project basis for organisations of 20 to 250 employees. The price depends on the number of employees, the number of modules and the reporting required.

Perspective: The human factor plays a role in 62% of data breaches (Verizon DBIR 2026) and phishing is the most common initial access route at 17% (IBM, Cost of a Data Breach 2026). A training programme addresses precisely that.

Results: what does phishing training deliver?

  • Lower click rates after the first training round
  • Significantly more reports of suspicious emails by employees
  • Faster incident response by IT teams
  • Demonstrable compliance for NIS2, ISO 27001 and GDPR audits
  • A stronger sense of shared responsibility for cybersecurity

How often should phishing training be repeated?

One-off training is better than no training, but not enough for lasting effect. Phishing attacks evolve constantly: AI-generated emails, deepfake voice calls and personalised spear phishing attacks are becoming ever more convincing. What employees learn today may be outdated a year from now.

What someone learns in a single training session then has to compete with the hundreds of emails that keep arriving. Without new training moments, attention fades. That is not a weakness in employees, it is simply how attention works: what is not repeated slips into the background.

Recommended repeat frequency:

  • At least annually: For organisations that want to demonstrate compliance without an intensive programme.
  • Every six months: The recommended standard. Measure in January, train in February and March, re-test in June, adjust in the autumn.
  • Quarterly: For organisations with NIS2 obligations, ISO 27001 certification or a high risk profile (financial sector, healthcare, accountancy).

Lumyo modules are short enough (10 to 15 minutes each) to keep repetition realistic for busy employees. New scenarios and updates keep the training relevant, so it does not feel like a repeat of the same material.

Phishing training by sector

Phishing affects every sector, but the most commonly used attack scenarios differ by industry. Good phishing training matches the specific threats employees encounter in their daily work.

Healthcare and social care

Fake messages from health insurers, medical equipment suppliers and care portals. Employees handle confidential patient data under time pressure every day, which is ideal ground for phishing.

Financial services

CEO fraud and fake payment requests are particularly relevant. Employees who process payments or have access to bank accounts are a priority target.

Construction and manufacturing

Fake invoices from subcontractors and suppliers, false order status notifications and bogus quotation requests are common attack forms in these sectors.

Professional services

Accountancy firms, law firms and consultancies handle confidential client information. A data breach through phishing can have existential consequences for their reputation.

At Lumyo we adapt the training content to your sector and organisation profile. Read more about what phishing awareness involves and how a programme fits your organisation.

Frequently asked questions about phishing training for employees

Why do employees need phishing training?

Phishing is the most common initial attack vector in data breaches (IBM 2026). Technical security measures stop most automated attacks, but targeted phishing slips through regularly. Phishing training gives employees the instinctive behaviour to recognise attacks before damage is done.

How long is a phishing training module?

Lumyo modules take 10 to 15 minutes each. Employees work through them at their own pace, on any device, without installations. A full training programme consists of several modules spread over weeks or months.

Is phishing training also suitable for non-technical employees?

Yes, especially so. Phishing affects all employees, regardless of their technical background. Lumyo modules are deliberately written without jargon and focus on recognisable, practical behaviour. The most vulnerable employees are often those with the least technical background but the most access to sensitive information.

Schedule a free introduction

Whether you have 5 or 500 employees - there is a solution for every business size.

This opens your email client. You send the email yourself.

Read our privacy policy