Human error is the entry point for the large majority of data breaches — commonly cited figures put some form of employee action, a click, a reply, an approved payment, behind more than 80-90% of successful attacks. Firewalls, antivirus, and email filters block plenty, but none of them can stop an employee from wiring money to a convincing fake vendor or typing a password into a well-made fake login page. Closing that gap requires training people, not just hardening systems, and it requires doing it in a way that actually changes behaviour rather than checking a compliance box once a year.
That's the point of this guide. We're not going to hand you a generic "train your employees" recommendation and move on — we're going to walk through five concrete steps that, taken together, form a program: assessing your real risk, building content that fits different roles, running realistic phishing simulations on a recurring basis, coaching people in the moment rather than punishing them after the fact, and measuring whether any of it is working. Each step builds on the last, and skipping one tends to undercut the others.
Who wrote this guide
This guide was written and reviewed by IT Cares certified technicians who design and run phishing simulation and awareness programs for Canadian small and mid-sized businesses. What follows is based on patterns we see repeatedly: programs that stall out after one annual session, and programs that produce a real, measurable drop in risk over a few months. The difference almost always comes down to structure, not effort.
Why Security Training Matters More Than the Technology Alone
It's tempting to think of security spending as a technology problem: buy better antivirus, add a firewall, turn on multi-factor authentication, and call it done. Those steps matter — genuinely, they do — but they all share a blind spot. None of them can evaluate whether an email asking someone to do something is legitimate. A phishing email that asks an employee to click a link isn't malware until the click happens, and a business email compromise message asking accounts payable to update a vendor's banking details isn't a virus at all — it's a request, written to sound completely normal, sent to a person who has no technical reason to distrust it.
That's why social engineering — manipulating a person rather than exploiting a piece of software — remains the dominant way attackers get in. It's cheaper than developing malware that evades modern endpoint protection, it works against businesses of every size and budget, and it exploits something no patch can fix: a normal, busy employee trying to do their job quickly, who receives dozens of legitimate emails a day and has to make an instant judgment call on each one.
📊 IT Cares field note: We've seen small businesses spend thousands on a next-generation firewall and endpoint detection platform, then lose $30,000+ to a business email compromise scam that never touched a single piece of malware — just a convincing email and an employee acting on it in good faith. Technology and training aren't competing budget lines; they're solving two different halves of the same problem.
None of this means technology doesn't matter — email filtering, endpoint protection, and multi-factor authentication all reduce how often a malicious message reaches an inbox or how much damage a compromised password can do. But they reduce the odds; they don't eliminate the need for the person reading the email to recognize when something is off. A security training program is what builds that recognition deliberately, instead of hoping employees pick it up by accident.
Not sure where your team's biggest risk is?
IT Cares can run a baseline phishing simulation and show you exactly which roles and departments need attention first — no judgment, just data.
The 5-Step Framework
Every effective program we've built or reviewed follows some version of this sequence. You can compress the timeline for a small team or spread it out for a larger one, but skipping a step tends to weaken the whole thing — role-based content without a baseline is guesswork, and simulations without coaching just measures failure without fixing it.
Assess your current risk and baseline
Run an initial phishing simulation before any training to get an honest baseline click rate, survey what employees actually know versus what you assume they know, and identify the highest-risk roles — typically finance, HR, and anyone with wire transfer or sensitive-data access.
Build role-based training content
Replace a single one-size-fits-all annual session with short, frequent modules tailored by role: wire-fraud and BEC training for finance, data-handling training for HR, phishing fundamentals for everyone. Microlearning beats a long annual video for retention.
Run realistic phishing simulations
Send fake-but-safe phishing emails using realistic pretexts — a fake invoice, a fake IT password reset — track who clicks and who reports, and repeat this monthly or quarterly, not once a year.
Reinforce with real-time coaching
Give immediate, non-punitive feedback the moment someone clicks a simulated phishing link through a private teachable-moment landing page, and recognize employees who report real phishing attempts.
Measure effectiveness and iterate
Track click rate, report rate, time-to-report, and repeat-clicker rate over time, present the trend to leadership in plain terms, and adjust content based on what's actually failing rather than what you assumed would be the problem.
Step 1: Assess Your Current Risk and Baseline
Skipping the baseline is the single most common mistake we see. Businesses that go straight to training — even good training — have no way of knowing afterward whether anything actually changed, because they never measured where they started. A baseline turns "we did some training" into "we went from a 27% click rate to 9% in four months," which is a completely different conversation with leadership, insurers, and clients.
Run an initial phishing simulation before any training
Send a realistic, safe simulated phishing email to the whole company before announcing that any training program is starting. The point isn't to catch people out — it's to get an honest number that reflects normal behaviour, not behaviour primed by the knowledge that a test is coming. Track who clicked, who entered any information on a fake landing page, and who reported the email to IT without being told to look for anything.
Survey what employees actually know
A short, anonymous survey — five to ten questions on phishing recognition, password habits, and what to do with a suspicious email — surfaces gaps that a click-rate test alone won't show. It's common to find employees who didn't click the test phishing email simply because they happened to be busy that day, not because they'd have recognized it under normal circumstances. The survey catches that nuance.
Identify your highest-risk roles
Not every employee carries equal risk. Map out who has the ability to approve wire transfers or change vendor banking details (usually finance and accounts payable), who handles personal or health information (HR, and depending on your industry, client-facing staff), who has admin access to core systems (IT and management), and who is most publicly listed online with a title an attacker could impersonate (executives and their assistants). These roles need training that goes beyond the basics covered in Step 2.
A low baseline click rate isn't a reason to skip the rest
We occasionally see a business run a baseline, get a surprisingly low click rate, and conclude their team is already well-trained enough to skip formal training. Be cautious here — a single test with one pretext catches employees who happen to recognize that specific approach. A more sophisticated or well-timed pretext later, especially one tied to a real, current event at the company, often performs very differently. One good result is a data point, not proof the risk is gone.
Step 2: Build Role-Based Training Content
A single annual training video shown to everyone from the receptionist to the CFO treats a low-risk role and a high-risk role identically, which wastes the CFO's time on generic content and leaves the receptionist under-prepared for anything targeted at reception-desk social engineering specifically. Role-based content fixes this by matching depth and topic to actual exposure.
What different roles actually need
- Everyone (company-wide baseline): How to recognize phishing red flags — mismatched sender addresses, urgency and pressure language, unexpected attachments or links, requests that bypass normal process — and exactly how to report a suspicious email in one click.
- Finance and accounts payable: Dedicated business email compromise (BEC) and wire-fraud training, including a hard rule that any change to vendor banking details or any urgent payment request gets verified by phone, using a known number, never a number or reply-to address supplied in the email itself.
- HR: Data-handling training tied to your actual obligations — safe handling of resumes, SIN numbers, health information, and how to spot fake "please update your direct deposit" requests, which frequently target HR and payroll specifically.
- Executives and executive assistants: Awareness that they are the most commonly impersonated identity in BEC attacks, plus practical steps like verifying unusual requests through a second channel, even when the request appears to come from them, from a colleague, or from a real client.
- IT and anyone with admin access: Credential-phishing awareness specific to admin tools, plus the habit of never approving unexpected multi-factor authentication prompts (MFA fatigue attacks), which have become a common way attackers push past MFA.
Short and frequent beats long and annual
Retention research on adult learning consistently favours short, spaced-out sessions over a single long one, and security training is no exception. A 45-minute annual compliance video is easy to schedule and easy to forget within weeks. Five- to ten-minute microlearning modules delivered monthly, each covering one specific concept — this month's topic might be invoice fraud, next month's might be fake shared-document links — build recognition gradually and keep the topic fresh without demanding a large block of anyone's calendar.
This is also where the pairing with Step 3 matters: content taught in isolation fades quickly, but content immediately followed by a related phishing simulation reinforces it through practice, not just exposure. Teaching "watch for lookalike domains" this month and then testing with a lookalike-domain pretext next month closes the loop between knowing and doing.
Step 3: Run Realistic Phishing Simulations
This is the step most businesses either skip entirely or run once and abandon, which is unfortunate, because it's arguably the most valuable one. A phishing simulation is a controlled, safe test: your business (or a platform you use) sends a fake phishing email to employees, tracks who interacts with it, and uses the results to target further training — all without any real risk, since the "malicious" link or attachment is entirely harmless and simply logs the interaction.
How a simulated phishing campaign actually works, technically
A simulation platform sends an email crafted to look like a real phishing attempt, using a domain that resembles — but isn't — a legitimate one. The email contains a tracked link or attachment. If an employee clicks the link, they're redirected to a landing page (see Step 4) rather than anything harmful, and the platform logs the click. Some simulations go a step further and present a fake login form; if the employee types credentials into it, that's also logged (and never stored anywhere beyond the test result) as a "credential entry," a more serious outcome than a click alone since it mirrors what would happen in a real attack. Employees also have the option to report the email using a "report phishing" button, ideally the same one they'd use for a real suspicious message, and that action is tracked too as a positive result.
Realistic pretexts perform better than obvious ones
A test phishing email announcing "you've won a prize" teaches employees to recognize an obviously fake email, which isn't the actual threat they'll face. Pretexts that resemble real business communication train the skill that actually matters:
- Fake invoice from a plausible vendor — tests whether accounts payable verifies unfamiliar invoices before paying.
- Fake IT password-reset or account-verification request — tests whether employees check the sender domain before entering credentials.
- Fake shared-document notification (mimicking Microsoft 365, Google Drive, or a file-sharing tool) — one of the most commonly clicked pretexts in real attacks, since it looks routine.
- Fake urgent request from an executive — tests whether employees verify unusual, time-pressured requests through a second channel rather than complying immediately.
Recurring cadence, not a once-a-year event
A single annual simulation tells you where you stood on one day. A monthly or quarterly cadence tells you a trend, catches regression before it becomes a real incident, and — just as importantly — keeps the underlying skill from decaying. Skill built through repeated, spaced practice holds up under pressure far better than skill demonstrated once and never revisited. Rotate pretexts across each cycle so employees build genuine pattern recognition rather than memorizing one specific fake email.
A note on tone
Simulations work best when they're framed to employees, in advance and in general terms, as a normal part of how the company trains for a real threat — not as a trap designed to catch people making mistakes. Businesses that introduce simulations honestly ("we're going to periodically test ourselves with fake phishing emails, and the results are used to improve training, not to discipline anyone") see meaningfully better engagement and higher report rates than businesses that spring it on employees without context.
Step 4: Reinforce With Real-Time Coaching
What happens in the sixty seconds after someone clicks a simulated phishing link matters more than almost anything else in the program. Handled well, it's the single most effective teaching moment in the whole cycle. Handled poorly — public callouts, a scolding email to the whole team, disciplinary action for a first click — it teaches employees to hide mistakes rather than report them, which is precisely the opposite of what a security program needs.
The teachable-moment landing page
Instead of a generic "you failed" message, a good landing page appears the instant an employee clicks, explains specifically what red flags were present in that particular email (the sender domain, the urgency language, the mismatched link), and offers a short, optional follow-up module on that exact topic. This is private — only the employee sees it, not their manager or the whole team — and it happens while the mistake is still fresh in memory, which is when the lesson sticks best.
Non-punitive by design
Research on security awareness consistently shows that punitive responses to simulated phishing clicks backfire. Employees who fear punishment for clicking a test email become less likely to report a real suspicious email too, out of fear that reporting draws attention to a possible past mistake. The goal of the program is a high report rate on real threats, and a culture of blame directly undermines that goal. Repeated clicks over many cycles by the same person is a signal to offer additional one-on-one coaching, not a disciplinary trigger — treat it as a training gap, not a performance issue, unless someone is actively ignoring assigned training altogether.
Recognize and reward reporting
The flip side of non-punitive coaching is active recognition for the employees who get it right. A simple monthly shoutout for whoever reported the most suspicious emails (real or simulated), a small reward tied to a strong department-wide report rate, or even just a genuine "thank you, that's exactly the right call" reply when someone reports a real phishing attempt, reinforces that reporting is valued, not just tolerated. Businesses that build this recognition loop in tend to see report rates climb noticeably faster than businesses that only measure and coach on clicks.
Step 5: Measure Effectiveness and Iterate
A training program without measurement is an act of faith. With four concrete metrics tracked over time, you can show leadership — and yourself — whether the investment is working, and adjust content toward whatever's actually failing rather than what you assumed would be the weak point.
The four metrics that matter
- Click rate over time. The percentage of employees who click a simulated phishing link, tracked cycle over cycle. The trend matters more than any single number — a steady decline shows the program is working.
- Report rate. The percentage of employees who correctly report the simulated (or a real) phishing email instead of ignoring or clicking it. Arguably the more important long-term metric, since a high report rate means your employees function as an active detection layer, not just a passive risk.
- Time-to-report. How quickly, on average, a suspicious email gets reported after it lands. A short time-to-report matters enormously in a real incident, since it directly limits how long a genuine phishing campaign or compromised account can do damage before IT can respond.
- Repeat-clicker rate. The percentage of employees who click on more than one simulation in a row, which flags who needs extra one-on-one coaching rather than another round of the same general content that clearly isn't landing for them.
Presenting results to leadership
Leadership generally responds better to a simple trend chart and a cost-avoidance framing than to a wall of statistics. "We went from a 28% click rate to 6% over six months, and our report rate is now higher than our click rate" tells a clear story. Pairing that with an honest estimate of what a single successful incident would likely cost — factoring in downtime, recovery, and potential regulatory exposure under PIPEDA or provincial privacy law — makes the ongoing investment easy to justify in dollar terms, not just abstract risk-reduction terms.
Adjusting content based on what's actually failing
If a particular pretext (say, fake shared-document links) keeps producing a high click rate cycle after cycle while others improve, that's a specific, fixable content gap — not a sign the whole program is failing. If one department consistently lags the rest, targeted coaching for that department, rather than a company-wide response, is usually the more efficient fix. Treat every simulation cycle as new data to refine the next one, not as a final verdict on the program.
How Training Approaches Compare
Not every approach to security awareness delivers the same result, and cost alone doesn't predict effectiveness — an inexpensive but consistent program regularly outperforms an expensive but sporadic one.
| Approach | Frequency | Realism | Typical Cost (CAD/employee/year) | Effectiveness |
|---|---|---|---|---|
| Annual compliance video | Once a year | Low — generic scenarios | $5–$15 | Weak — knowledge fades within weeks |
| Quarterly live workshop | 4x per year | Medium — discussion-based, not tested | $20–$45 | Moderate — good for culture, weak on behaviour proof |
| Monthly phishing simulation platform | Monthly | High — realistic, tracked pretexts | $18–$40 | Strong — measurable click-rate decline |
| Gamified microlearning platform | Weekly/biweekly micro-modules | Medium-high — scenario-based quizzes | $15–$35 | Strong — good retention, best paired with simulations |
| Ad-hoc informal reminders | Irregular, no schedule | Low — inconsistent messaging | Near $0 in licensing, high in staff time | Weak — no measurement, easily ignored |
| Combined program (role-based content + monthly simulations + coaching) | Continuous, layered | High — realistic and reinforced | $30–$60 | Strongest — measurable, durable behaviour change |
Illustrative Scenarios: What This Looks Like in Practice
The following are composite, illustrative scenarios built from patterns we commonly see across Canadian SMBs — not real named clients, but realistic representations of how this framework plays out.
Scenario 1 — A 35-person Ontario tech company
An Ontario software company with 35 employees ran a baseline simulation and found a 28% click rate, higher than the founders expected given the technical background of much of the team. They rolled out role-based microlearning modules, added a monthly simulation cadence with rotating pretexts, and paired every click with a private teachable-moment landing page instead of any manager notification. After six months, their click rate had dropped to 4%, and their report rate — employees flagging the simulated email without clicking — had climbed from near zero to over 60%. The founders noted that the drop in click rate mattered less to them, in hindsight, than the jump in report rate, since it meant real suspicious emails were now getting flagged to IT within minutes instead of being silently ignored.
Scenario 2 — A 15-person Quebec law firm
A 15-person Quebec law firm had implemented basic phishing-awareness training a year earlier as part of a broader PIPEDA and Law 25 compliance push. An employee in accounts payable received an email that appeared to come from a long-standing vendor, requesting an update to banking details ahead of an upcoming invoice payment. Trained to verify any banking-detail change by phone using a number on file — not one supplied in the email — the employee called the vendor directly, discovered the request was fraudulent, and reported it to the firm's IT provider immediately. The firm estimated the averted loss, based on the invoice amount in question, at roughly $40,000. The firm's leadership pointed to this single incident as validating the entire training investment on its own.
Scenario 3 — A 60-person Alberta healthcare clinic
A 60-person multi-location healthcare clinic in Alberta had relied on a single annual compliance video for several years. A near-miss — a staff member almost entered credentials into a fake patient-portal login page before noticing the URL looked slightly wrong — prompted a review. The clinic built role-specific training: front-desk and clinical staff received data-handling and patient-privacy-focused modules given their PHIPA-equivalent obligations, while billing staff received dedicated BEC and wire-fraud training. They introduced quarterly simulations tailored to healthcare-specific pretexts (fake patient portal alerts, fake scheduling-system notifications) rather than generic templates. Over the following year, no further near-misses of that type were reported, and staff surveys showed meaningfully higher confidence in recognizing suspicious messages.
Want a program built around your team's actual risk, not a generic template?
IT Cares designs and runs role-based training and phishing simulation programs for Canadian small and mid-sized businesses, with plain-language reporting for leadership.
Is Your Security Training Program Actually Working? Quick Self-Check
Run through this checklist honestly. A handful of "no" answers points directly at where to focus next.
- ☐ We ran a baseline phishing simulation before starting any formal training
- ☐ We know our current click rate and report rate, not just a rough impression
- ☐ Finance/accounts payable staff have received dedicated wire-fraud and BEC-specific training
- ☐ Training content differs by role instead of being identical for every employee
- ☐ We run phishing simulations at least quarterly, ideally monthly
- ☐ Simulation pretexts are rotated and resemble real threats we actually receive
- ☐ Employees who click a simulated email get private, immediate, non-punitive coaching
- ☐ We track click rate, report rate, and time-to-report as a trend over months, not a single test
- ☐ Employees who report suspicious emails receive some form of positive recognition
- ☐ Leadership sees training metrics on a recurring basis, not just once a year
What Security Awareness Training Costs a Canadian SMB
Budget expectations vary widely depending on how far you take the program. Rough, realistic CAD per-employee-per-year ranges:
- DIY / free resources: $0–$10 per employee per year. Using free materials from the Canadian Centre for Cyber Security, manually sent test phishing emails, and internally run discussions. Workable for very small teams (under 10 employees) but time-intensive for whoever manages it, and lacks tracking and trend reporting.
- Paid platform (self-managed): $15–$40 per employee per year. A dedicated phishing simulation and microlearning platform that your IT staff or an internal champion configures and runs, with built-in tracking, landing pages, and reporting dashboards.
- Fully managed program: $30–$60+ per employee per year. A managed IT or security provider designs role-based content, schedules and runs simulations, handles coaching workflows, and delivers plain-language reporting to leadership — removing the internal time burden entirely.
For context, the average cost of a single successful business email compromise incident for a Canadian SMB commonly runs well into five figures once downtime, recovery, and reputational impact are factored in — meaning even the fully managed tier typically pays for itself many times over if it prevents even one serious incident over a few years.
Canadian Government Resources for Security Awareness Training
Several free, credible Canadian resources are worth building into any program, particularly for businesses on a tight budget:
- Canadian Centre for Cyber Security (cyber.gc.ca), part of ISED, publishes free "Get Cyber Safe" employee awareness materials specifically aimed at small businesses, including phishing-recognition guidance and posters that can be used directly in internal training without licensing costs.
- BDC (Business Development Bank of Canada) offers small business advisory resources, including guidance on cybersecurity risk management and budgeting, useful for framing the business case for a training investment to ownership or a board.
- Office of the Privacy Commissioner of Canada (priv.gc.ca) publishes guidance tied to PIPEDA obligations around safeguarding personal information, which is directly relevant to training content for any employee who handles client, patient, or employee personal data — tying awareness training explicitly to a legal obligation rather than treating it as optional best practice.
If you'd rather have a professional design and run this rather than building it from scratch, our security audit service can identify your specific risk areas first, and IT Cares can build and manage an ongoing training and simulation program around what that audit finds — removing the guesswork of where to start.
Frequently Asked Questions
Ready to Build a Training Program That Actually Works?
IT Cares can run your baseline simulation, build role-based content around your real risk areas, and manage the ongoing coaching and reporting — so your team gets measurably better at spotting real threats.
Comments (3)
We switched from an annual video to monthly simulations about five months ago. Our click rate dropped a lot faster than I expected, but the bigger surprise was how many more people started actually reporting suspicious emails instead of just deleting them.
The point about not punishing people for clicking really resonated. Our old approach basically taught people to keep quiet when they messed up, which is the opposite of what we needed.
Good breakdown of the role-based approach. We'd been giving our finance team the exact same training as everyone else, which in hindsight made no sense given how often they're the actual target.
Leave a Comment