Staff Cyber Security Awareness Training

Build a Cyber-Secure Workforce

Technology plays an important role in cyber security, but most cyber incidents still involve a human decision somewhere along the way.

Whether it’s clicking a phishing email, responding to a fraudulent invoice request, sharing sensitive information or overlooking the signs of an incident, attackers often rely on people rather than technology to achieve their goals.

Our Staff Cyber Security Awareness Training helps organisations build a stronger cyber security culture by giving employees the knowledge, confidence and practical skills they need to recognise threats and respond appropriately.

Sessions are delivered by Police Cyber Protect specialists and align with guidance from the National Cyber Security Centre (NCSC), the UK’s technical authority for cyber security. As part of the Home Office-funded Police Cyber Crime Programme, this training is provided completely free of charge.


Who Is It For?

Suitable for:

  • Private sector organisations
  • Charities and voluntary organisations
  • Public sector organisations
  • NHS and healthcare providers
  • Educational organisations
  • Housing associations
  • Critical national infrastructure operators
  • Professional services firms
  • Manufacturers and industrial organisations

The training is suitable for staff at all levels, from front-line employees through to senior managers. In fact, we strongly encourage leaders to attend alongside their teams, even where we are also delivering our Leadership Cyber Security Training. Simply being present helps demonstrate that cyber security is important to the organisation and reinforces the culture that keeping the organisation safe is everyone’s responsibility.


Tailoring to You

We tailor delivery according to the size and cybersecurity maturity of the organisation.

Micro and Small Organisations

For micro and small organisations, training is typically delivered virtually through webinars. Where demand exists, we may also work with business networks, trade bodies and chambers of commerce to deliver sessions to multiple organisations at once.

Medium and Large Organisations

For medium-sized and large organisations, we can usually deliver training in person at your premises, allowing greater interaction, discussion and engagement with staff.


What Staff Will Learn

Topics may include:

  • Why cyber security is everyone’s responsibility
  • The most common cyber threats affecting organisations
  • How cyber criminals steal usernames and passwords
  • Multi-Factor Authentication (MFA) and 2-Step Verification
  • Data breaches and password reuse
  • Password managers and passkeys
  • Device security and updates
  • Malware and ransomware
  • Physical security in the workplace
  • Security culture and safe behaviours
  • Phishing, vishing and social engineering
  • Business email compromise and invoice fraud
  • Privacy and information exposure online
  • What to do if a cyber incident occurs
  • Reporting phishing, fraud and cyber crime

What Participants Take Away

Attendees leave with:

  • Greater confidence recognising phishing and social engineering attacks.
  • A better understanding of how cyber criminals target organisations.
  • Practical actions they can take immediately at work and at home.
  • Improved awareness of modern cyber threats and scam techniques.
  • A clearer understanding of their role during a cyber incident.
  • Increased confidence challenging suspicious requests and unusual behaviour.
  • Awareness of free cyber security resources available from policing and government.

Why We Take a Personal-First Approach

Many employees naturally view cyber security as somebody else’s responsibility, whether that’s the IT department, a cyber security team or senior management.

We’ve found that people engage far more readily when we start with the technology and accounts they use every day in their personal lives. After all, protecting your family photos, personal email, social media accounts and online banking matters to everyone.

The reality is that the behaviours which keep people safe at home are often the same behaviours that protect organisations at work: using strong authentication, spotting phishing attempts, questioning unusual requests and adopting secure online habits. By helping people protect themselves first, we make it easier for them to understand how those same behaviours contribute to a stronger, more resilient organisation.

To support this approach, we introduce attendees to Police CyberCheck, our free cyber security improvement tool that helps individuals take practical steps to improve their personal cyber resilience.

The result is training that benefits both the individual and the organisation.

Enquire Now

Tell us a little about your organisation, location, cybersecurity maturity and audience size and we’ll discuss the options with you. We typically need at least one month’s notice to find a date that works for everyone, although this can sometimes be longer during busy periods.

FAQs

Nothing.

This service is provided completely free of charge through the Home Office-funded Police Cyber Crime Programme.

The training is designed for all staff, regardless of role, department or technical ability, including senior leaders and managers.

We strongly encourage leaders to attend alongside their teams. When employees see leaders investing their time in cyber security awareness, it sends a powerful message about the importance of security and helps build a positive security culture across the organisation.

This session is deliberately designed for everyone and focuses on the practical behaviours that help prevent cyber incidents. There is little overlap with our Leadership Cyber Security Training, which is aimed specifically at boards, executives and senior decision-makers and explores strategic cyber risk, governance, organisational resilience and incident leadership.

Cyber security is not solely an IT responsibility. Every member of staff has a role to play in protecting their organisation, colleagues, customers and services.

Yes. For medium and large organisations we can often deliver sessions to sizeable audiences, subject to venue capacity and available technology.

Where organisations have very large workforces, we can discuss a combination of in-person and virtual delivery options, including multiple deliveries in person on the same day where possible.

No. The content is designed for everyday users of technology rather than technical specialists.

The focus is on practical behaviours, recognising threats and understanding how staff can help prevent cyber incidents.

Yes, to a degree. Whilst there are key messages and learning outcomes we are expected to deliver, we can tailor examples, scenarios and discussion points to make them relevant to your sector, workforce and operating environment.

Typically between 60 and 90 minutes.

We require at least one hour to ensure key topics can be covered and staff have an opportunity to ask questions.

For small organisations, training is typically delivered virtually.

For medium-sized and larger organisations, we can usually deliver training in person at your premises.

We’ll discuss the most appropriate option when planning the session.

No. This training is intended to complement, not replace, any organisation-specific training, policies or compliance requirements.

Your organisation’s policies and procedures should always take precedence where applicable.

Many organisations already provide mandatory cyber security awareness training, and that’s a good thing.

Our role is not to replace those programmes. Instead, we supplement them with current threat intelligence, real-world examples, lessons learned from actual incidents and practical advice grounded in policing experience and NCSC guidance.

We often find that hearing these messages from outside the organisation helps reinforce existing internal training and encourages greater engagement from staff.

Maybe. In some circumstances we may be happy for organisations to record sessions for internal use, however this should be discussed with us before the event.

We may need to adjust content to ensure material remains current, accurate and suitable for ongoing use.

Cyber security awareness should not be treated as a one-off activity. We would expect all organisations to provide cyber security awareness training to staff at least annually.

Threats, scams and criminal tactics evolve constantly, and people naturally forget information that isn’t reinforced over time. Organisations should consider how they maintain awareness through regular communications, exercises, policy updates and refresher training.

In our experience, the most effective approach combines short, regular cyber security messages throughout the year with more substantial training sessions delivered periodically, giving staff the opportunity to engage, ask questions and discuss emerging threats.

Our training can form part of a wider approach to building and maintaining a positive security culture.

Our training is based on recognised cyber security best practice and aligns with guidance from the National Cyber Security Centre (NCSC), the UK’s technical authority for cyber security. We focus on principles, behaviours and practical actions that help reduce cyber risk across all organisations. These should not conflict with well-designed organisational policies and procedures.

Where there are areas that are commonly organisation-specific, such as reporting phishing emails, escalating suspicious activity or responding to incidents, we make it clear that staff should follow their organisation’s local policies and procedures.

If there are particular policies, processes or messages you’d like us to reinforce during the session, we’re happy to discuss this as part of the planning process. We can also run through the content with your team beforehand to identify any organisation-specific considerations and ensure the training complements your existing policies, procedures and ways of working.

Yes. Our sessions are delivered by Police Cyber Protect officers and staff who work with organisations across the South East to improve cyber resilience and reduce cyber crime.

Our advice is aligned with guidance from the National Cyber Security Centre (NCSC) and informed by real-world incidents, emerging threats and policing experience.

Quite a lot.

Police Cyber Protect teams regularly support organisations affected by phishing attacks, ransomware, business email compromise and other cyber incidents.

We work closely with policing, government and industry partners, deliver threat briefings to organisations of all sizes and have insight into the threats currently affecting businesses, charities and public sector organisations.

This allows us to deliver practical advice based on both recognised best practice and lessons learned from real incidents.

No.

Presentation slides on their own rarely provide the full context of a live session.

Instead, we signpost attendees to trusted resources including Police CyberCheck and guidance from the National Cyber Security Centre.

Not currently.

Our focus is on delivering practical, engaging cyber security awareness training rather than formal certification. While attendees do not currently receive a certificate of attendance, they leave with practical skills, trusted guidance and access to free resources that can help them continue improving their cyber security.

Use the button below to contact our team.

Tell us a little about your organisation, location, workforce size and preferred delivery method, and we’ll discuss the available options.


Service Availability and Disclaimer

All services are delivered through the Home Office-funded Police Cyber Crime Programme and are subject to available resources, operational commitments and ongoing programme funding.

Services are primarily available to eligible organisations, communities and individuals located within the South East region served by SEROCU, including Berkshire, Buckinghamshire, Oxfordshire (Thames Valley Police); Hampshire & the Isle of Wight; Surrey; and East Sussex and West Sussex (Sussex Police).

In exceptional circumstances, we may be able to support organisations outside the region where there is a clear connection to our policing area, such as organisations headquartered within the region but seeking to use an alternative venue elsewhere. Any such arrangements are entirely at our discretion.

Whilst we aim to accommodate requests wherever possible, submission of an enquiry does not guarantee that a service will be delivered. We reserve the right to decline, defer or prioritise requests based on operational priorities, capacity, funding, audience suitability and anticipated impact.

All advice, guidance, training and exercising activities are based on recognised good practice and align with guidance published by the National Cyber Security Centre (NCSC), the UK’s technical authority for cyber security. However, responsibility for assessing, implementing and acting upon any advice remains with the individual or organisation receiving the service. Training and awareness services are intended to complement, not replace, organisation-specific policies, procedures, legal obligations, professional advice or regulatory requirements.

The South East Regional Organised Crime Unit, participating police forces and partners accept no liability for any loss, damage, cost or consequence arising from reliance upon information, advice, training materials, exercise outcomes or recommendations provided through these services.