The role of the human factor

According to the Verizon Data Breach Investigations Report for 2025, the human factor was present in 60 per cent of all the breaches analysed. This is not about disloyal employees — the picture is dominated by credential abuse and social engineering, above all phishing. In the same report, ransomware featured in 44 per cent of breaches, and the median ransom paid was USD 115,000, while 64 per cent of the organisations attacked did not pay a ransom at all.

The Polish data points the same way. In 2025 CERT Polska registered 260,783 incidents, of which computer fraud accounted for 97.1 per cent, and phishing alone for 78,391 cases — 30 per cent of all events.

The conclusion is an uncomfortable one for IT budgets: you can buy the best tools on the market and still lose data, because somebody typed their password into a page that looked deceptively like the company's own.

Attack techniques

Social engineering is the art of manipulating people into disclosing confidential information or granting access to systems. Phishing is the most common form of social engineering, where an attacker sends an email apparently from a trusted source (a bank, a manager or a colleague, say) asking the recipient to click a link or enter a password. Spear phishing is a more targeted form, where the attacker gathers information about a specific employee and crafts an email designed for that person alone. Vishing is phishing conducted by telephone — the attacker calls the company, posing as an IT employee or a service provider, and asks the employee to confirm a password "for security reasons". Smishing is phishing by SMS. Pretexting is a technique in which the attacker invents a credible story in order to obtain information — calling an HR employee, for example, posing as a job applicant and asking them to confirm a security procedure.

The human factor was present in 60 per cent of security breaches.

All of these techniques are surprisingly effective. An IBM report from 2023 indicates that the average click rate on phishing links is 3.4 per cent, and in some sectors reaches 10 per cent. That means that if you send a phishing email to 1,000 employees, on average 34 will be inclined to click the malicious link, and several will be inclined to enter their password. If employees are not trained, those numbers can be considerably higher.

The awareness programme

A security awareness programme is a set of activities designed to raise employees' knowledge and awareness of security threats. It should cover several elements. The first is induction training for new employees, explaining the security threats, the company's security policy and the employee's responsibilities. The second is periodic training (at least once a year) for all employees, refreshing their knowledge of threats and procedures. The third is role-specific training — finance staff should know about financial fraud, customer service staff should know about threats to customer data, and so on.

Training as a legal obligation, not good practice

It is worth knowing that in some organisations security training has stopped being a matter of choice.

The Polish NIS-2 implementing act (the KSC Act), as amended on 3 April 2026, transfers responsibility for cybersecurity to management bodies, together with an obligation for senior management to take part in training. It cannot be delegated — a fine may fall personally on the head of the entity, of up to 300 per cent of their remuneration.

The National Interoperability Framework (KRI) Regulation (Journal of Laws 2024, item 773), in §19(2)(6), requires entities performing public tasks to provide training on threats, the consequences of breaches and the use of protective measures. This is a continuing obligation, not a one-off induction session.

The GDPR identifies awareness-raising and training of staff in Article 39(1)(b) as a task of the data protection officer, and in Article 32 requires appropriate organisational measures — of which training is one.

ISO/IEC 27001:2022 sets requirements in clauses 7.2 (competence) and 7.3 (awareness), and Annex A adds control 6.3 on information security awareness, education and training.

The common denominator of all four regimes: what counts is evidence. An attendance list with no record of the topics covered and no check that the knowledge was absorbed is a document, not proof that the obligation has been met.

Training methods

The format of training matters. E-learning courses are accessible and easy to roll out, but can be dull and of limited effectiveness — many employees will get through a course without actually taking the information in. Interactive workshops, where employees can discuss threats and scenarios, are considerably more effective. The most effective tool of all is phishing simulation — employees receive "fake" phishing emails (clearly flagged as a test), and those who click are directed to a short piece of training explaining the mistake. Combined with repetition, this creates conditions for learning that are far more effective than traditional training.

Phishing simulations are the most effective tool.

Article 39(1)(b) GDPR states clearly that the data protection officer should support the organisation in training staff involved in processing operations. ISO 27001, clause 7.2 (Competence) and clause 7.3 (Awareness), requires the organisation to ensure that everyone with access to information systems is competent and aware of security threats. These requirements are enforced — non-compliance may be identified by auditors or by the regulator.

A year-long programme, step by step

An awareness programme that works has a rhythm and assigned ownership. The structure below has proved itself in organisations of anything from a few dozen to a few hundred people.

Starting point: a baseline measurement. Before the first training session, it is worth running a phishing simulation and a short knowledge survey. Without one, there is no way of later demonstrating that anything has changed — and that is the question both the board and the auditor will ask.

First quarter: the basics for everyone. Recognising phishing, password hygiene and multi-factor authentication, rules for remote working, the route for reporting suspicions. Short modules, concrete examples from the organisation's own sector.

Second quarter: high-risk roles. Accounting and finance (CEO fraud, changed bank account numbers), HR (special categories of data, attachments from unknown senders), IT administrators (secure configuration, privileged account management), the board (targeted attacks, obligations under the KSC Act).

Third quarter: rehearsing the response. A tabletop exercise on an incident scenario involving the people who will actually take the decisions if an event occurs. It is the only moment at which it comes to light that the procedure assumes contacting someone who left the company a year ago.

Fourth quarter: measurement and conclusions. Repeat the simulation and the survey, compare against the baseline, report to management and plan the year ahead. Lessons from incidents that actually occurred are more valuable here than the result of any simulation.

Throughout the year: onboarding. A new employee takes the basic module in their first week, not at the next quarterly campaign. The period between joining and the first training session is the window in which risk is highest.

What not to do

Do not punish people for clicking in a simulation. A programme in which the simulation result feeds into performance appraisal teaches one thing: don't report. And reporting is the only moment at which the organisation can act before harm is done.

Do not run a single annual session "for everyone". A three-hour lecture once a year has documentary value and almost no operational value. Short, frequent and specific works better than long and rare.

Do not copy phishing scenarios from the internet. An effective simulation mirrors the messages that actually reach that organisation — from its systems, its suppliers, its sector. A "DHL parcel" message in a company that does not use DHL measures nothing.

Do not stop at e-learning. A platform is a means of delivering content, not a programme. Without exercises, measurement and feedback, all you are left with is a report on completion rates.

Measuring effectiveness

The effectiveness of a security awareness programme can be measured through several KPIs (Key Performance Indicators). The first is the phishing click rate — what percentage of employees click links in phishing tests. If that figure is 10 per cent at the start of the programme and falls to 3 per cent after a year of training, that is a substantial improvement. The second is the reporting rate — what percentage of employees report suspicious emails to the security function. Employees who actively look for and report threats are a valuable support to the security team. The third is time to report — how quickly employees react to suspicious activity. The fourth is the number of incidents linked to employee error — is that number falling over time?

The scale of the problem is well illustrated by the data leak at the University of Warsaw — the entry point was an infected private computer, not a vulnerability in the university's systems.

Security culture

Building a security culture in an organisation requires management commitment. If senior management, led by the CEO, takes security seriously and actively supports the awareness programme, employees will be more interested and more engaged. If, on the other hand, management ignores security and does not take part in training, employees will conclude that it does not matter. The organisations with the best programmes are those in which management itself takes part in phishing simulations and draws conclusions from the results, rather than treating them as a report on the workforce.

The economics are worth working out on your own numbers, not on averages from reports. On the cost side of the programme there are three items: employees' time, preparing materials tailored to the sector, and a phishing simulation tool. On the risk side there is the cost of operational downtime, the cost of restoring data, any administrative fine, and the cost of handling notifications to the individuals whose data has leaked.

That last item tends to be underestimated. In a breach affecting a few thousand people, simply handling the notifications and the queries that follow them can occupy a team for weeks.

It is also worth making sure the programme measures the right thing. A falling click rate on its own can be misleading — after a few campaigns, employees learn to recognise simulations, not attacks. A far better measure of maturity is the reporting rate: what proportion of the people who received a suspicious message reported it to the security team. An organisation in which the click rate has fallen to zero but nobody reports anything has not become safer — it has become quieter.

The "Security Champions" model also works well — designating in each department a person who receives extended training and acts as the first point of contact for their colleagues. A distributed approach can be more effective than centrally educating everyone at once, because it is easier to ask about a suspicious email at the next desk than to ask an external trainer.

Cybersecurity training is not a one-off project — it has to be a permanent part of the organisation's culture. Threats evolve, new attack techniques appear regularly, and employees need constant refreshers. Organisations that take regular information security training seriously can substantially reduce their cybersecurity risk and — just as importantly — can build a culture in which everyone understands their role in protecting the company's data and systems.

Training is one of the pillars — we describe the others in Cybersecurity in your company.