Skip to content
otterly.cloud

Security guide

Does cyber security training actually work?

Short answer: yes, when it's practice instead of a lecture. Here's what good training looks like, what it shouldn't feel like, and what it costs per user.

Cartoon coach otter with a clipboard addressing a row of attentive otter pups

Technology catches most attacks. People catch the rest.

Our minimum standard screens email for phishing and watches every device with 24/7 EDR, and that layer catches the overwhelming majority of attacks. But no filter on earth catches everything, and attackers design the survivors specifically to look legitimate: the supplier invoice with new bank details, the boss "urgently" needing gift cards, the login page one pixel off the real one. The last line of defence is the person reading the email, and that person performs exactly as well as they've practised.

What good training looks like

Simulated phishing, little and often. Realistic but harmless fake phishing emails land in your team's inboxes through the year. Click one and you get a friendly, thirty-second explanation of the tells you missed, at the exact moment it's most memorable. Report one and you've just rehearsed the single most valuable habit in security.

Bite-size lessons, not annual marathons. A few minutes a month beats a two-hour compliance video everyone plays at double speed in November. Short, regular, slightly varied: the same way otters teach their pups to swim.

No blame, ever. The goal is a team that reports suspicious emails early and often, and nobody reports anything in a workplace where clicking the test gets you mocked in the group chat. The metric that matters most isn't the click rate going down, it's the report rate going up.

Cartoon otter presenting beside an old-fashioned projector

Does it measurably help?

Yes. Across the industry, organisations running continuous simulation programs typically see click rates on phishing tests fall from roughly one in three to the low single digits within a year. More importantly, reporting speed climbs, and reporting speed is what turns "forty compromised mailboxes" into "one weird email we deleted at 9:07am". You'll see your own numbers in plain-English reports, so the improvement is visible rather than vibes-based.

What it costs

On the Otterly menu, cyber security training is an optional add-on at $8 per user per month: ongoing phishing simulations and bite-size security training for your team. Tick it in the calculator to see it against your headcount. Then run the 5-minute phishing check to see how your team would do today, before any training at all.

← Back to resources

Train the raft before the river tests them

Add cyber security training to any plan from the calculator. First simulation can be in inboxes within a fortnight.