Microsoft is retiring SMS and voice MFA. Passkeys become the default on 1 September 2026; SMS and voice switch off on 1 February 2027. Book your free health check
IT Next Door
← All insights
Awareness · 5 min read

Why staff training beats buying another security product

Most incidents we respond to start with a person making a reasonable decision on a convincing page. No product catches all of that.

There is a natural instinct, after a near miss, to buy something. Another filter, another agent, another console. It feels like action. It is also usually the least effective thing you can do with that money.

Where incidents actually start

The pattern is consistent. Somebody receives a message that looks legitimate — often from a real supplier whose own mailbox was compromised first, referencing a real invoice, in a thread they recognize. They enter their credentials on a page that looks exactly like the Microsoft sign-in. Or they approve an MFA prompt at a moment when they happen to be signing in to something else anyway.

No technical control catches all of this, because nothing about it is technically anomalous. A legitimate domain sent a legitimate message, and a legitimate user typed their own password. The filter has nothing to object to.

What training actually changes

The claim is not that training makes people infallible. It is narrower and more useful than that:

  • Click rates fall measurably. Organizations running regular simulations typically see the proportion of staff who click a phishing test drop substantially over the first few months, then hold.
  • Reporting rates rise, which matters more. One person reporting a message at 9:15 lets you purge it from every other mailbox before the second person opens it. That is the difference between an incident and a non-event.
  • The MFA-fatigue attack stops working once people understand that an unexpected prompt is an attack rather than a glitch.
  • Payment fraud gets caught by process, because staff who have seen how invoice interception works start calling the supplier on a known number before changing bank details.

Why it is cheaper than the alternative

Awareness training costs a fraction of a security platform per user per year. It requires no deployment, no agent, no console, and no tuning. And unlike a product, it improves the effectiveness of everything else you already own — trained staff generate the reports that make your detection tooling useful.

What good training looks like

Not an annual hour-long video. That is a compliance exercise and everybody knows it.

  • Short modules, a few minutes, delivered regularly rather than annually.
  • Simulations that look like the real thing — your suppliers, your systems, your language — not obvious tests with spelling mistakes in them.
  • Content that adapts to the individual, so people who keep clicking get more, and people who do not are not punished with repetition.
  • A reporting button in Outlook, and a culture where using it is welcomed rather than treated as an admission.
  • Reporting to management on trend, not on individual blame. The moment people fear being named, they stop reporting.

The honest caveat

Training is not a substitute for the technical controls. MFA, Conditional Access, patching and endpoint protection all still need to be in place — they catch what training misses, and training catches what they miss. The argument is about sequencing. If you have the basics configured and you are choosing what to add next, the people are usually the better investment.

We run this with Phin: short adaptive modules, realistic simulations and reporting you can show a board or an insurer.

Ask us about your setup More insights →