# Security awareness in the mid-market: training that works at the decisive moment

> How awareness works instead of annoying: show real attack patterns, train short and often, build a reporting culture, involve managers and make the effect measurable.

URL: https://techport.ai/en/it-beratung/sicherheit-und-resilienz/awareness-und-schulung

---

1.  [IT Consulting](/en/it-beratung)/
2.  [Security and Resilience](/en/it-beratung/sicherheit-und-resilienz)/
3.  Training and awareness

[Security and Resilience](/en/it-beratung/sicherheit-und-resilienz)

# Training and awareness

By Redaktion techport.ai, IT-Beratung · Last updated on 21 August 2026

The most common entry into a company network runs through a person who clicks something that looks genuine. That is not an argument against people but an argument for preparation. Attacks by email and telephone today are well made, linguistically flawless, often referencing real transactions and real names from the company.

Awareness works when it is concrete and when reporting is easier than staying silent. It does not work as an annual compliance module with a click-through.

## How you notice it

*   After a suspicious click nobody speaks up, for fear of consequences.
*   Training happens once a year and uses examples that look obviously fraudulent.
*   It is unclear who to report a suspicion to and what happens then.
*   Payment instructions by email get processed without a callback when the sender looks familiar.

## Why this happens

Security training is frequently designed as compliance: once a year, the same for everyone, with generic content. It creates an awareness that fades within two weeks and conveys a picture of attacks that bears little resemblance to reality. At the same time, a culture in which a mistake counts as misconduct prevents exactly the behaviour that matters in an emergency: immediate reporting. In a successful attack, time is the decisive factor.

## How we go about it

1.  **Show real patterns.** We work with examples that fit your company: forged invoices from your actual suppliers, requests in the name of your management, calls from supposed providers. Those examples stick, generic warnings do not.
2.  **Train short and often.** We use short units several times a year rather than one long annual session, supplemented by targeted content for particularly exposed areas such as finance, purchasing, sales and HR.
3.  **Build a reporting culture.** We set up a simple reporting route, ensure the reporting person gets feedback and make clear that reporting after a click is expressly wanted. Managers have to model that.
4.  **Measure the effect and adjust.** We measure how many reports arrive and how quickly, and use test campaigns with a sense of proportion. The aim is a rising reporting rate, not a falling click rate at any cost.

## What you gain

*   Suspicious cases reported within minutes rather than not at all.
*   Staff who recognise the patterns actually in use.
*   Evidence of completed training for audits and customers.

## From our projects

The most important metric is not how many people click a test message but how many report it and how fast. A company where ten percent click and half of them report within minutes is in better shape than one with a low click rate and not a single report. We therefore set up the reporting route first and train afterwards. The second recurring finding: test campaigns without prior announcement of the procedure damage trust. We agree them in advance with management and, where one exists, with the works council, and evaluate them exclusively in anonymised form.

## Good to know

For companies within the scope of the German BSI Act, training is part of the duties, and members of management have to attend training themselves in order to be able to assess risks. Independently of that, since 2 February 2025 Article 4 of the AI Act requires that staff using AI systems have a sufficient level of AI literacy. Both requirements can be combined into one training concept. Where test campaigns are evaluated in a personally identifiable way, data protection and codetermination have to be observed, which is why anonymised evaluation should be the rule.

## Häufige Fragen

How often should we train?

A short unit per quarter has proven itself, supplemented by ad hoc notices when a new wave of attacks appears. A single long session per year satisfies documentation duties but changes behaviour hardly at all. For new staff a unit belongs in the onboarding, within the first few days.

What do we do when someone has fallen for a phishing email?

Have it reported immediately, lock the account or reset the password, end affected sessions, check devices and document it. What matters is how the person is treated: anyone who answers a report with consequences will not receive a report next time. The mistake is the click, the damage comes from the time until the response.

## Let us talk about Training and awareness

In a thirty minute first call we work out where your biggest lever sits and whether we are the right people for it.

[Arrange an initial call](/en/kontakt)[Our consulting](/en/so-funktionierts)

## Further reading

[Security and ResilienceOrdering identities and accessWho may do what and why: build an access concept, use roles instead of individual rights, introduce multi-factor authentication, automate joiners and leavers and review permissions regularly.](/en/it-beratung/sicherheit-und-resilienz/identitaeten-und-zugriffe)[Security and ResilienceNIS2 and cyber securityWhether your company falls under the new German BSI Act, which duties follow, how risk management, reporting and supply chain are implemented, and what applies personally to management.](/en/it-beratung/sicherheit-und-resilienz/nis2-und-cybersicherheit)[Rollout and ChangeSupporting the changeWhy technically finished systems stay unused and what helps: involve those affected early, inform managers first, take resistance seriously and measure adoption after go-live.](/en/it-beratung/einfuehren-und-veraendern/change-management)[KnowledgeIT maturity checkKnow where your IT stands in ten minutes.](/en/it-beratung/reifegrad-check)[KnowledgeIT metricsDefinitions and formulas read the same way across the company.](/en/it-beratung/kennzahlen)

Back to the field [Security and Resilience](/en/it-beratung/sicherheit-und-resilienz)

Rt

Written by

[Redaktion techport.ai](/ueber-uns), IT-Beratung

Mehr als 15 Jahre Erfahrung in IT-Projekten des Mittelstands, Auswahl und Einführung von Unternehmenssoftware, Aufbau von IT-Betrieb und Informationssicherheit in wachsenden Organisationen.

This page reflects the position at the date given and does not replace legal advice. For specific questions we work together with your legal advisers.

[More about us](/en/ueber-uns)

More from techport.ai

[

Software

Custom process software for mid-sized companies.

](/en/loesungen)[

HR consulting

People processes and the systems behind them.

](/en/hr-beratung)[

IT maturity check

Ten minutes to a clear position.

](/en/it-beratung/reifegrad-check)[

HR maturity check

24 statements, a result per field.

](/en/hr-beratung/reifegrad-check)[

Funding

BAFA grant plus more than 50 programmes for delivery.

](/en/foerderung)[

Process in practice

How workflows become reliable software.

](/en/sop-praxis)[

Data and AI

Analysis, forecasts and assistance systems.

](/en/daten-ki)[

About us

The people behind techport.ai.

](/en/ueber-uns)
