consigliere of your IT administrationABOVE IT

Annual Security Awareness Training Is Not Enough

Annual security awareness training does not measure or increase an organization’s cyber expertise or resilience, nor does it change ways of working. Instead, security training should be thought of as a continuous and measurable activity across the entire organization. In this blog, we go through the effects of training on organizational security and why we at Above IT chose Moxso as a partner to raise our customers’ security resilience.

Attacks Are Evolving Faster Than Ever

In some organizations, security training still means one thing: in the autumn, a one-hour video is watched, completion is marked, and it is recorded for auditing purposes that the staff has been trained. In March, a near-perfect phishing message arrives, someone logs into the wrong page, and the credentials are in the hands of the attacker. The problem is not that people don’t care. The problem is primarily the lack of training and deficient processes.

Easily recognizable phishing messages with typos are a thing of the past. Nowadays, Finnish-language scam messages are linguistically so flawless that you cannot tell it is a scam based on the language alone.

Channels have also changed. An attack no longer starts only in email. Phishing has moved to users’ phones, where company protections may not be available. CEO fraud starts with an email and continues with a text message or a phone call aimed at confirming requests. The combination works because each individual event adds credibility when the previous one has already laid the groundwork.

Familiar, more familiar Teams?

External Teams communication is open by default. Anyone from another M365 tenant can send a message or call a person. Teams is trusted more than email, and attackers have noticed this too. Training should take different channels into account, rather than focusing solely on scam attempts coming through centralized email.

It is also noteworthy that training alone is not enough. Technical security measures must be implemented and developed alongside it, both in Teams and in other areas.

Security Awareness Can and Should Be Measured

Instead of the same training for everyone, a more effective model starts with a baseline measurement. Simulated phishing messages are sent to the organization’s employees to see what happens. Who clicked, who entered credentials, who reported the message, etc.

The results form risk profiles at an individual level. Training is targeted accordingly. A high-risk person receives intensive, repeated exercises on identifying phishing, and those who already know the basics receive more challenging content. Progress is actively monitored.

Why We Chose Moxso as a Partner

We reviewed a number of security training platforms and settled on the Danish company Moxso because it best met our requirements. Their philosophy on security training resonated with us. The platform combines continuous phishing simulations and short training sessions, and it forms individual-level risk profiles that update based on behavior.

Moxso’s benefits in a nutshell:

  • Content is in Finnish and authentically created. Training videos are filmed with actors also in Finnish. It is not just machine-translated subtitles over an English video.
  • Simulations are not limited to a standard email link. Campaign types include various realistic scam attempts that are not limited to email messages or the links within them.
  • Data breach monitoring is included in the same service. The platform allows you to see if the organization’s user credentials appear in external data breaches.
  • Training is micro-learning. In small doses at a time, which does not take up too much time.
  • Gamification is included. The platform enables small-scale competitions. Who in the organization has identified the most phishing messages and completed the most training.
  • Reporting is one button away. Phishing is reported using a button found in Outlook, which is easily accessible to everyone. Likewise, users receive immediate feedback when they identify a phishing message. This way, IT or colleagues are not unnecessarily burdened with reports of phishing simulations.

NIS2 and the Cybersecurity Act Brought Requirements for Training Too

The Cybersecurity Act came into force in Finland in April 2025, bringing the requirements of the NIS2 directive into national legislation. For organizations within its scope, staff security training is no longer just a nominal practice, but part of the required risk management, for which the organization’s management is ultimately responsible.

The supervisory authority may ask the following questions: is the training continuous, is it documented, and can you show progress in numbers? A video watched once a year or a document read does not answer any of these. A program based on simulations and metrics answers all three without separate reporting work.

Where Should You Start?

A good progression model for developing security awareness is this:

  1. Measure the baseline. Perform a baseline measurement before you train anything. Without it, you cannot demonstrate progress.
  2. Agree on metrics and reporting. Decide what and when to report to management or the rest of the organization. For example, a quarterly summary is sufficient.
  3. Start training with short sessions. A long mandatory course is discouraging and does not bring the desired expertise.
  4. Make reporting easy and link it to existing security processes. User reports of phishing messages and other security anomalies/incidents must end up somewhere where they are acted upon.
  5. Do not name those who click. If the simulation turns into shaming, reporting rates will drop and you will lose one of your most important metrics.
  6. Target content by role. For example, finance needs invoice scams, management needs targeted spear-phishing, and production needs equipment and physical security.
  7. Take training beyond email. Include QR campaigns by the second round at the latest. If you have never tested anything other than an email link, you have no idea how the organization reacts to a scam coming to a phone.

Security awareness is the only control that works even when technical protection fails. Therefore, it should be considered with at least the same seriousness as backups: continuous, measurable, and regularly tested.

We are a Moxso partner and together with our customers, we build a security training program that produces measurable change and withstands audits. We handle baseline measurement, implementation, role-based targeting, and management reporting. Contact us, and let’s go through where your organization should start.

Book a meeting from my calendar!

As your IT management’s trusted advisor, our task is to ensure that the IT environment you manage remains secure and is not compromised. By learning and working together, your organization will succeed.

Search site:

Search site: