Sound familiar?
- Staff have been caught by fake Microsoft login pages
- Someone nearly paid a fake supplier invoice
- People share passwords by email or on sticky notes
- Staff are scared to admit they clicked something
- MFA prompts get approved without thinking
- Insurers or customers ask whether staff are trained
Key facts
- The Cyber Security Breaches Survey 2025/2026 found only 19% of UK businesses ran staff cyber security training or awareness activities
- Phishing affected 38% of UK businesses in the same period
- Sessions are short, practical and based on your own systems, not generic slides
- Covers phishing, invoice fraud, MFA, password managers, file sharing and reporting
- The NCSC offers free 'Top Tips for Staff' training that we can build on
- Delivered remotely by video call at £45 an hour + VAT
Why training matters for small teams
In a small business, one person's click can affect everyone. According to the UK Government's Cyber Security Breaches Survey 2025/2026, phishing affected 38% of businesses in the previous year, yet only 19% of businesses ran any staff training or awareness activity. In large businesses the figure was 84%. That gap is easy to close.
Technical controls catch most attacks. Training is for the ones that get through: the fake invoice from a real supplier's hacked mailbox, the phone call from "Microsoft support", the MFA prompt that arrives when you are not signing in.
What we cover
- Phishing: how to check the real sender address, hover over links before clicking, spot fake login pages and recognise "shared document" lures. See phishing protection.
- Invoice and payment fraud: why bank detail changes must always be confirmed by phone on a known number.
- MFA: what an unexpected MFA prompt means, why you never approve one you did not trigger, and how number matching works.
- Passwords: using a password manager, why reusing passwords is the real danger, and passphrases.
- Phone scams: fake IT support and bank calls, and never installing remote access software for a caller.
- Sharing files safely: OneDrive and SharePoint sharing links, "specific people" versus "anyone with the link".
- Devices: locking screens, installing updates when prompted, using work devices for work.
- Reporting: who to tell, how fast, and that reporting a mistake is always the right call.
How sessions work
We deliver training remotely over Microsoft Teams, Google Meet or Zoom. A typical session for a small team is about an hour, with time for questions. We base examples on the systems you actually use, so staff see what a real Microsoft 365 sign-in page looks like compared with a fake one, and where the "Report" button is in their own Outlook.
New starters can have a shorter one-to-one session as part of their IT setup. We can also send short follow-up notes when a new scam is doing the rounds.
Real examples we use
Generic slides are forgettable. We show staff the scams that actually reach small UK businesses, with the tell-tale signs pointed out:
- A "voicemail received" email with an HTML attachment that opens a fake Microsoft 365 sign-in page.
- A DocuSign or Adobe Sign request for a contract nobody is expecting.
- A text claiming to be from HMRC, a parcel courier or the DVLA with a payment link.
- A reply in an existing email thread with a supplier, sent from a lookalike domain one letter different from the real one.
- A QR code in a PDF asking staff to "re-verify" their account on their phone, which takes them away from the protection on their work PC.
Seeing the real thing makes the next one much easier to spot.
A no-blame reporting culture
The most important outcome is not that nobody ever clicks. It is that when someone does, they tell you straight away. A compromised Microsoft 365 account reported in five minutes can be locked down before any damage is done. One reported two weeks later may already have been used to send fake invoices to every customer.
We help you set a simple rule: if in doubt, forward it to IT and ask. On our Complete plan at £99 a month + VAT, staff can forward suspicious emails to our helpdesk and get an answer, which makes asking easy.
Free resources and pricing
The NCSC publishes free "Top Tips for Staff" e-learning, which is a good baseline. We often recommend staff complete it first, then use our session to apply it to your business, your systems and the scams your sector actually receives.
Training sessions are charged at £45 an hour + VAT, including preparation tailored to your setup. If training is part of a wider cyber security project or Cyber Essentials readiness, we quote it together.
What it costs
Support plans from £25 a month + VAT, or £45 an hour + VAT for one-off fixes. Pick a plan if you want it looked after every month, or pay by the hour for a one-off job.
Essential
Keep it updated, backed up and watched.
- Website software updates (core, plugins, themes) applied and checked
- Daily backups
- Uptime monitoring
- Security monitoring
Business
Updates plus an hour of fixes every month.
- Everything in Essential
- 1 hour of fixes or changes every month
- Priority support
Complete
Website and your team's IT, covered.
- Everything in Business
- 3 hours of fixes or changes every month
- IT and Microsoft 365 helpdesk for your team
No plan? The first 30 minutes are the minimum charge, then we bill in 15-minute blocks.
Frequently asked questions
How long is a staff security training session?
dijitul's standard session for a small team is about an hour, delivered remotely by video call, with time for questions. We tailor it to the systems you use, such as Microsoft 365 or Google Workspace. New starters can have a shorter one-to-one version as part of their setup.
How much does cyber security training cost?
dijitul charges £45 an hour + VAT for training, including tailoring it to your business. A typical small team session is around an hour of delivery plus preparation. If you are on the Complete plan at £99 a month + VAT, the included hours can be used for training.
Is there free cyber security training for staff?
Yes. The NCSC offers free 'Top Tips for Staff' e-learning covering phishing, passwords and devices. dijitul recommends it as a baseline, then runs a practical session showing what real attacks look like on your own systems and how staff should report them.
Do you run phishing simulation tests?
If you have Microsoft Defender for Office 365 Plan 2 or Microsoft 365 E5, Attack Simulation Training is built in. dijitul can set up simulated phishing campaigns and assign follow-up training. For smaller licences we focus on live sessions using real examples instead.
What should staff do if they click a phishing link?
Tell IT immediately, even if nothing seemed to happen. If they entered a password, it needs changing from a trusted device and active sessions revoked. dijitul trains staff that reporting fast is always the right thing, because a quick report stops most damage.
Related
Get it fixed
One-off fixes are £45 an hour + VAT. You'll know the likely cost before we start.