Cyber Awareness Month: four 10-minute habits for your team

One short exercise a week through October gives your team four security habits they'll keep using. No slides, no test, and nothing that needs an IT department.

An office kitchen counter displays a cork bulletin board with a four-week checklist, a desk phone, a lanyard, and a key fob next to a tap.

In short

Run four 10-minute exercises, one a week through October. Check what a message asks you to do rather than how it looks. Set up a password manager and protect the accounts that move money. Agree a call-before-you-pay rule. Make reporting something you thank people for. Short, repeated habits stick where a single training day fades, and you can measure them through report rates, not click rates alone.

October is Cybersecurity Awareness Month, which runs across Europe as European Cybersecurity Month, coordinated by ENISA, the EU Agency for Cybersecurity. Most small businesses mark it with one training session that everyone has forgotten by Friday. A better plan is four short habits, one a week, that your team keeps doing long after October ends.

Your staff are the people who notice when something is off. Filters catch most bad email, but the message that gets through lands in front of a person, and a team that knows what to do with it is the control that counts. Each exercise below takes about 10 minutes at a team meeting. No slides, no test at the end.

Week 1: judge the request, not the spelling

The old advice was to look for bad spelling and odd logos. Scam messages are now well written, often with the help of AI tools, so that advice no longer holds. What still works is looking at what the message wants you to do.

For this week's exercise, bring three real examples: one email, one text message and one Teams or WhatsApp chat. Your junk folder or your IT provider will have plenty. For each one, ask the team two questions:

  1. What is this asking me to do? Click, log in, pay, change something, or keep it quiet?
  2. How would I check it without using anything in the message itself?

That second question is the habit. Phoning a number you already hold, opening the website from a bookmark, or asking the colleague in person beats any amount of squinting at a sender address. Our post on phishing by phone, text and QR code covers the formats your team is most likely to meet.

Week 2: one password manager, then passkeys where money moves

Most account takeovers start with a reused or guessed password. Long, complex password rules made this worse, because people respond to them by writing passwords down or recycling one across every site. We explain why in password fatigue: why complexity rules backfired.

Spend this week's 10 minutes setting up a business password manager together, so everyone leaves with it installed and one login saved. Then, as a group, list the accounts that can move money or change bank details:

  • online banking
  • payroll
  • your accounting package
  • supplier and Revenue portals

Protect those first with multi-factor authentication (a second check, such as an app prompt, on top of the password) or, where the service offers it, a passkey. A passkey is a login stored on your phone or laptop and unlocked with your fingerprint, face or PIN. There is no password to steal or type into a fake page, which is why it's worth switching on wherever it's available.

Week 3: the call-before-you-pay rule

Invoice fraud needs no hacking on your side. A criminal sends a convincing email, often from a real supplier's compromised mailbox, saying the bank details have changed or a payment is urgent.

Agree one sentence as a team and write it down. For example:

"We never change bank details or make an urgent payment on the strength of an email. We ring the person on a number we already hold, and we wait."

Read it aloud at the team meeting so everyone has heard it, including the owner or managing director. Then agree who keeps the list of known phone numbers for suppliers and senior staff, and where it lives. The rule only works if the number to ring is easy to find. Our post on the invoice scam Irish SMEs miss walks through how these attacks unfold.

The rule protects staff as much as the business. Nobody has to decide alone whether an urgent email from the boss is real.

Week 4: make reporting the thing you praise

The most useful thing a staff member can do after clicking something suspicious is tell someone straight away. Speed matters: a password reset in the first hour is routine, while the same reset a week later may come after a mailbox has been misused without anyone noticing.

People only report quickly if they expect thanks rather than a telling-off. This week:

  • Agree one place to report, such as a named person, a shared mailbox or the report button in Outlook.
  • Thank every report out loud, including the false alarms. A false alarm is the habit working.
  • Promise feedback within 24 hours, so people learn whether the message was real.

If someone does click, treat it as useful information rather than a failure. What you want is a team that speaks up within minutes.

How to tell whether it's working

Click rates on test phishing emails are the number most people track, but they tell only half the story. Look at these as well:

  • Report rate: the share of test or real suspicious messages that someone reports.
  • Time to report: how long between a message arriving and someone flagging it.
  • A follow-up simulation: a test phishing email a month or two after October, to see whether the habits stuck.

A rising report rate and a shorter time to report are the signs to look for. A click rate of zero is unlikely, and chasing it tends to make people nervous of their own inbox.

Keep it going after October

Four weeks builds the habits. Keeping them takes little effort: repeat one exercise each quarter at a team meeting, and walk new starters through all four in their first week. Ireland's National Cyber Security Centre publishes guidance worth bookmarking alongside this plan.

If you'd like a hand, we run phishing simulation and staff awareness training for clients as part of our managed IT service, and a vulnerability assessment gives you a clear starting point. Get in touch and we'll help you plan the month.

What is Cybersecurity Awareness Month, and does it apply in Ireland?

Cybersecurity Awareness Month runs every October. In Europe it is called European Cybersecurity Month and is coordinated by ENISA, the EU Agency for Cybersecurity. It applies to any organisation that wants to use it, Irish businesses included. Nothing about it is mandatory. It is a timely prompt to spend a few short sessions building staff security habits, using free material from ENISA and Ireland's National Cyber Security Centre.

How long should security awareness training take for a small team?

Short and regular works better than long and annual. Around 10 minutes a week for a month builds habits, and a 10-minute refresher each quarter keeps them. Add a short walkthrough for every new starter in their first week. A single half-day session is easy to schedule but most of it is forgotten within days, while repeated short exercises tend to stick.

What security topics should small business staff be trained on first?

Start with the four that come up most often. Recognising scam messages by what they ask you to do. Using a password manager and multi-factor authentication on accounts that move money. Verifying payment and bank-detail changes by phone on a known number. Reporting anything suspicious quickly. These cover email, text, phone and chat scams without needing any technical knowledge.

How do we know if staff security training is working?

Track how many suspicious messages staff report and how quickly they report them, as well as click rates on test phishing emails. Run a follow-up simulation a month or two after the training to see whether the habits held. A rising report rate and a shorter time to report are stronger signs of success than chasing a click rate of zero.

Should staff be disciplined for clicking a phishing email?

Generally no. Punishing a click teaches people to hide mistakes, and a hidden mistake gives an attacker days instead of minutes. Thank people who report, including after they have clicked, and use the event to improve training. Repeated, deliberate breaches of an agreed policy are a separate HR matter, but an honest mistake that is reported quickly is the outcome you want.

All blog posts

Start with a free IT review.

You'll get a clear picture of where you're exposed today, and what it looks like to have your whole IT covered as one managed system. No obligation.