There is a phrase every manager has already heard about cybersecurity: humans are the weak link. It gets repeated at conferences, in brochures and in sales pitches.

It is both true and deeply counterproductive. True, because the vast majority of attacks today go through a person rather than a technical flaw. Counterproductive, because an employee who feels labelled as the system’s weakness does exactly the opposite of what you need: they stay silent.

Here is why this phrase frames the problem wrongly, and what distinguishes awareness training that changes reflexes from a box ticked on a checklist.

Why do attackers target people?

Attacking a machine takes time, skill and luck. You need to find a flaw, exploit it before it is patched, get around a firewall. Attacking a person takes a well-worded e-mail and a little patience.

Swiss figures reflect this choice. In the second half of 2025, of all the reports received by the National Cyber Security Centre, fraud accounted for 15,090 reports, or 52% of the total, ahead of phishing with 6,299 reports. In other words: more than one report in two concerns an attempt to deceive someone, not to break into a machine.

CEO fraud illustrates this phenomenon well. This type of attack, where a scammer poses as an executive to obtain an urgent transfer, was the subject of 605 reports from Swiss companies in the first half of 2025 and 366 in the second. None of these attempts rely on any technical feat. All of them rely on authority, urgency and trust.

The attacker’s reasoning is simple: your firewall does not answer the phone, your accountant does.

A practical consequence follows: company size no longer offers protection. Campaigns do not target anyone in particular, they sweep broadly. A six-person company receives the same fraudulent messages as an international group, with far fewer resources to filter them.

Typical scenario: what no tool blocks

Friday, 4:40 pm. The phone rings at accounting. A polite caller introduces himself as the new contact at a supplier you know well. He announces a change of bank details, confirmed by an e-mail sent moments later from an address that looks like the right one. Nothing in this exchange is technically abnormal: no malware, no attachment, no trapped link. The spam filter will see nothing. Only a person trained to verify any change of bank details through a call to a known number will stop the operation.

What no technical tool can do for you

Technical protections remain essential. An e-mail filter, two-factor authentication and proper backups rule out the majority of automated attacks. We cover them in detail in the Best practices pillar.

But three situations lie completely beyond their reach.

A phone call. No software analyses the conversation an employee has with a convincing stranger. It is the preferred channel for fake IT support and fake suppliers.

An urgent request that appears to come from management. If the message contains neither a link nor an attachment, it is technically harmless. What makes it dangerous is the hierarchical relationship it exploits. See our article on CEO fraud.

A legitimate e-mail sent from a hacked mailbox. When an attacker takes control of a real partner’s mailbox, the message comes from a genuine address, in a genuine conversation thread. No technical protection flags it, because there is nothing abnormal about it. See e-mail account compromise.

In these three cases, your company’s last line of defence is a person. Not a weak link: a line of defence. It is a difference in perspective, but it changes everything else.

What does the absence of awareness training cost?

The cost is not measured in training francs saved. It is measured in reaction time.

An SME without a security culture loses time at three moments. Before the incident, because no one spots the signs of an ongoing attempt. During, because the person concerned does not know who to alert. Above all afterwards, because the problem is discovered by chance, often several days later, when a transfer has already gone out or files are already encrypted. Business interruption, data loss, notification obligations, damaged trust: each of these consequences worsens with elapsed time.

There is a second, less visible cost: that of the decisions no one dares to make. Faced with an unusual payment request, refusing risks upsetting a client or a superior, accepting may mean carrying out a fraud. In the absence of a clear rule, most people choose not to make waves. Awareness training’s first purpose is to give them the right to say no, and a procedure to rely on when doing so.

Our attack cost simulator lets you estimate, using your own figures, what a few days of downtime would mean for your company. This is generally the calculation that convinces a hesitant management team best.

What does not work

Many companies feel they have already dealt with the topic. They have often done one of these four things.

The internal memo. An internal e-mail reminding everyone to “stay alert” informs, but trains no one. No one knows what “alert” actually means on a Tuesday morning in front of their inbox.

The charter signed and then forgotten. The document signed on hiring has real legal value, which we cover in our article on the IT charter. It has no educational value two years later.

The annual two-hour session. It ticks the box, it reassures, and its effect fades within a few weeks. Security is not knowledge to be acquired once, it is a reflex to be maintained.

Blaming. This is the most costly of the four. Humiliating the person who clicked, in a meeting or through a remark, sends a crystal-clear message to the whole team: next time, it is better to say nothing and hope it goes unnoticed.

The real risk is not the click, it is the silence that follows

An employee who reports their mistake within ten minutes gives you a chance to isolate the device, change passwords and block a transfer that is still pending. The same employee who does not dare say anything leaves you to discover the problem three days later. The mistake is identical, the damage is nothing alike. A company that punishes the click ends up only learning about incidents once they are irreversible.

What works

Effective awareness training rests on a few principles, all applicable without a special budget.

PrincipleIn practiceWhy it works
Short15 to 20 minutes, a single topicAttention and memory keep up
Regular3 to 4 times a year, rather than onceMaintains a reflex instead of knowledge
ConcreteYour real suppliers, your real processesGeneric content never applies to anyone
OpenQuestions welcome, mistakes discussedBrings doubts to light before the incident
SharedManagement and executives includedThey are the primary targets

Format matters less than frequency. A fifteen-minute point during a team meeting, based on a suspicious e-mail actually received the previous week, is worth more than a one-hour online module watched on fast-forward. To spread these sessions over a whole year, with one theme per period, see our ready-to-use awareness programme.

The priority topics are few: recognising a phishing attempt, verifying any change of bank details through an independent channel, never sharing an authentication code by phone, and knowing exactly who to alert in case of doubt.

This last point deserves a written answer known to everyone. One person, one number, available. An employee who does not know who to call does not call.

A free, French-language resource

The national S-U-P-E-R campaign, run by the Confederation and its partners, offers awareness materials designed for a non-technical audience, built around four simple rules: Sauvegarder (back up), Updater (update), Protéger (protect), Épier les recommandations (keep watch on the recommendations). The Federal SME portal usefully complements these materials. These documents are directly reusable in a team session, free of charge.

One last adjustment matters: tailoring examples to each person’s role. Accounting faces payment fraud, management is targeted because they approve, reception handles calls and visitors, meaning the manipulations described in our article on social engineering. Our public exposure tool also shows what an attacker can gather about your company without any particular effort.

How do you create a climate where reporting is valued?

This is the most important point in this article, and the least costly to implement.

Everyone will eventually click on something. Today’s attacks are polished, written in correct language, tailored to the company’s context. Assuming that a trained team will never be fooled is unrealistic.

The only variable you keep control over is the time between the click and the report. This delay depends on one thing: what the employee thinks will happen to them if they speak up.

In practice, this is built through three habits. Publicly thanking whoever reports something, even when the alert turns out to be unfounded. Never naming the person who made a mistake in front of the team. And recounting incidents as learning cases, without names, in the next awareness session.

A management team that admits it nearly missed an attempt itself does more for the company’s security than three training modules.

This climate is built, it cannot be decreed, and a few management reflexes are enough to destroy it unintentionally. We detail them in building a security culture without blame.

What internal awareness training cannot tell you

Everything above is within reach of an SME, without a significant budget, and produces real effects. It should be done, and doing it yourself is perfectly legitimate.

Two limitations remain, however.

You will not know whether it works. A team that is attentive in a session is not a team that will react correctly six months later, faced with a polished message on a Friday evening. Measuring real behaviour requires structured observation, and a perspective other than that of the person who ran the training. This is precisely what phishing simulations aim to achieve, provided they are run as a teaching tool and not as a trap.

You will not know what to teach as a priority. The scenarios that actually threaten you depend on your financial flows, your service providers, your access rights and your line of business. They appear in no generic material. Identifying them requires looking at your organisation as it actually is, not as a brochure describes it.

These measures form a solid foundation. They do not replace an analysis of your particular situation, nor a review by someone who knows where to look.

To gauge your starting point, the cyber check-up devotes several questions to team training and incident reporting. The other articles in the Training your teams pillar then detail how to build a programme and what to do once a mistake has been reported. If you would rather use ready-made material than produce everything yourself, we are preparing online training courses for French-speaking Swiss SMEs.