← Back to all posts

Phishing Training for Small Businesses: What Actually Works

Small businesses need phishing training because every employee is the last filter between an attacker and the company's money, and there is no security team behind them to catch a mistake. But the usual approach, one compliance video a year, barely changes behavior. What works better is short, frequent practice on realistic messages with immediate feedback, backed by technical controls like MFA. That is why we built a free phishing assessment and an arcade game anyone can play, with no account required.

Take the free phishing assessment

Why phishing hits small businesses hardest

Large companies have layers: a security operations team, a help desk that notices odd password resets, and a finance department with dual approval on wire transfers. A ten-person business usually has none of those. When an employee approves a fake invoice or types a password into a lookalike sign-in page, there is often nobody positioned to catch it before the money moves.

The money involved is real. Business email compromise, where attackers impersonate a vendor or executive to redirect payments, accounted for about $3 billion in reported US losses in 2025 according to the FBI's Internet Crime Complaint Center, second only to investment fraud (IC3 annual reports). Those are only the reported losses. A single redirected payment can be a serious event for a small company, and it often arrives as an ordinary-looking email about a changed bank account or an overdue invoice.

There is also a paperwork reason. Cyber insurance applications and customer security questionnaires routinely ask whether you train employees on phishing, and the NIST Cybersecurity Framework includes awareness and training as part of its Protect function. Our guide to NIST CSF 2.0 for small businesses covers where it fits.

The uncomfortable research: most training doesn't work

The best recent evidence is not flattering to the training industry. In an eight-month randomized experiment covering more than 19,500 employees at UC San Diego Health, researchers found "no significant relationship" between recently completing annual, mandated cybersecurity training and falling for phishing emails. Embedded training, the page shown after someone clicks a simulated phish, "only reduced the likelihood of clicking on a phishing link by 2%," and 75% of users spent a minute or less on it (UC San Diego).

That doesn't mean training is pointless. It means the common formats are: a long video once a year, or a lecture page that appears right after someone has been caught out and wants to close it. The researchers' own recommendation is telling: technical controls such as two-factor authentication and password managers that only fill in credentials on the correct domain "would have better return on investment."

What works better

Training is one layer, not the control. With that framing, here is what we think a small business should aim for:

  1. Short and frequent beats long and annual. Five minutes a quarter keeps the habits fresh. An hour once a year is forgotten by spring.
  2. Feedback the moment a decision is made. Learning happens when someone sees exactly what they missed, in the message itself, right after they missed it.
  3. Practice on safe mail too. If every training message is a phish, people learn to distrust everything, which is its own business problem. Telling a real vendor receipt from a fake one is half the skill.
  4. Specific tells, not general warnings. "Be careful" doesn't help. "Hover the link and read the real destination," "check whether the domain has a capital I where the l should be," and "verify any bank-detail change by phone using a number you already have" do.
  5. Fresh messages on every retake. If the same ten emails come back each time, the second attempt is a memory test.
  6. A no-blame way to report. Someone who clicks and says so in five minutes is far more useful than someone who clicks and stays quiet. Our guide on what to do if you clicked a phishing link is a good thing to share with the team in advance.
  7. Technical controls underneath it all. Enforce MFA, use a password manager, and filter mail before it reaches people. Training reduces the mistakes that get through; it does not replace the controls that stop most of them.

Try it free: Inbox Defense

Inbox Defense is a free phishing assessment that runs in your browser. You run Harborline Logistics, a fictional company, and handle 10 emails, deciding Safe or Phishing for each one. It takes about five minutes, and there is no account to create. The Phishing Training page covers scoring, categories, and team recording in detail.

  • Realistic messages, nothing live. Hover a link (or long-press on a phone) to see its real destination, as you would in a mail client. Links and attachments never open, download, or load anything.
  • A mix of difficulty. Each run draws routine, tricky, and advanced messages from a larger pool, including lookalike domains, fake invoices and bank-detail changes, executive impersonation, QR-code lures, malicious attachments, and MFA-fatigue prompts, alongside legitimate mail that looks similar.
  • Instant feedback. After each decision you see whether you were right and the one detail that gave the message away.
  • A real debrief. At the end you get a score (80% passes), accuracy by category, and every message with its tells highlighted in place.
  • Mistakes cost money in both directions. Missing an advanced phish costs the company a breach. Flagging a legitimate message as phishing also costs a little, because blocking real customers and vendors is a mistake too.

Play Inbox Defense

Then play the arcade

Finish a training run and the arcade opens up. It's the same skill under pressure: mail arrives continuously, every correct call earns money, and you spend it on tools that mirror real Blue Lantern Security checks. Those include a sender domain check, a link inspector, a header reveal for SPF, DKIM, and DMARC, and an attachment scanner. You can hire analysts to help, but each one brings in more mail. The game ends when you can afford to deploy AI, and you can probably guess how that email reads.

A typical game takes 9 to 12 minutes, and your best time is saved in your browser. It's free, and you can send anyone straight to it.

Jump straight to the arcade

Recording results for your team

Playing is free for everyone. Recording results per employee requires a Seat License, and it turns the game into training evidence you can show an insurer or customer:

  • Personal links. From the Monitoring Hub, an admin generates a personal training link for each member of the organization. Results are attributed to that member without them signing in.
  • The employee chooses what to save. Each finished run offers "Record your results," and only runs the employee saves are recorded. Grading happens on our servers, not in the browser.
  • A Training view in the Monitoring Hub. Admins see each member's latest result, completion date, number of attempts, and per-category results.
  • Security Attestation Report. The report includes a Security Awareness Training section: how many active members have passed in the last 12 months, who attempted but scored below the pass mark, and who hasn't started.

A simple program for a small team: everyone completes a run when they join, everyone retakes it each quarter (each run draws new messages), and anyone who scores below 80% retakes it until they pass.

Frequently asked questions

Is phishing training required for small businesses? There is usually no law requiring it, but cyber insurers, enterprise customers, and frameworks like NIST CSF and SOC 2 commonly expect it. If you're asked, you need records showing who completed training and when.

Does phishing training actually reduce clicks? The traditional formats barely do, according to the UC San Diego study above. Short, frequent practice with immediate feedback is a better bet, and it works best alongside MFA, a password manager, and email filtering rather than instead of them.

How often should employees do phishing training? Quarterly is a reasonable rhythm for a small business: frequent enough to keep habits current, light enough that nobody resents it. Add a run after any real phishing attempt that reaches the team.

Is Inbox Defense really free? Yes. The assessment and the arcade are free to play with no account. Saving results to a team's record requires a Seat License.

What if someone spots a suspicious email at work? Don't click to check. Forward it to whoever handles IT, or analyze the original message with our free email analyzer. Our guide to reading an email analysis report explains the results.