Skip to content

Training fades. A written first hour doesn't.

One annual course and a folder nobody's opened since is the usual shape of security awareness at a growing business. The fix isn't a bigger program. It's a shorter, recurring nudge for staff and a plain answer to who does what in the first hour of a bad day.

Book a scoping call

Four familiar reasons awareness fades.

  • Novelty

    A single course is memorable for about a month

    Annual security-awareness training is common, and its effect decays quickly—the same click-through rate creeps back up within weeks of the certificate being issued.

  • Attacks change

    The examples get old before the course does

    A phishing example from last year's training doesn't resemble this quarter's invoice-fraud attempt or a fake multi-factor prompt.

  • No feedback

    Nobody hears about the near miss

    An employee who almost clicked, then didn't, rarely tells anyone. The near miss teaches nothing beyond the one person who noticed.

  • Response assumed

    Everyone assumes someone else knows the first step

    Ask five people what to do the moment a suspicious sign-in alert or a ransom note appears, and expect five different answers.

Basics kept current, not a SOC.

Recurring awareness and a written first hour, not a security operations centre.

This isn't managed detection and response, a staffed monitoring desk, or a formal incident-response retainer with its own service commitments—Defender basics already draws that boundary for day-to-day protection, and it holds here too. What's missing underneath that boundary is smaller and more practical: a habit of short, current phishing nudges instead of one annual course, and a plain written answer to "what do we do in the first hour" that doesn't depend on the right person being in the office that day.

Neither piece needs a dedicated security program to be worth having. A short recurring nudge keeps one real, current example in front of staff. A first-hour outline assigns who isolates a device, who resets credentials, who decides whether customers or authorities need telling, and who's actually allowed to make that call—written down before the day it's needed, not during it.

Four steps, agreed in advance.

  1. Contain

    Contain first

    Isolate the affected device or disable the affected account before anything else. Speed matters more than certainty at this step.

  2. Confirm

    Confirm what actually happened

    Get a plain description from whoever noticed it first, before assumptions harden into the official story.

  3. Decide

    Decide who tells whom

    A named business decision-maker, not necessarily whoever's most technical, decides on customer, staff, or regulatory notification.

  4. Record

    Record it as you go

    Write down what was seen, what was done, and when. It's the same record a cyber-insurance claim or a privacy-breach assessment will ask for later.

Five things worth keeping current.

  • A current phishing example reaches staff at least once a quarter, not once a year
  • The first-hour outline has a named person in each role, not just a title
  • Contact details for anyone outside the building—insurer, legal counsel, a specialist responder—are current
  • The outline has actually been read by the people named in it, not only written once
  • A near miss or a real click gets a short debrief instead of silence

A confirmed compromise needs its own response and its own privacy assessment.

A confirmed compromise, a ransom demand, or a breach involving personal information needs a dedicated incident-response engagement and, in Canada, its own privacy-breach assessment against PIPEDA—both are separately scoped, not something a recurring awareness cadence absorbs.