A small IT team can run security awareness training by drawing one line: the decisions stay with a person, and everything that repeats on a schedule belongs to a platform. Your side is the one-time setup, a monthly read of the trend, and the exceptions. Hoxhunt does that scheduled work, so simulations and training keep reaching people in the weeks nobody has time to send them.
You’re the security team. You’re also the IT team, and three other teams, and this sits wedged between tickets, projects, and whatever broke this morning. Nobody at your headcount gets a dedicated security awareness hire, so the real question is who runs the program on a Tuesday.
Running a better program should not mean adding another standing job to your week, and at your size it does not have to. What follows is what running one actually involves, month by month: which parts a platform can take, which parts have to stay with you, and what the results look like at companies about as big as yours.
There is one distinction worth making before we get to how much work a security awareness program takes to run: training and phishing simulations are not the same thing, though the words get used interchangeably.
- Security awareness training is the content people complete: courses and short modules on the behaviors you want.
- Phishing simulations are safe fake emails sent to real inboxes to see what people actually do with them.
Most programs run both, and that is where the recurring work described on this page comes from.

What does owning the program actually involve?
Whoever owns IT makes the decisions and handles the exceptions. The first decision is how to divide employees into groups, because attackers hit a finance team and a warehouse team with different attacks, so the same simulations and the same training should not go to both. After that come the judgment calls: what to do with an employee who keeps clicking, and when a reluctant department needs a conversation instead of another simulation.
Everything that repeats on a schedule is a different kind of work, and that is the part a platform can take over. Where no platform runs it, the repeating work lands back on the IT owner’s desk.
That is where most small programs stall, and not because anyone stopped caring. Building next month’s campaign competes with the ticket queue, the migration that is already late, and whichever system is down today. It is also the only item on that list that nobody will chase you about, so it is the one that slips.
How much work is a security awareness program if you run it by hand?
It is enough work that most programs quietly shrink to fit the time available. No single task here is difficult. The problem is that all of them come back, and they come back whether or not this was the week the file server died.
Five jobs make up the delivery of a program, meaning everything that has to happen for the training and the simulations to actually reach people. They come back every round, for as long as the program runs.
- Build the next round. Pick or write the simulated phishing email, choose which training goes out with it, decide who receives each, and schedule both.
- Cut the cohorts. Decide which groups exist, then reconcile them against everyone who joined, left, or changed team since the last round.
- Chase completion. Send reminders to everyone who has not finished their training, then chase the people who ignored the reminders.
- Track and record. Pull the numbers, and keep the evidence of who was tested and who completed which training, in a form somebody else could audit.
- Handle the exceptions. Have the conversation with the repeat clickers, and with the manager who does not want their team tested.
None of those five is the security work you actually want your judgment going into, and none of them is optional either. That combination is what makes the load persistent.
So the program shrinks to the hours available. One person running this by hand sustains roughly one campaign a quarter, which comes to four exposures a year for each employee. Four moments spread across 12 months is not enough repetition to change how anyone behaves, and that gap is a capacity problem rather than a commitment problem.
This counts delivery only. Reading the trend, and the judgment calls further down, stay with you either way. Ordermark’s figure comes from its case study, and so does the manual cadence: one campaign a quarter is what Bird & Bird, a law firm covered further down, built by hand before automating.
How much work is a security awareness program once a platform runs the delivery?
You set the program up once, and after that the work that comes back is a review of what the dashboard already shows: failure rate, report rate, and how quickly people report. The platform builds each round, sorts the groups, sends the reminders, and keeps the records, without waiting for you to start it. You handle the exceptions, which is the only part of that list that was ever worth your judgment.
Here is what the same program asks of you when delivery is automated.
- Scope it once. Get your people into the platform, choose the languages, and roll out the button employees press to flag a suspicious email. You do this a single time, instead of standing up a fresh project every quarter.
- Let difficulty find each person. Define your groups once, then let the platform score each employee’s skill level and pitch the simulations to match. The monthly cohort re-cut disappears.
- Read the trend, monthly. Check failure rate, report rate, and time to report. The default dashboard panels already show all three.
- Handle only the exceptions. Deal with the repeat clickers and the occasional reluctant team. Your judgment goes here, where an hour of it actually pays.
Those four steps are what the month asks of you. If you want the how-to for each stage, from planning and content through tracking people’s progress, our guide to an automated security awareness program covers the build.
The cadence that follows is the real gain. Instead of one large campaign a quarter, employees get short simulations spread across the year, each one costing them a few seconds of attention in an inbox they were already reading. Frequency goes up while the demand on any one person’s day goes down, including yours.
Publishing Factory is an IT services company in Lausanne with about 240 employees, and the Managing Director runs the program together with a technical project manager, so nobody there does security awareness full time either. Asked what stood out about running it, the Managing Director described the same split.
“My favorite part is that training is automatic. It is very low maintenance. I get involved only when someone is reluctant: to change their mind.”
Pierre Guiol, Managing Director, Publishing Factory case study
Bird & Bird, an international law firm of around 3,300 staff, built one phishing campaign per quarter by hand. After automating, its program delivered 36 simulations a year, which is one roughly every 10 days instead of one every three months.
That jump did not come from anyone working harder. It came from the campaigns no longer waiting for a person to build and launch them. The Bird & Bird case study has the full before and after.
What can you hand to a platform, and what has to stay with you?
Delivery belongs to the platform and judgment belongs to you, and that is the division to test in a demo. Go through it line by line, and for each job on the list ask one question: does the platform do this on a schedule, or does somebody have to start it?
| Handed to the platform | Stays with you |
|---|---|
| Choosing each simulation from current threat data | Deciding which groups exist and who belongs in them |
| Setting difficulty per employee from their measured skill level | Judging when a reluctant team needs a conversation instead of another simulation |
| Delivering simulations, reminders, and completion tracking across the whole staff | Reading failure rate, report rate, and time to report once a month |
| Assigning follow-up training the moment someone clicks or reports | Deciding what to do with repeat clickers who need more than training |
| Producing the coverage and behavior record as the program runs | Explaining to leadership what the trend means |
Sources for everything under “handed to the platform”: per-person difficulty and in-the-moment micro-training are described on the Hoxhunt phishing training page. Automated delivery across an entire staff is what Publishing Factory runs.
Treat everything under “handed to the platform” as a buying test rather than a feature list. Every job on it comes back whether or not anyone has time for it, so buying the execution is what keeps a security owner working on risk. A platform that assumes a full-time owner is built for a different company than yours.
Bottom line: In a demo, don’t evaluate the feature list. Evaluate which of the jobs that come back every month the platform takes off your plate. And check whether it is still taking them off nine months in, once onboarding is over.
Generating the simulations is where small programs rot.
A fixed template library is itself a maintenance job. Somebody has to keep it current with what attackers are actually sending, nobody on a stretched team ever gets to it, and the same handful of fake invoices circulates until people recognize them on sight. That gets worse as attackers use generative tools to write cleaner and better-targeted lures, which dates a static library faster than it used to.
Hoxhunt picks each simulation from current threat data, and sets the difficulty of each one from the individual’s measured skill level. Nobody on your side maintains the library. Freshness stops being a task on your list and becomes a property of the product.
That matters because a simulation people recognize stops testing anything: they learn the pattern of your fake emails rather than the shape of a real attack, while your numbers keep looking fine.
What changes in the numbers when a platform runs the program?
Coverage and reporting both rise, and they stop depending on whether you had a free week.
At Publishing Factory the program still reaches every member of staff, on what the case study calls complete automation of the phishing training program.
Ordermark jumped from 60 employees to over 300 in under a year, so its program had to absorb constant onboarding rather than a settled headcount. Almost six months in, its fail rate had gone from about 18% to 5%, with engagement holding at 80%. The simulations were getting harder over that period.
What moves the numbers is frequency, and frequency is the one thing a busy owner cannot guarantee by hand. Bird & Bird’s resilience ratio, which measures reporting against failure, rose from 5.3 to 37.8 after that same shift from one manual campaign a quarter to 36 automated simulations a year. Behavior change happens through repetition, and repetition is exactly what stops in a quarter where everything else is on fire.
For the design detail underneath these numbers, our guide on how to run a phishing training program covers what makes the training itself effective.
What proof does security awareness training give you for leadership and auditors?
The same numbers answer both leadership and auditors, and the program produces them as it runs, so the evidence is already there when you need to export it.
For leadership: is this getting better or worse?
Leadership wants a direction, not a document. Show them your failure rate and your report rate, tracked month over month: one line should be going down and the other up.
For auditors: did people actually get trained?
An auditor wants evidence against a specific control. ISO/IEC 27001:2022 control A.6.3 requires that personnel receive awareness, education, and training, and that they get regular updates on the policies relevant to their role.
So the auditor is really asking two things: proof that the coverage was real, and proof that people took part. Publishing Factory answers both: 100% of its staff were trained and tested, and 93.5% of them took part.
If you want an outside reference for what a managed program looks like, NIST SP 800-50 Rev. 1 (September 2024) is free, and it says its approach is intended to address the needs of large and small organizations alike. It is written for federal agencies, so it guides you rather than binding you.
Both of those answers come out of running the program properly. A program built only to satisfy an audit produces the document and nothing else. A program built to change behavior produces the same document plus a trend line that survives the follow-up question.
What has to be true in your company for a continuous security awareness program to work?
Three things have to be true, and none of them is company size.
- Somebody reads the dashboard once a month. The reason it cannot be nobody’s job is that a platform can flag the person who keeps clicking but it cannot go and have a conversation with them, or notice that a whole team has quietly opted out. Those are the cases that turn into a real incident, and they are the only ones that need a human.
- The organization commits past the first quarter. Behavior curves form through repetition over time, so a program canceled at week 10 has been paid for but never given long enough to show a result. That commitment is far easier to keep when the training is something people do not resent: short, built around threats in circulation now, and pitched at each person’s level.
- The actual goal has to be fewer successful attacks. In practice that means fewer people handing over a password to a real phishing email, and moving that number takes months of repetition. If nobody in the business actually wants that number to move, the program gets judged on completion rates instead, and a completion rate does not protect anyone from a real attack.
Headcount is not on that list, budget is not on it, and neither is having somebody with security in their job title. What decides this is whether one person can own the monthly review, and whether the business will let the program run long enough to work.
Which makes compliance on its own the weakest reason to buy. Hoxhunt ships audit-ready training with regulatory tracks for PCI DSS, HIPAA, GDPR, and the EU’s Digital Operational Resilience Act, and the record builds itself as the program runs, so getting it out is an export rather than a project.
But the record is the easy part. If nobody in the business wants fewer clicks and faster reporting, the record alone will not justify the line item.
So how can a small IT team run security awareness training?
On one condition: the recurring delivery has to belong to the platform, and the decisions have to belong to a person.
A small IT team that owns both ends up running an annual program, because an annual program is what fits in the hours left over. A small IT team that owns only the decisions can run a continuous one at the same headcount. Publishing Factory does that with nobody on it full time, and Ordermark did it through a year of constant hiring.
If you have not built a shortlist yet, start there. Our security awareness training comparison ranks the field, KnowBe4 alternatives covers the case for replacing an incumbent, and the reviews page gathers what customers said on Gartner, G2, and Capterra.
Frequently asked questions
Who should own security awareness training when nobody’s job title says “security”?
Whoever owns IT should own the program, with a named executive sponsor above them. ISO/IEC 27001:2022 clause 5.3, on organizational roles, responsibilities and authorities, requires top management to assign responsibility for information security roles and to communicate who holds them, without saying who the owner should be. A program nobody is named on is the program that goes quiet during the first busy quarter. The sponsor matters in two moments: when a department head pushes back, and when reminders stop working on someone.
How much of my time does a security awareness program take each month?
That depends on whether a platform runs the delivery, and the gap is large. Run by hand, building each round, sorting the groups, chasing completion, and keeping the records all land on one person, and about one campaign a quarter is what that person can sustain. With delivery automated, what stays fixed is one look at the dashboard, plus the exceptions: the people who keep clicking and the occasional team that pushes back.
Is a continuous security awareness program overkill for a company our size?
A continuous program is not overkill at 200 to 500 employees, provided it does not need a full-time owner to run. Needing a full-time owner is what makes a platform wrong for a small IT team, and that has nothing to do with employee count. Publishing Factory covers 100% of about 240 staff on a fully automated program.
What do we have to set up before a continuous security awareness program can run?
There are three tasks, and each of them happens once: get your people into the platform so it knows who works there, choose the languages you need, and roll out the button employees press to flag a suspicious email. After that, simulations and training go out on a schedule without anyone starting them.
We already run annual compliance training. Do we have to replace it?
A continuous program replaces the way training reaches people and changes nothing about what you owe. The obligation stays, the completion record stays, and the difference is that content arrives in small pieces across the year instead of one annual session, with a behavior trend attached to the record. Running both is the version to avoid, because staff then sit through the annual session as well, and that session is the half that does not change how anyone behaves.
How long before phishing failure and reporting rates start to move?
Phishing failure and reporting rates move over months rather than weeks. Ordermark was almost six months in when its phishing failure rate had gone from about 18% to 5%, and six months is worth treating as an order of magnitude rather than a promise. How fast the curve moves depends on how often people meet a realistic phishing attempt.
What happens when somebody keeps clicking on phishing simulations?
With a platform running the program, the platform assigns follow-up training automatically every time that person clicks, so the early failures need nothing from you. The ones worth your attention are the people it keeps happening to, because more training is rarely what they are missing. What they need is a conversation, or a change to what they can access, and that is one of the few parts of a program that has to stay with a person.
- Subscribe to All Things Human Risk to get a monthly round up of our latest content
- Request a demo for a customized walkthrough of Hoxhunt


.avif)
.avif)