One Tuesday morning, the bookkeeper at a small business near République gets an email signed by the owner: an urgent transfer of 8,400 € to a new supplier, confidential matter, don't mention it before the board signs off. The tone is pressing, the spelling is flawless, and the sender address looks almost identical to the real owner's — off by a single character. She hesitates, then calls the owner on his mobile instead of replying to the email. That thirty-second phone call stops a textbook CEO fraud attempt cold. No antivirus, no firewall would have caught that email: no infected attachment, no malicious link, just a well-told story and a manufactured sense of urgency. That's the real security gap I run into at most small businesses in Paris — not the network, the person sitting in front of the screen.

People are the entry point, not the hardware
On the small-business jobs I handle, almost every incident starts with a click, misplaced trust, or well-timed pressure — never some exotic technical flaw. A fake support call, a phishing email that mimics a bank, an invoice edited with a new account number: I already covered the exact mechanics of tech support scams in a separate article, so I won't repeat them here. What matters for this guide is that these scams work because they target ordinary human instincts — wanting to be helpful, not wanting to bother the boss, acting fast under pressure — not because the victim was careless or unqualified. Training a team isn't about teaching everyone IT. It's about giving them six simple habits they can pull out on autopilot, even on a tired Monday morning. For the more technical protections that sit alongside this — firewall, backups, updates — my article on protecting a business against cyberattacks covers that side of things.
The six habits worth drilling
Verify any payment change with a phone call
A new bank account number, changed payment details, an urgent invoice from a regular supplier: the one habit to drill is calling the person on a number you already have — never the one in the email — before approving anything. It takes two minutes and stops almost every CEO fraud or fake-supplier attempt cold.
Hover before you click
Hovering over a link without clicking shows the real destination at the bottom of the browser or mail client. A link that claims to lead to "microsoft.com" but actually points to a long address stuffed with hyphens is almost always phishing. It's a habit you can demonstrate in thirty seconds during a session, and it needs to become automatic after that.
Never share a verification code
A code sent by text or an authenticator app should never be read out to anyone, even someone claiming to be tech support or the bank. That code proves it's you logging in, not that the person on the phone is legitimate. Someone asking for it over the phone is usually the clearest red flag there is.
Report without fear of blame
This is the most overlooked habit, and the most valuable one. Someone who clicked a suspicious link needs to be able to say so within the minute, not hide it for three days out of fear of getting told off. The earlier the alert comes in, the smaller the damage — changing a password five minutes after a bad click is a completely different situation from finding out a week later.
Use a password manager
Reusing the same password across several work accounts is still the most common and most dangerous habit I run into. A password manager — built into Microsoft 365 or a dedicated tool like Bitwarden — generates a unique password per service and fills it in automatically. I usually set this up alongside a Microsoft 365 setup, so it doesn't get left behind.
Lock the screen when stepping away
Windows+L, or Ctrl+Cmd+Q on a Mac, every single time someone steps away, even for a two-minute coffee run. In an open-plan office or a reception area with visitors, an unlocked computer is an open door — no sophisticated hacking needed if anyone can sit down and start going through the inbox.
Running a 45-minute session yourself — the concrete agenda
You don't need a consultant in a suit or an e-learning platform costing several thousand euros a year to get started. Here's the agenda I use when I run a session for a client, or recommend to an owner who'd rather do it themselves. The first five minutes are for a real, recent example — a local news story, or an anonymized case from the business itself or a similar client — because that grabs attention far better than a slide full of statistics. Next comes a live demo, about fifteen minutes, on a real phishing email that's been defused, projected on screen: hover over the link, look at the header, spot the fake urgency. The six habits come next, one by one, over roughly fifteen minutes, each illustrated with an example drawn from the business's actual work rather than a generic case pulled off the internet. The following five minutes are for a short exercise: two or three emails, real or made up for the occasion, that the team sorts together into "safe" or "suspicious." The last five minutes are for questions and signing the one-page charter. Do it standing up, in the break room or around a table, not in a lecture hall; it works best with eight people at most, and past that I'd rather split into two groups to keep the discussion alive.

The simulated phishing test — done properly
Sending a fake trap email to the whole team to see who clicks is tempting, and it does work for measuring how well the session actually landed. But done carelessly, the exercise turns into surveillance and breaks the trust the training was meant to build in the first place. Three rules I stick to: the owner or manager is informed beforehand, never the staff themselves, or the test proves nothing; results stay anonymous or limited to management, never posted with names attached; and nobody gets punished for clicking. Whoever clicks gets an immediate, friendly message explaining what they just saw and how to spot it next time — two minutes, not a disciplinary write-up. Technically, a free tool like GoPhish is plenty for a small business. And if a genuine trap link slips through one day and someone really does click, my article on what to do with a hacked account covers the first-hour steps.
Onboarding a new employee from day one
A new hire is statistically the most exposed person on the team: they don't know the company's habits yet, they want to make a good impression, and they have no baseline for spotting what looks off. The six habits need to be covered on their very first day, not at the next quarterly meeting three months later. I recommend setting up their account with a unique password generated by the password manager — never a quick "Welcome2026" typed on the spot — having them sign the charter before they touch their inbox, and giving them the name and direct number of whoever to call when in doubt, not a generic address buried in an org chart.

The one-page internal charter — what to put in it
A ten-page security policy ends up in a drawer, unread. A single page, on the other hand, can be reread in three minutes and pinned up near a workstation. It should fit that format and cover: the six habits summarized in one line each, the name and direct number of who to call when in doubt, a requirement to use the provided password manager, a ban on sharing verification codes over the phone, the screen-lock rule, and a clear line stating that reporting a mistake will never be punished. I often draft it with the owner during a Microsoft 365 setup or a maintenance plan rollout, since it only takes about twenty minutes once the habits are already explained.
How often to repeat it
One long session a year gets forgotten within three months. I prefer a short refresher — ten or fifteen minutes — every quarter, plus an immediate reminder whenever a wave of scams hits the business's sector or makes local news. A new employee gets the full session on arrival, without waiting for the next scheduled group refresher. That lighter cadence costs far less, in both time and money, than one big annual session nobody remembers by spring.
Realistic pricing if a technician runs the session
For a Paris small business that would rather outsource it, an on-site 45-minute session for a team of up to eight people runs around 180 to 250 €, including demo material and the one-page charter. Adding a simulated phishing test costs another 100 to 150 € depending on how many accounts are targeted. For a business on a regular IT maintenance plan, I'm happy to fold a short quarterly refresher into the package rather than billing it separately each time — it's also a service I offer outside any contract, as a one-off engagement (French page: prestations freelance). If you'd rather run it yourself using the agenda above, it costs nothing beyond your team's 45 minutes — often the best option for a very small business of two or three people.
Frequently asked questions
Do I need a formal training budget to train my staff on IT security?
No. A 45-minute session run in-house or by a technician, plus a one-page charter, is enough for most small businesses. You don't need an e-learning platform or a formal training budget to get started.
Is a simulated phishing test legal in France?
Yes, as long as the owner or manager is informed and the test is used for coaching, not punishment. Results should stay anonymous or limited to management, and for a company with staff representatives, it's safer to inform them too. The goal is always to teach, never to trap someone into being blamed.
How long should an effective session last?
Forty-five minutes works best in my experience: long enough to cover all six habits with real examples, short enough that attention holds until the end. Past ninety minutes, the key points get lost.
What should I do if an employee clicks a scam link anyway?
No panic and no blame: have them report it immediately, change the affected password from a clean device, and check active sessions. My article on what to do with a hacked account covers the first-hour checklist in detail.