Blog

Beyond Basic IT: What Architecture & Engineering Firms Really Need

Architecture and engineering firms ask a lot more of their technology than the average office. 
Large Revit models, CAD files, rendering software, plotters, high-performance workstations, and years of project data all have to work together. Add contractors, consultants, and clients who need access to project information, and even a relatively small firm can have a fairly complex IT environment. 
That means the technology supporting an A&E firm needs to be built around how the firm actually works — not around a standard office setup. 
Here are some of the areas that matter most. 
For an A&E firm, project files aren’t just documents sitting on a server. They’re active work product, project history, and often the result of hundreds or thousands of hours of work. 
Losing access to a model or drawing set can delay a project quickly. Even losing a few hours of recent work can create a significant headache when a deadline is approaching. 
That means determining how much recent work the firm can reasonably afford to lose, protecting the systems and project data that matter most, and keeping backup copies separate from the primary environment. 
It also means testing restores. 
A backup can report that it completed successfully every night, but that doesn’t necessarily tell you whether the data can be recovered when you actually need it. Regular restore testing helps make sure the recovery plan works before there’s an emergency. 
A computer used primarily for email and Microsoft Office has very different requirements from one running Revit, AutoCAD, Civil 3D, or rendering software all day. 
Memory, graphics capability, processors, storage, and even the way the workstation is configured can affect how well those applications perform. 
And simply buying the most expensive workstation isn’t necessarily the answer. 
Hardware should match the applications, project sizes, and workloads your team actually uses. It also needs to be maintained with those applications in mind. 
The same goes for support. If an administrative computer is having a minor issue, that’s inconvenient. If a project team’s workstation can’t open a model the day a drawing set is due, that’s a production problem. 
IT support should understand the difference. 
A&E firms also deal with something many other businesses don’t: different clients, consultants, and projects may require different versions of the same software. 
One project might still be in an older version of Revit while a new project starts in the latest release. A consultant may be using a different AutoCAD version. Certain plugins or add-ons may only work with specific releases. 
Updating everything at once isn’t always practical — and doing so without planning can create compatibility problems. 
IT needs to understand which versions are required, how updates affect active projects, and when upgrades can happen without disrupting production. 
That also means keeping track of licensing, plugins, workstation requirements, and dependencies instead of treating every software update like a routine “click install” situation. 
In a typical office, a printer problem is annoying. 
In an architecture or engineering firm, a plotter problem can hold up a deliverable. 
Plotters, scanners, conference-room technology, specialized peripherals, and other production equipment should be treated as part of the firm’s overall technology environment. 
That includes maintaining the network connections, drivers, permissions, and configurations those devices rely on. 
It’s easy to overlook this equipment when thinking about IT, right up until something stops working when the team needs it. 
Architecture and engineering projects involve a lot of people who don’t work for your firm. 
Contractors, structural engineers, MEP consultants, owners, and other partners may all need to exchange files or review project information. 
Business cloud services can make that much easier, but they also need to be configured properly. 
External users shouldn’t have access to more information than they need. Old project links shouldn’t remain open indefinitely. Employees shouldn’t have to fall back on personal accounts or improvised file-sharing methods because the approved process is too difficult to use. 
The goal is straightforward: make collaboration easy enough that people actually use the right tools while keeping access controlled and visible. 
Security matters, but so does usability. 
If security controls make everyday project work unnecessarily difficult, people tend to find ways around them. On the other hand, leaving everything wide open creates obvious risk. 
A practical cybersecurity plan should protect accounts, devices, project data, and backups without turning routine work into an obstacle course. 
That can include multi-factor authentication, endpoint protection, access controls, patching, secure backups, and monitoring for unusual activity. 
Monitoring can also help identify problems such as failing hardware or suspicious activity before they become larger disruptions. 
It’s worth understanding exactly what your IT provider means by monitoring, though. 24/7 system monitoring isn’t necessarily the same thing as having someone sitting at a help desk 24 hours a day. Firms should know how monitoring, support hours, and after-hours escalation actually work. 
Technology decisions shouldn’t only happen when something breaks. 
If you’re hiring more designers, opening another office, taking on larger projects, changing design software, moving more work into the cloud, or replacing aging workstations, those decisions affect the rest of the IT environment. 
Planning ahead gives the firm time to budget and make changes deliberately instead of discovering limitations in the middle of a project. 
InfiNet’s vCIO & IT Strategy approach connects those technology decisions to the firm’s broader plans. That can include workstation replacement cycles, storage capacity, software requirements, cybersecurity, backup and recovery, and future infrastructure needs. 
An IT provider doesn’t need to be an architect or engineer. 
But they should understand the environment they’re supporting. 
They should know why Revit performance matters, why different software versions may need to coexist, why a plotter can be production-critical, and why recovering yesterday’s project files isn’t always good enough. 
More importantly, they should be able to talk about technology in terms that matter to the firm: downtime, project schedules, productivity, risk, and client commitments. 
Because ultimately, that’s the job of IT in an A&E firm. 
A&E firms typically need support that understands CAD and BIM applications, high-performance workstations, plotters, project-file storage and backup, cybersecurity, and collaboration with outside contractors and consultants. IT should be designed around the firm’s production environment rather than a standard office setup. 
Applications such as Revit, AutoCAD, Civil 3D, and rendering software can require considerably more processing power, memory, graphics capability, and storage than typical office applications. Workstations should be selected based on the software and workloads each employee actually uses. 
Active projects, clients, consultants, plugins, or project requirements may depend on specific software versions. Upgrading too early can create compatibility problems, so firms may need to maintain multiple versions and plan upgrades around active projects. 
Backups should run often enough to reflect how much recent work the firm can reasonably afford to recreate. Important data should have protected copies separate from the primary environment, and restores should be tested regularly to confirm that files and systems can actually be recovered. 
Yes, when it’s configured appropriately for business use. Access should be limited to the people who need it, external users should be authenticated where appropriate, and sharing permissions should be reviewed as projects and teams change. 
Start with issues that could stop production or put project and client data at risk: failed or untested backups, aging hardware, account security, overly broad access, software compatibility problems, and inadequate protection of endpoints and project data. 
If your technology is becoming something your team has to work around instead of something that helps them work, it may be time to take a closer look.
Learn more about InfiNet’s Architecture & Engineering IT Support. 

Beyond Basic IT: What Architecture & Engineering Firms Really Need Read More »

The Omaha Business Cybersecurity Checklist (No IT Degree Required)

You don’t need to understand every cybersecurity tool your business uses. But there are a few questions you should be able to get a clear answer to. 
Is MFA turned on? Are your backups working? Are computers getting updated? Does your team know what to do with a suspicious email? And if something unusual happens, who is actually paying attention? 
If the answer to some of those is “I’m not sure,” that’s a good place to start. 
Here’s a straightforward cybersecurity checklist for businesses in Omaha, Lincoln, Council Bluffs, and the surrounding area.
Check: Can employees access email, financial systems, or other important business applications with only a password? 
If they can, turn on multi-factor authentication (MFA). 
MFA requires another form of verification in addition to a password. That means a stolen password alone usually isn’t enough to get someone into an account. 
At minimum, look at: 
• Microsoft 365 or Google Workspace 
• Accounting and financial applications  
• Remote access and VPN accounts 
• Administrative accounts 
• Other systems containing sensitive business or customer information
 Where available, consider stronger options such as passkeys or security keys. 
Software updates aren’t just about getting new features. They frequently fix known security problems. 
The important question isn’t whether employees occasionally click Update. It’s whether your business has a consistent process for keeping devices and applications current. 
• Operating systems receive security updates 
• Business applications are kept current 
• Browsers are updated 
• Network equipment and other business technology receive appropriate updates 
• Someone is responsible for identifying devices that fall behind 
If updates depend entirely on employees remembering to install them, there’s room for improvement.
Most businesses will confidently say they have backups.
The better question is: When was the last time you tested one?
A backup is useful only if you can recover what you need from it.
• Important business data is backed up
• Backups run automatically
• Backup failures are reviewed 
• Restore tests are performed periodically 
• You know how long recovery would realistically take 
If nobody can remember the last successful restore test, put this one near the top of your list.
You don’t need an elaborate 20-page password policy. You do need some basic rules that everyone follows. 
• Employees use unique passwords for work accounts 
• Passwords aren’t shared through email, Teams, or sticky notes 
• A business-approved password manager is available 
• A business-approved password manager is available 
• Shared or administrative credentials are controlled 
• MFA is used wherever possible
The policy only matters if it reflects what people actually do.
Email remains one of the easiest ways to get in front of an employee. 
Fake invoices, password-reset notices, Microsoft 365 login pages, messages that appear to come from an executive, and requests to change payment information can all look convincing. 
Your email system should have tools in place to identify and filter suspicious messages before employees ever see them. 
But filtering isn’t perfect—which brings us to the people using it.
Security awareness training doesn’t need to mean sitting through the same hour-long presentation every year. 
Short, practical training throughout the year is generally more useful. 
Employees should know:
• How to recognize common phishing attempts
• Where to report a suspicious message 
• What to do if they accidentally click something 
• Not to approve an unexpected MFA request 
• How to verify unusual requests involving money or sensitive information
That last one is especially important. 
If someone receives an email asking them to change banking information, send a wire, buy gift cards, or provide sensitive employee information, verify the request another way. Call a known number or speak to the person directly rather than using the contact information provided in the message. 
Mistakes happen. What matters next is how quickly your business knows about them. 
Employees should know exactly who to contact if they:
• Click a suspicious link 
• Enter a password on a questionable website 
• Approve an MFA request they didn’t initiate 
• Open a suspicious attachment 
• Notice unusual activity on their computer or account 
You want people reporting those situations immediately—not spending an hour worrying that they’ll get in trouble.
Security tools can generate warnings about things like unusual logins, failed backups, missing updates, or systems that suddenly stop checking in. 
But an alert doesn’t accomplish much if nobody reviews it. 
Ask:
• Who reviews security alerts? 
• Who checks backup failures? 
• Who identifies computers missing important updates? 
• Who investigates unusual login activity? 
• Who is responsible for responding when something needs attention? 
You don’t necessarily need someone staring at a dashboard around the clock. You do need tools watching for problems and a clear process for deciding what happens when they find one. 
If you don’t want to go through the entire list today, start here. 
Ask whoever handles your IT these five questions: 
1. Is MFA required for everyone’s email? 
2. When did we last successfully restore something from backup? 
3. Are all of our computers current on security updates? 
4. What should an employee do immediately after clicking a suspicious link? 
5. Who reviews our security alerts? 
You’re looking for specific answers. 
“We should be.” 
“I think so.” 
“Probably.” 
“Someone gets those alerts.” 
Those aren’t really answers. 
Not every business needs an internal cybersecurity department. But somebody needs to own these responsibilities. 
If you went through this checklist and found several questions you couldn’t answer, that doesn’t automatically mean your business has a major security problem. It means you’ve identified what needs to be checked. 
Start there. 
InfiNet works with businesses throughout Omaha, Bellevue, Council Bluffs, Papillion, Lincoln, and surrounding communities to understand what protections are already in place, identify gaps, and prioritize what actually needs attention. 
You don’t need to become a cybersecurity expert. You just need to know the right questions to ask. 
What is the most important cybersecurity step for a business owner to take right now? 
Start by making sure MFA is required for email and other important business accounts. A password by itself shouldn’t be enough to access sensitive systems. Where available, consider phishing-resistant methods such as passkeys or security keys. 
Do I need an IT background to understand my company’s cybersecurity risk? 
No. You don’t need to understand how every security tool works. You should, however, be able to get clear answers about MFA, backups, updates, employee training, monitoring, and who is responsible for each. 
How often should employees receive security awareness training? 
Security awareness works best as an ongoing practice rather than a once-a-year event. Include it during onboarding, reinforce important habits throughout the year, and provide additional guidance when threats or business processes change. 
How do I know whether our backups are good? 
Test them. A successful backup notification tells you the backup process ran; a successful restore tells you that you can actually recover your data. Periodic restore testing is an important part of a reliable backup strategy. 
What does proactive monitoring mean? 
It means using tools to watch for conditions that may need attention, such as unusual logins, failed backups, missing security updates, or security tools that stop reporting. Just as importantly, someone needs to be responsible for reviewing and responding to those alerts. 
When has a business outgrown informal IT support? 
One warning sign is when important questions consistently get uncertain answers. If nobody can confirm whether backups work, updates are current, security alerts are being reviewed, or former employees have lost access, your business probably needs a more defined IT process. 
Do small businesses really need cybersecurity? 
Yes. Phishing, compromised accounts, ransomware, and other threats aren’t limited to large companies. The appropriate tools may differ based on the size and needs of the business, but basic protections matter at any size.

The Omaha Business Cybersecurity Checklist (No IT Degree Required) Read More »

Microsoft Is Phasing Out Text-Message MFA. Here’s What Businesses Need to Know 

If you’re used to signing into Microsoft 365 and waiting for a six-digit code to arrive by text, that experience is on its way out. 
Microsoft is moving away from SMS and voice calls as preferred methods of verifying sign-ins and pushing users toward more secure options, including passkeys and the Microsoft Authenticator app. 
For businesses, this is less about learning another Microsoft feature and more about making sure employees are ready before their familiar sign-in option changes.

Why Is Microsoft Moving Away From Text Messages?

Text-message verification was a big improvement over using a password alone. The problem is that attackers have gotten better at getting around it. 
SMS codes can be intercepted or stolen through phishing and SIM-swapping attacks. They also depend on your mobile carrier actually delivering the message. Anyone who has stared at a login screen waiting for a code that never arrives knows that isn’t always a given. 
Microsoft now recommends stronger authentication methods that don’t rely on a text message being sent to your phone. 
That includes Microsoft Authenticator, Windows Hello for Business, security keys and, increasingly, passkeys. 

Wait — What’s a Passkey?

A passkey is essentially a replacement for a traditional password that uses something you already have, such as your phone or computer, to verify that you’re really you. 
Depending on the device, that might mean using your fingerprint, Face ID, Windows Hello or your device PIN. 
The important part isn’t the terminology. It’s that passkeys are designed to be much harder for an attacker to steal through a fake login page. 
Microsoft Authenticator can also be part of this experience. The app supports MFA approvals, verification codes, passwordless sign-in and passkeys. 

What Is Actually Changing?

Microsoft has been moving users toward stronger authentication for some time, but there are now some important dates for businesses using Microsoft Entra ID. 
Beginning September 1, 2026, Microsoft plans to start automatically enabling passkey registration prompts for users who are still enabled for SMS or voice authentication. 
Then, beginning February 1, 2027, Microsoft-provided SMS and voice authentication will be retired in Microsoft Entra ID. 
That doesn’t mean everyone’s text-message MFA will suddenly disappear tomorrow. Organizations have time to prepare, and Microsoft provides administrators with options for managing the transition. 
But it does mean businesses shouldn’t wait until employees are confronted with an unfamiliar sign-in screen to figure out what they’re supposed to do. 

What Does This Mean for Your Employees? 

For most users, the biggest change will simply be how they prove it’s really them when they sign in. 
Instead of:
Password → Receive text → Enter six-digit code 
they may use something like: 
Password → Approve sign-in through Authenticator 
or eventually: 
Passkey → Face, fingerprint or device PIN  
Depending on how your Microsoft environment is configured, the exact experience may look different.

And that’s important: businesses shouldn’t tell employees to blindly follow every unexpected authentication prompt they receive. Your IT provider or internal IT team should determine which authentication methods your organization is using and communicate that process to employees.

Why This Is a Good Thing 


Any change to the login process can be annoying at first. From a security standpoint, though, moving away from SMS makes sense. 

Passwords get stolen. Text-message codes can be phished. Attackers routinely create convincing Microsoft login pages designed specifically to capture credentials and verification codes. 

Modern authentication methods make that considerably harder. 

Microsoft is also increasingly using system-preferred authentication, which means that when someone has multiple authentication methods registered, Microsoft can prompt them to use the strongest available option instead of automatically falling back to something weaker.

The goal is pretty simple: make the easiest way to sign in also one of the safest. 

What Should Businesses Do Now? 


You don’t need to panic, and you don’t need to wait until 2027 either. 

This is a good time to have your team review:

• Which employees are still using SMS or voice calls for MFA

• Whether Microsoft Authenticator is properly configured 

• Whether passkeys are appropriate for your organization 

• Which authentication methods are allowed in Microsoft Entra ID 

• How employees will be notified and trained before their sign-in experience changes 

• What your recovery process looks like when someone loses or replaces a phone 

A little preparation now can prevent a lot of “I can’t get into my email” calls later.

MFA Isn’t Going Away — It’s Getting Better


The takeaway isn’t that Microsoft is getting rid of multi-factor authentication. 

Quite the opposite. 

Microsoft is moving away from some of the older ways of doing MFA and toward methods that are harder for attackers to steal, intercept or trick users into handing over.

If your business still relies heavily on text-message codes, now is a good time to review how your Microsoft 365 accounts are protected and start preparing employees for what’s coming. 

Not sure which authentication methods your organization is currently using? InfiNet Solutions can review your Microsoft 365 security configuration, identify users still relying on older authentication methods and help you plan the transition without turning it into a company-wide login headache. 

          Microsoft Is Phasing Out Text-Message MFA. Here’s What Businesses Need to Know  Read More »

          HIPAA Compliance Isn’t a Checkbox. Here’s What Omaha Healthcare Practices Actually Need to Do. 

          Your practice manager forwards you an email: your insurance carrier wants documentation of your latest HIPAA Security Risk Analysis. You start looking. What you find is a training certificate from a few years ago, a privacy policy saved in a shared folder, and a vendor agreement nobody is sure is current. 
          What you do not find is a clear record showing how your practice identifies security risks, addresses them, and reviews its safeguards over time. 
          That is where many dental, eye care, and medical practices get stuck. HIPAA compliance is not a certificate you earn once. It is an ongoing process built around documented policies, staff responsibilities, technology safeguards, vendor oversight, and incident planning. 
          For day-to-day operations, three HIPAA rules matter most. The Privacy Rule governs how protected health information may be used and disclosed. The Security Rule applies to electronic protected health information, or ePHI. The Breach Notification Rule explains what regulated organizations must do after certain breaches of unsecured information. 
          In a healthcare practice, ePHI may be stored or transmitted through practice management software, billing systems, email, cloud applications, workstations, mobile devices, backups, and diagnostic imaging. Panoramic dental images, X-rays, retina scans, and intraoral photos can be protected health information just like chart notes and billing records. 
          A workable compliance program should include: 
          • A documented Security Risk Analysis that reflects the current environment 
          • Written privacy and security policies staff can follow 
          • Role-based training that is updated when systems or procedures change 
          • Business Associate Agreements where the vendor relationship requires one 
          • A breach response plan with clear responsibilities and escalation steps 
          The goal is not paperwork for its own sake. It is to protect patient information and be able to show how the practice manages risk when an insurer, auditor, or regulator asks. 
          A Security Risk Analysis, or SRA, is the foundation of the HIPAA Security Rule’s risk-management process. It identifies where the practice creates, receives, maintains, or transmits ePHI and evaluates the threats and vulnerabilities that could affect that information. 
          The analysis should cover the full environment, not only a list of computers. That may include practice management and imaging systems, email, remote access, front-desk devices, connected equipment, cloud platforms, backups, third-party integrations, and staff access from mobile or personal devices. 
          The current Security Rule does not set one required schedule for every organization. HHS describes risk analysis as an ongoing process. Many practices use an annual review as a practical baseline, with additional review after a security incident or a meaningful change in technology, staffing, vendors, ownership, or operations. 
          A useful SRA should lead to action. Each significant finding should have a planned response, a responsible owner, a target date, and a way to confirm that the issue was addressed. 
          HIPAA does not require every practice to use the same products or build the same technology environment. It does require reasonable and appropriate administrative, physical, and technical safeguards based on the risks the practice identifies. 
          Common areas to review include: 
          • Individual accounts and role-based access, rather than shared logins 
          • Prompt access changes when an employee changes roles or leaves 
          • Multi-factor authentication for email, remote access, cloud services, and administrative accounts 
          • Encryption decisions that are based on risk and documented in writing 
          • Backups that are protected, tested, and recoverable 
          • System monitoring with clear ownership for reviewing and escalating alerts 
          Under the current rule, encryption is an addressable implementation specification. Addressable does not mean optional. A practice must determine whether encryption is reasonable and appropriate, document that decision, and use an equivalent alternative when appropriate. The same practical review should cover both stored information and data sent through email, file transfers, portals, or system integrations. 
          Backups also need more than a successful status message. Recovery testing should confirm that patient records, schedules, images, and billing data can be restored after an outage or security incident. 
          A Business Associate Agreement, or BAA, is generally required when a vendor creates, receives, maintains, or transmits protected health information while performing services on behalf of a covered entity. 
          Depending on the services provided, that may include a billing company, cloud hosting provider, practice management vendor, document destruction company, consultant, or IT service provider. Not every company that works with a practice is automatically a business associate; the deciding factor is what the vendor does and whether the service involves PHI. 
          Review the vendor list regularly and confirm which relationships require a BAA, whether each agreement is signed and current, and whether relevant subcontractors are covered. A BAA documents responsibilities, but it does not replace basic due diligence about how the vendor protects information and reports incidents. 
          HHS proposed a major update to the HIPAA Security Rule in December 2024, and the proposal was published in January 2025. As of August 2026, it has not been finalized, so the current Security Rule remains in effect. 
          The proposal would remove the distinction between required and addressable implementation specifications and add more specific requirements for areas such as multi-factor authentication, encryption, asset inventories, network maps, compliance audits, vulnerability testing, incident response, and business associate verification. 
          The federal Unified Agenda currently lists July 2027 as the anticipated date for final action. That is an agency planning estimate, not a guaranteed publication date or compliance deadline. The final requirements and timing could still change. 
          One change is already in effect. As of February 16, 2026, covered healthcare providers and health plans are required to include applicable information about substance use disorder patient records under 42 CFR Part 2 in their Notices of Privacy Practices. Practices should confirm that their current notice contains the required language and is posted or distributed where required. 
          The practical approach is to address known risks now without treating a proposal as current law. Improvements such as stronger account protection, tested recovery, current documentation, and clear vendor oversight reduce risk today and make future changes easier to manage. 
          An IT provider should not replace your attorney, privacy officer, or compliance advisor. Its role is to manage and document the technology that supports the compliance program. 
          A qualified provider should understand which systems contain ePHI, how access is controlled, how backups are protected, how security alerts are handled, and how the practice will recover after an incident. The provider should also be prepared to sign a BAA when its services make it a business associate. 
          InfiNet’s Managed IT Services can support ongoing technology management, while Cyber Security Solutions and IT Support for Healthcare provide relevant security and healthcare-focused context. 
          HIPAA compliance should be reflected in the way the practice manages information every day. When policies, technology, vendors, and staff procedures support one another, the work becomes more manageable and the practice is better prepared when questions arise. 
          Need help making the technology side of HIPAA easier to manage? Let’s talk. 
          An SRA documents where ePHI exists, the threats and vulnerabilities that affect it, and the level of risk. The current rule does not prescribe one fixed schedule. Review frequency should reflect the practice’s environment, with updates when significant changes or incidents affect ePHI. 
          Generally, yes, when the provider creates, receives, maintains, or transmits PHI while performing services for the practice. The answer depends on the actual service relationship and access to PHI. 
          Yes. Diagnostic images maintained as part of a patient’s record can be PHI. When stored or transmitted electronically, they are subject to the Security Rule’s protections for ePHI. 
          Common gaps include incomplete risk analysis, outdated access lists, missing vendor documentation, weak account protection, untested recovery plans, and policies that no longer match how the practice actually works. 
          The Notice of Privacy Practices change tied to 42 CFR Part 2 took effect on February 16, 2026. The proposed Security Rule overhaul remains pending as of August 2026, and July 2027 is only the current anticipated date for final action. 
          Outcomes depend on the facts and may include technical assistance, corrective action, monitoring, a settlement, or a civil monetary penalty. Clear documentation and timely remediation help a practice explain what happened and how it responded. 
          Yes. Monitoring can help identify failed backups, suspicious logins, disabled security tools, unauthorized changes, and other technical issues. It supports compliance when alerts are reviewed, documented, and connected to a response process. 

          HIPAA Compliance Isn’t a Checkbox. Here’s What Omaha Healthcare Practices Actually Need to Do.  Read More »

          Security Awareness Training That Actually Works (Without Being Annoying) 

          It’s the third Tuesday of the quarter, and an email lands in every inbox with the subject line, “Mandatory Security Training – Complete by Friday.” You can practically hear the collective groan roll through the office. 
          Everyone clicks through the slides, guesses their way through the quiz, and moves on with the day. Then a convincing invoice request arrives two months later, and the employee facing it has never practiced what to do in that moment. 
          If that sounds familiar, you have not failed at cybersecurity. You may simply be relying on a training model designed to document completion instead of build better habits. For businesses in Omaha, Lincoln, and Council Bluffs, the goal is not to make employees cybersecurity experts. It is to help them recognize suspicious activity, slow down, and report it quickly. 
          A long annual presentation may satisfy an administrative requirement, but it gives employees very little practice. The Federal Trade Commission recommends reinforcing security messages with periodic refreshers and updates, rather than treating training as a one-time event. 
          Most employees are moving quickly, switching between tasks, answering customers, approving invoices, and trying to keep work on schedule. A realistic phishing message is designed to take advantage of that pace. 
          The 2026 Verizon Data Breach Investigations Report found that the non-intentional human element was present in 62% of breaches. That does not mean people are the only security problem. It does mean employee decisions remain an important part of the risk picture, alongside technical weaknesses and criminal tactics. 
          A large 2026 benchmark from KnowBe4 shows what repeated practice can change. The report analyzed 42 million simulated phishing tests across 14.8 million users at 64,000 organizations. Its average Phish-prone Percentage was 33.2% before training, 20.1% after 90 days, and 4.2% after one year of ongoing training and testing. These are vendor customer benchmarks, so every organization will not see identical results, but the direction is clear: consistent practice is more useful than a once-a-year reminder. View the 2026 benchmark source. 
          Security awareness is not a course employees finish once. It is a set of habits the organization reinforces, and leadership sets the tone. 
          • Leadership participates. Owners and managers complete the same training and follow the same verification steps as everyone else. 
          • Reporting is treated as a win. Thank employees who flag suspicious messages, even when the message turns out to be legitimate. 
          • High-risk requests get a second check. Wire transfers, payroll changes, gift card requests, and unusual account updates should be verified through a known phone number or established process, not by replying to the message. 
          • Security habits stay visible. Password manager use, careful review of multi-factor authentication prompts, safe handling of personal devices, and quick reporting should appear in regular reminders and team conversations. 
          Done well, this stops feeling like another training assignment. It becomes part of how the team works. 
          A completion percentage tells you who opened the training. It does not tell you whether employees are becoming faster or more confident at recognizing risk. 
          • Phishing engagement rate. How many employees clicked, opened an attachment, entered information, or otherwise interacted with a simulation? 
          • Reporting rate. How many employees used the reporting process, and how quickly did they report? 
          • Repeat behavior. Are the same people making the same mistake, or are they improving after coaching? 
          • Simulation difficulty. Was the test easy, moderate, or difficult for the intended audience? Use that context before comparing one campaign with another. 
          The goal is not a perfect score. The goal is steady improvement and faster reporting when something looks wrong. 
          Security awareness training is just one piece of a comprehensive cybersecurity strategy. The most effective organizations take a layered approach that combines people, processes, and technology to reduce risk and improve resilience. 
          A trusted managed IT partner should help implement and maintain the technical safeguards that support your business, including: 
          • Identity and access management  
          • Endpoint protection  
          • Email security  
          • Regular patching   
          • Secure backups  
          • Continuous monitoring  
          • Vulnerability management  
          • Incident response plan.  
          Together, these layers help prevent attacks, limit their impact, and support a faster recovery when incidents occur. 
          Technology alone isn’t enough, and neither is training alone. Lasting cybersecurity comes from combining informed employees with well-designed systems, thoughtful policies, and ongoing guidance that evolves alongside today’s threats. The result is a security program that protects your business without getting in the way of the people who keep it running. 
          There is no universal schedule for every business. A practical starting point is short monthly refreshers paired with regular simulated phishing tests, then adjust the cadence based on employee roles, risk, and results. The important part is consistent reinforcement, not one long annual session. 
          It can, when it is part of an ongoing program. In KnowBe4’s 2026 customer benchmark, the average Phish-prone Percentage moved from 33.2% before training to 20.1% after 90 days and 4.2% after one year of training and testing. Those results are not a guarantee for every organization, but they support the value of repeated practice and measurement. See the source data. 
          Provide quick, private, judgment-free coaching. Explain the clues in the message, show the correct reporting process, and give the employee a chance to practice again. Public callouts can make people less willing to report a real mistake. 
          Results vary, but the KnowBe4 benchmark showed a measurable change within the first 90 days and a much lower average engagement rate after one year. Track your own baseline and trend instead of assuming a published benchmark will match your organization exactly. 
          Requirements vary by industry, framework, contract, and insurance policy. A slide deck may document that training occurred, but it may not satisfy requirements for recurring education, testing, reporting, or proof of completion. Confirm the exact requirements that apply to your business with the appropriate compliance, legal, or insurance resource. 
          Include password and multi-factor authentication habits, payment and payroll verification, safe use of personal devices, handling of sensitive information, physical security, and how to respond to suspicious texts, phone calls, collaboration messages, or AI-generated impersonation attempts. 
          No. Training reduces avoidable mistakes, but it does not replace technical protections. The strongest approach combines employee awareness with multi-factor authentication, secure email controls, monitored backups, patching, endpoint protection, and proactive network monitoring. 

          Security Awareness Training That Actually Works (Without Being Annoying)  Read More »

          Talk to our Team