Workforce training: Positive shift in cyber resilience testing Proportion of organisations training/not training their employees in cybersecurity (% of respondents) 6% No Across all sectors, most surveyed organisations train their staff in cybersecurity or familiarise them with current cyber threats at least once a year. Only 6 % of respondents do not train their employees at all (Fig. 12). Informing staff via email or internal portals is the most widespread training method, used by almost two thirds of the respondents. Organisations in the healthcare and education sectors provide the least training, with around 85 % of the surveyed organisations offering training. 94 % Yes Figure 12 Methods of testing staff resilience to cyber threats in 2023 (% of respondents). Simulated phishing campaigns 44 % No tests 40 % Penetration tests 25 % 13 % Social engineering techniques 12 % Technical or non-technical exercises Other 6% 0% Simulated phishing campaigns are the most common form of testing Figure 13 20 10 % 20 % 30 % 40 % However, 40 % of organisations do not conduct any testing of their staff. 50 %

Select target paragraph3