Article Read Time

Most breaches start with a person. A year of cyber security training for a small office, including part-time staff, takes under five hours per employee.
Sixty-two percent of the breaches Verizon examined for its 2026 Data Breach Investigations Report involved the human element. That means a clicked link, a reused password, a file sent to the wrong address, or a caller who was not who they claimed to be. That figure has stayed in roughly the same range for years, and it points small organizations toward a plain conclusion. Firewalls and backups matter, but the cheapest protection most offices can buy is focused time with the people who open the email, answer the phone, and pay the invoices.
What follows is a practical outline for a typical Kentucky office with 10 full-time employees and four part-time staff. That is the kind of payroll found at a family insurance agency or a non-profit on Main Street. The program costs mostly staff time, and much of the material is free.
1. Start with one session cyber security training for everyone, part-time staff included
Hold a 90-minute cyber security training kickoff during paid hours, and run it twice if it takes that for the four part-time employees to attend. Part-time staff often have the same email access and the same login to the shared drive as everyone else. Attackers don’t check a work schedule before sending a message.
The session should cover four things in plain terms. First is how to spot a phishing email, a message dressed up to look like it came from someone you trust. The second is multifactor authentication, which means a second login step beyond a password. The last two are what to do when a caller or text asks for money, and who to tell when something feels off.
2. Name one person and one way to report
Training most often fails in the minutes after an employee clicks something they should not have. Pick a single person, usually the office manager, and a single channel, such as a phone call. Then tell staff plainly that reporting a mistake quickly will never be held against them. An office that learns about a bad click within 10 minutes can reset a password and contain the damage. An office that learns about it three weeks later is often on the phone with its insurance carrier.
3. Give the people who move money their own cyber security training
In an office of 14, one or two people usually handle payroll and vendor payments. Criminals target those people with fake invoices and changed account numbers. They need an extra 30 minutes built around one rule. Confirm any request to change where money goes by calling a number already on file, never a number listed in the email. That single habit shuts down the most common version of the invoice fraud that small businesses report to the FBI.
4. Keep it short and keep it monthly
A single annual session fades within weeks. The better rhythm is a 15-minute refresher once a month, folded into a staff meeting the office already holds. Build each one around a real example, such as a scam text making the rounds in Kentucky or a message someone in the office received that week. Across 14 people, that’s about 3.5 hours of staff time each month.
5. Practice with simulated phishing, and keep the results anonymous
Quarterly practice emails, sent by the office or a trusted partner, show whether the lessons are sticking. Share results as a group number, never tied to a name in front of coworkers. The aim is to measure the office as a whole. Include texts and phone calls in the practice, because Verizon found that social engineering aimed at mobile phones succeeds about 40 percent more often than traditional email phishing.
6. Cover personal phones, new tools, and departures
Part-time employees in particular tend to check work email on personal phones, so training should cover locking the phone, keeping it updated, and keeping work files out of personal apps. It should also set a policy on artificial intelligence tools. The Verizon report found employee use of unapproved AI tools rose from 15 percent to 45 percent in a single year. New hires should get the core session in their first week, and accounts should be closed the same day an employee leaves.
What cyber security training costs
The program comes to roughly 65 hours of staff time a year. That covers about 21 hours for the kickoff, 42 hours of monthly refreshers, and a little extra for the people who handle money. Spread across 14 people, that is less than five hours per employee. It is a modest line item next to a single wire transfer sent to the wrong account.
Commonwealth Sentinel can manage the whole cyber security training program for an office of this size for less than $3,000 a year. That works out to about $214 per employee, or under $18 a month per person, and it means the office manager does not have to build or run any of it from scratch.
Our team brings more than 30 years of work in cyber security and critical infrastructure protection across the U.S. Navy, the FBI, and InfraGard to every session we lead. We track the scams reaching Kentucky offices each month, so the refreshers and practice emails reflect whatever is landing in inboxes and on phones right now, including newer tricks built with artificial intelligence.
Between sessions, we are always a phone call away at 502-234-5554 when an employee receives something that does not look right and wants a second opinion before clicking. The people trying to get into a small office are counting on a busy employee in a hurry. The best defense that office has is staff who know they can slow down and call someone.
