MALWARE AND PHISHING CyberArtical Editorial Team

Staff ransomware training versus the controls that do the work

A group of employees with lanyards sitting in rows at a training session, one of them speaking

Every organisation that has thought about ransomware for ten minutes has considered staff training, and most of them have then treated the training as the control. It is not. It is a useful supplement to three technical measures that CISA names ahead of anything to do with awareness. This piece sets the two side by side, then describes what a short staff session should actually contain.

Where each one applies

  • The #StopRansomware Guide’s headline controls are phishing-resistant MFA, offline encrypted backups that are regularly tested, and regular patching.
  • Training works on the moment of decision. The three controls above work whether or not anyone made a good decision.
  • CISA’s teachable sequence is short enough to remember: resist clicking, report, delete. Do not reply.
  • The FBI does not support paying a ransom — it does not guarantee data back and it encourages perpetrators to target more victims.
  • In the 2025 IC3 report ransomware drew 3,611 complaints and $32,320,105 in losses, against 191,561 phishing and spoofing complaints.

Train people, but fund the backups first

Do both, but do not let the training budget stand in for the backup budget. If you can only do one thing this quarter, make it offline, encrypted, tested backups, because that is the control that decides whether an incident is a bad week or an existential one.

Training’s value is that it shortens the time between something going wrong and someone saying so. That is genuinely worth having. It is just not the same category of protection as a restorable backup.

What the two approaches actually do

A technical control changes what is possible. Phishing-resistant MFA on email means a stolen password is not enough. An offline backup means encrypted files are an inconvenience rather than a loss. A patched system means a known vulnerability is closed regardless of who clicks what.

Training changes what is likely. It can raise the chance that a member of staff hesitates over an urgent message, and — more usefully — that they report a mistake quickly instead of hoping it goes away.

The failure mode of relying on training alone is that it puts the entire defence on the least forgiving surface: one person’s attention, once, under time pressure. CISA’s own phishing guidance quietly concedes how hard that is, noting that with AI-written lures some emails will now have perfect grammar and spelling.

The three controls CISA puts first

Note that MFA appears with a qualifier. CISA’s MFA hierarchy ranks phishing-resistant FIDO/WebAuthn and PKI at the top and SMS or voice codes at the bottom, the latter described as vulnerable to phishing, SS7 and SIM swap attacks. CISA also holds that any MFA is better than no MFA, so the sequence is: turn something on now, upgrade the email account first.

On backups, CISA’s separate device guidance adds the detail people skip — avoid leaving the external drive connected when you are not actively backing up. A drive that is always plugged in is a drive that ransomware can reach.

  • Implement phishing-resistant MFA for all services, particularly for email, VPNs, and accounts that access critical systems.
  • Maintain offline, encrypted backups of critical data, and regularly test the availability and integrity of the backups.
  • Regularly patch and update software and operating systems to the latest available versions.

What belongs in a twenty-minute staff session

  1. CISA’s three-step response, taught as a reflex: resist clicking links or attachments, report it using the mail client’s report option, delete the message without replying.
  2. The out-of-band rule: to check whether a message is genuine, look up another way to contact the company or person directly. Never the number or link in the message.
  3. The signs that still work now that spelling doesn’t: urgency and claims of dire consequences, requests for personal or financial information, untrusted shortened URLs, and near-miss domains like amazan.com.
  4. Who to tell, by name, and the explicit promise that reporting a mistake fast will not get anyone into trouble.
  5. What the organisation does not do: the FBI’s position that it does not support paying a ransom, so nobody assumes payment is the plan.

What people get wrong about this comparison

The first mistake is treating a simulated phishing campaign as a measurement of security. It measures how many people clicked one particular email on one particular day. Neither CISA nor the FTC publishes a figure for how much training reduces real compromise, and any article quoting one should be asked where it came from.

The second is scale. Ransomware occupies far more consumer coverage than its complaint volume warrants — 3,611 complaints in the 2025 IC3 report against 191,561 for phishing and spoofing, 89,129 for extortion and 67,456 for personal data breach. Train for the common case and you will have covered the rare one on the way through.

The third is forgetting who to call. Keep CISA’s ransomware line — Central@cisa.dhs.gov or 1-844-729-2472 — and IC3.gov somewhere that is not on the network you are trying to restore.

Sources: CISA — #StopRansomware Guide · FBI — Ransomware · CISA — Recognize and report phishing · FBI IC3 — 2025 Internet Crime Report · CISA — StopRansomware

Reviewed 27 August 2026 by the CyberArtical editorial team against primary guidance from CISA and the FBI. Security guidance changes over time; where our earlier version of this page said something different, we say so in the article rather than editing it out quietly.

More Stories