Decoding the world of cybersecurity

academy+ brings cyber training into Staff Skills

academy+ will offer Bob’s Business awareness training and phishing simulation through its Staff Skills course hub as UK training gaps persist.

academy+ brings cyber training into Staff Skills
Summary
  • academy+ has partnered with Bob’s Business to add cyber awareness training and phishing simulation to its Staff Skills academy+ course hub.
  • The partnership focuses on phishing, social engineering, human behaviour, and security culture.
  • The UK relevance comes from persistent gaps in staff training and phishing’s continued role in reported cyber incidents.

academy+ has partnered with Bob’s Business to add cybersecurity awareness training and phishing simulation to the Staff Skills academy+ course hub.

The partnership will make Bob’s Business training available to academy+ clients, combining compliance and skills-based learning with cybersecurity content focused on human behaviour, phishing, social engineering, and everyday security decisions. The training will sit inside the Staff Skills academy+ Course hub, which already includes CPD-certified courses covering compliance, professional development, and wellbeing.

academy+ cited UK government survey data showing that phishing remained the most common type of cyber attack among organisations that identified a breach or attack, while staff training remained uneven across the market. GOV.UK’s later 2025/2026 Cyber Security Breaches Survey continued to show phishing as the most prevalent type of breach or attack overall, affecting 38% of businesses and 25% of charities.

Ian McClelland, CEO of academy+, said: “We’re delighted to partner with Bob’s Business to bring engaging cybersecurity awareness training to our clients. Strengthening the human element of security is critical, and this partnership allows us to deliver a more complete and effective solution.”

Neil Frost, CEO of Bob’s Business, added: “Real cybersecurity resilience comes from people, not just technology. By working with partners like academy+, we’re helping organisations build security cultures that are practical, engaging, and built to last.”

Security awareness training is a limited but useful control. It cannot compensate for weak identity architecture, poor patching, exposed services, missing multifactor authentication, inadequate email controls, or supplier compromise. Its role is to reduce avoidable mistakes, increase reporting, support phishing simulation, and create evidence that security expectations have been communicated and reinforced.

Placing awareness training inside an existing staff skills platform may improve adoption for organisations that do not have dedicated security training workflows. Smaller businesses and public-sector teams often buy compliance training, HR learning, wellbeing content, and cybersecurity awareness through separate systems. Consolidation can make completion tracking and management oversight simpler.

Measurement will decide whether the training becomes a meaningful control. Completion rates alone show attendance, not resilience. More useful evidence includes phishing simulation results, reporting rates, repeat-clicker trends, department-level patterns, and follow-up activity where users or teams need more support.

The UK government’s longitudinal cyber research has also noted limits in training effectiveness where staff still click phishing links or provide credentials after training. That finding supports a balanced approach. Training needs to sit alongside technical controls, clear reporting routes, identity protections, management support, and usable guidance that reflects the threats employees actually face.

The academy+ partnership gives clients another route to integrate cybersecurity into routine workforce development. Its value will depend on how consistently organisations use the content, whether phishing simulation results feed into risk decisions, and whether training is connected to controls that make safe behaviour easier during ordinary work.

×