BadgerQuest
Play a roundWhy it sticksFor managersWho it's forLearnDocsPricingSign in
For anyone who takes card payments

If you take cards, phishing training is not optional

Retail, hospitality, clinics, charities taking donations: the same standard applies, and it names the topic by name.

Taking card payments puts you inside PCI DSS whether or not you think of yourself as a technology company. A café, a physiotherapy clinic and a charity with a donate button are all in scope.

Version 4 of the standard is unusually specific here. It does not merely ask for security awareness training in the abstract. It names the thing your staff are actually going to be hit with.

Start free and see what your staff would practiseTalk to us

The evidence, and where it comes from

Every figure below links to the source it came from. We have quoted what each number counts, because a percentage without its denominator is not evidence, it is decoration.

Named

PCI DSS v4 requires organisations to “include phishing and social engineering in security awareness training”, wording that appears across the self-assessment questionnaires under Requirement 12.[1]

58%

of retail breaches involved the human element, across 997 incidents and 806 confirmed breaches, with 68% involving a third party. Three patterns account for 95% of them, and social engineering is one.[2]

What this does not say

Requirement 12 is quoted from the Council's own published material because the standard itself sits behind a licence agreement. Read the standard for the full requirement, and treat your acquirer or QSA as the authority on what applies to you. We can evidence the training. We cannot certify your compliance.

What you get for the requirement

Phishing and social engineering, by design

That is the entire product rather than a module bolted onto one: forged email, text messages and phone pretexts, practised rather than watched.

Records that survive a question

Completion per person, certificates with verifiable serials, and an audit log, so “show me” is a link rather than a project.

It scales down

No seat minimum. A three-person shop pays for three people, and a sole trader can buy it for themselves.

What your people will practise, explained free

These are the same scams this page is about, written for the person who has to spot one on a Tuesday morning. No account needed to read them.

How to tell if a website is fake (the padlock isn't enough)How to spot a phishing emailQR code scams (quishing): the sticker on the meter

What is true in every sector

62%

of breaches involved the human element, up from 60% the year before, across more than 22,000 confirmed breaches in 145 countries.[2]

31%

of breaches began with vulnerability exploitation, which this year overtook credential abuse (down to 13%) as the single most common way in. People are involved in most breaches, but they are not the most common entry point, and we are not going to tell you otherwise.[2]

16%

of breaches came through social engineering, the third most common pattern. In simulations, the median click rate for voice and text lures runs 40% higher than for email.[2]

And the uncomfortable part, which we would rather you heard from us

One of the largest field studies of phishing training ever published followed roughly 19,500 staff at a large health system through ten simulated campaigns over eight months. It did not flatter the industry we are in.

2 points

was the entire effect of embedded phishing training on the likelihood of clicking a phishing link. Having recently completed annual mandatory security training showed no significant relationship with falling for phishing at all.[3]

75%

of the people who landed on the training page spent a minute or less on it, and about a third closed it immediately. That is a finding about attention, not about people being careless.[3]

We read that as the strongest argument for how BadgerQuest is built, not against it. What the study measured is the industry standard: an annual module, an ambush simulation, and a training page served to somebody who has just been told they failed. Nobody reads that page. Training that gets skimmed for forty seconds is not a smaller dose of training that works, it is a different thing entirely.

So the daily round is two minutes and it is a game, because that is the version people voluntarily finish. We do not send simulated phishing to real inboxes, because being ambushed by your own IT department is what produces the closed tab. Nobody is shamed for a wrong call, and what we train is the judgement to tell the two apart rather than a reflex to flag everything. Topics somebody keeps missing come back around instead of being marked complete.

The study's authors also recommend refocusing on technical countermeasures, specifically two-factor authentication and password managers that only fill on the correct domain. They are right, and those will stop more attacks than any training will. Do them first. We will say the same on a sales call. Training is for the part those controls do not cover, and it should be honest about being exactly that.

Sources

Read them yourself. That is the entire habit we are trying to teach, and it would be a strange thing for us to ask of your staff and not of ourselves.

  1. [1]PCI Security Standards Council. PCI DSS v4 self-assessment questionnaires, Requirement 12 Wording quoted from the Council's own published material; read 5 August 2026. The standard itself sits behind a licence agreement we cannot link you through.https://blog.pcisecuritystandards.org/pci-dss-v4-whats-new-with-self-assessment-questionnaires
  2. [2]Verizon Business. 2026 Data Breach Investigations Report, Executive Summary 19th edition, published May 2026. More than 31,000 security incidents, of which more than 22,000 were confirmed data breaches, across organisations in 145 countries. Figures quoted here are from the executive summary PDF.https://www.verizon.com/business/resources/executivebriefs/2026-dbir-executive-summary.pdf
  3. [3]Ho et al., University of Chicago, UC San Diego and UC San Diego Health. Understanding the Efficacy of Phishing Training in Practice 46th IEEE Symposium on Security and Privacy, May 2025. Roughly 19,500 staff at UC San Diego Health, ten simulated campaigns over eight months. Findings summarised by UC San Diego Today, 17 September 2025.https://today.ucsd.edu/story/cybersecurity-training-programs-dont-prevent-employees-from-falling-for-phishing-scams

Start free and see what your staff would practise

Free for individuals, forever. Teams are $4 CAD per person per month, month to month, no minimum, cancel whenever you like.

Start free and see what your staff would practiseTalk to us

Not quite your sector?

MSPsSmall businessNon-profitsHealthcareSchools & collegesPublic sectorLaw firmsAccounting firmsAll of them
BadgerQuest by CyberBadger
Who it's forLearnDocsAPIHelpCheck a certificatePrivacyTermsMade in Canada