BadgerQuest
Play a roundWhy it sticksFor managersWho it's forLearnDocsPricingSign in
For schools, colleges and universities

When something goes wrong at a school, it is almost always phishing

Security awareness training staff will actually finish, for institutions whose attack surface includes everyone who has ever had a login.

Schools run on trust and on email: parents, suppliers, boards, students, and a staff room where nobody was hired to think about attackers. The finance office pays real invoices, and the safeguarding records are as sensitive as anything a hospital holds.

The UK government breaks its annual survey out by institution type, and the answer is the same at every level, at a rate that leaves very little room for anything else.

Start free and try it on one departmentTalk to us

The evidence, and where it comes from

Every figure below links to the source it came from. We have quoted what each number counts, because a percentage without its denominator is not evidence, it is decoration.

90%

of primary schools that identified a breach said phishing was the threat, making it overwhelmingly the main one.[1]

96%

of secondary schools that identified a breach said the same, as did 96% of further and higher education institutions that identified one.[1]

68%

of education breaches worldwide involved the human element, and phishing was the second most common way in at 22%, across 1,302 incidents and 1,252 confirmed breaches.[2]

What this does not say

The 90% and 96% figures are UK-only, and are percentages of institutions that identified a breach rather than of all schools. We quote the base because it changes what the number means. The 68% is global, and is a share of breaches rather than of institutions.

Built for a staff room, not a SOC

Minutes, in a week that has none

One message to judge each day, and a short set of questions once a week. It fits between a lesson and a meeting, which is the only slot that actually exists.

Departments, not one average

Finance, reception and leadership face different scams and are scored separately, so the office paying invoices is not hidden inside a school-wide number.

Nobody is set up to fail

No simulated phishing to real inboxes, and nobody shamed for a wrong call. Staff who feel tricked by IT stop reporting, and reporting is the thing you actually want.

Evidence for the board

Completion, certificates and a readiness score you can put in front of governors without exporting anything by hand.

Budget is a conversation, not a wall

The list price is $4 CAD per person per month. Schools, colleges and universities are priced case by case. Tell us your headcount and which budget year you are working to, and we will work from that.

What your people will practise, explained free

These are the same scams this page is about, written for the person who has to spot one on a Tuesday morning. No account needed to read them.

How to spot a phishing emailFake sign-in alerts and how attackers steal passwordsGift card scams: why your "boss" is asking for them

What is true in every sector

62%

of breaches involved the human element, up from 60% the year before, across more than 22,000 confirmed breaches in 145 countries.[2]

31%

of breaches began with vulnerability exploitation, which this year overtook credential abuse (down to 13%) as the single most common way in. People are involved in most breaches, but they are not the most common entry point, and we are not going to tell you otherwise.[2]

16%

of breaches came through social engineering, the third most common pattern. In simulations, the median click rate for voice and text lures runs 40% higher than for email.[2]

And the uncomfortable part, which we would rather you heard from us

One of the largest field studies of phishing training ever published followed roughly 19,500 staff at a large health system through ten simulated campaigns over eight months. It did not flatter the industry we are in.

2 points

was the entire effect of embedded phishing training on the likelihood of clicking a phishing link. Having recently completed annual mandatory security training showed no significant relationship with falling for phishing at all.[3]

75%

of the people who landed on the training page spent a minute or less on it, and about a third closed it immediately. That is a finding about attention, not about people being careless.[3]

We read that as the strongest argument for how BadgerQuest is built, not against it. What the study measured is the industry standard: an annual module, an ambush simulation, and a training page served to somebody who has just been told they failed. Nobody reads that page. Training that gets skimmed for forty seconds is not a smaller dose of training that works, it is a different thing entirely.

So the daily round is two minutes and it is a game, because that is the version people voluntarily finish. We do not send simulated phishing to real inboxes, because being ambushed by your own IT department is what produces the closed tab. Nobody is shamed for a wrong call, and what we train is the judgement to tell the two apart rather than a reflex to flag everything. Topics somebody keeps missing come back around instead of being marked complete.

The study's authors also recommend refocusing on technical countermeasures, specifically two-factor authentication and password managers that only fill on the correct domain. They are right, and those will stop more attacks than any training will. Do them first. We will say the same on a sales call. Training is for the part those controls do not cover, and it should be honest about being exactly that.

Sources

Read them yourself. That is the entire habit we are trying to teach, and it would be a strange thing for us to ask of your staff and not of ourselves.

  1. [1]UK Department for Science, Innovation and Technology, and Home Office. Cyber security breaches survey 2025/2026: education institutions findings Official Statistic, published 30 April 2026. United Kingdom only.https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026-education-institutions-findings
  2. [2]Verizon Business. 2026 Data Breach Investigations Report, Executive Summary 19th edition, published May 2026. More than 31,000 security incidents, of which more than 22,000 were confirmed data breaches, across organisations in 145 countries. Figures quoted here are from the executive summary PDF.https://www.verizon.com/business/resources/executivebriefs/2026-dbir-executive-summary.pdf
  3. [3]Ho et al., University of Chicago, UC San Diego and UC San Diego Health. Understanding the Efficacy of Phishing Training in Practice 46th IEEE Symposium on Security and Privacy, May 2025. Roughly 19,500 staff at UC San Diego Health, ten simulated campaigns over eight months. Findings summarised by UC San Diego Today, 17 September 2025.https://today.ucsd.edu/story/cybersecurity-training-programs-dont-prevent-employees-from-falling-for-phishing-scams

Start free and try it on one department

Free for individuals, forever. Teams are $4 CAD per person per month, month to month, no minimum, cancel whenever you like. Schools, charities and public bodies are priced case by case, so ask us.

Start free and try it on one departmentTalk to us

Not quite your sector?

MSPsSmall businessNon-profitsHealthcareCard paymentsPublic sectorLaw firmsAccounting firmsAll of them
BadgerQuest by CyberBadger
Who it's forLearnDocsAPIHelpCheck a certificatePrivacyTermsMade in Canada