Start here
What uSecure is for #
Security training has a reputation for being a long video once a year that nobody remembers. uSecure is the opposite: it finds out what you personally are shaky on, then teaches you those specific things a few minutes at a time.
It does four jobs:
- Asks you a short set of questions, called a gap analysis, to see where your knowledge actually is.
- Enrols you on short courses aimed at the gaps it finds, rather than making everyone sit through the same material.
- Tests the whole company with simulated phishing emails, so the training gets practised rather than just watched.
- Tracks progress across the organisation, which is what your insurer and your certification auditor want to see.
Almost all of it comes to you by email. You do not need to remember to log in, check a dashboard or chase anything down.
You will get an email asking you to complete a gap analysis. Do it honestly, and everything after that is a handful of short courses picked to suit you. The whole first round is usually under half an hour.
Getting started
How you get access #
You do not sign up for uSecure and there is nothing to install. Your account already exists.
We connect uSecure to your Microsoft 365 directory and let it sync. Everyone with a work mailbox is enrolled automatically, using their work email address as their identity. In practice that means:
- You are already on it. The first thing you will see is an email, not an invitation to create an account.
- New starters are picked up on their own. Someone joining next month appears in uSecure shortly after their Microsoft 365 account is created, and starts the same journey you did.
- Leavers drop off on their own. When an account is disabled, the person stops receiving training and stops counting against your figures.
- Nothing is installed on your machine. Courses run in your browser.
You should never need to. If you land on a uSecure page offering to sign you up, or asking you to choose a password, stop and contact us. Your account is created for you and tied to your work email address.
Getting started
Signing in with a link #
There is no uSecure password. You sign in with a single-use link sent to your work email, sometimes called a magic link.
- Open the email from uSecure Every email it sends you, whether that is the gap analysis, a new course or a reminder, contains the button that signs you in. Most of the time you never think about signing in at all, you just click through from the email.
- Select the button in the email The link authenticates you and drops you straight onto whatever it was asking you to do.
- If you need to start from scratch, request a link Go to the uSecure sign in page, enter your work email address, and it will send you a fresh link. There is no password field, so nothing to get wrong.
The link is single use and time limited. If you open an email from last week and the link has expired, do not keep clicking it. Request a new one.
Open the link on the device you are reading the email on. Forwarding it to yourself or pasting it into another browser will usually fail, which is the point: it stops anyone else using it.
The main event
Your gap analysis #
This is the one thing we really need you to do. Everything else uSecure asks of you is decided by how you answer it.
The gap analysis is a short questionnaire covering the everyday security decisions people actually face: spotting a dodgy email, handling passwords, what to do with a USB stick you found, working on public Wi-Fi, that sort of thing. It is multiple choice, there is nothing to prepare, and most people finish it in well under ten minutes.
It arrives by email shortly after you are enrolled. If you leave it, you will get a reminder or two. It is genuinely the shortest part of the whole programme.
What it covers
| Area | The sort of thing it asks |
|---|---|
| Email and phishing | Whether you can pick out a fake message, and what you would do with one. |
| Passwords | How you choose them, where you keep them, and what you do when one is reused. |
| Devices | Locking your screen, updates, and what happens if a laptop or phone goes missing. |
| Handling data | Where company information is allowed to go, and what counts as sensitive. |
| Working away from the office | Public Wi-Fi, home networks, and working somewhere people can see your screen. |
| Reporting | Who you tell, and how quickly, when something looks wrong. |
Nobody is marking you and nobody is comparing you to your colleagues. The score exists so uSecure can pick your courses, and so the business can show it is improving over time. A low score on day one is completely normal, and is exactly the situation the training is there to fix.
The main event
Answering it properly #
This is where people tie themselves in knots, so it is worth two minutes of your time before you start.
The questions are written to work for every kind of business, from a two-person practice to a factory. That means the answers on offer will not always describe how your company does things. People hit a question, decide that none of the options match their workplace, and either stall or pick at random.
Do not look for the answer that matches your business exactly. Look at the options you have been given and choose the one that is most appropriate out of those. If your company does something a little differently, pick the answer closest to it and move on. The questionnaire is measuring whether you know the right sort of thing to do, not auditing your company's procedures.
Do
- Answer from your own head, in one sitting.
- Pick the closest option when nothing matches your workplace exactly.
- Answer what you would actually do, not what sounds best.
- Take the ten minutes properly. It saves you time later.
Do not
- Look the answers up, or ask the person next to you.
- Stall on a question because the wording does not fit your team.
- Guess at random to get to the end faster.
- Pick the answer you think we want to see.
uSecure builds your training from your answers. Flatter yourself and it will decide you already know the material, skip those courses, and leave you with the gap you actually had. Answer honestly and you get a short, relevant set of courses instead of a long, generic one.
What happens next
The courses you are given #
You do not choose your courses and you do not have to go looking for them. They are assigned from your gap analysis and they turn up by email.
Once your answers are in, uSecure works out which topics you were weakest on and enrols you on short courses covering those. Somebody who sailed through the phishing questions but was hazy on data handling gets a different list to the person next to them. That is the whole point of doing the gap analysis first.
Each course is short: usually a few minutes of video or slides, then a couple of questions to check it landed. You can stop partway through and pick up where you left off.
From the email
Straight from the email
This is how most people do it, and it is the path of least resistance.
- Open the course email It names the course and roughly how long it takes.
- Select the button It signs you in and opens that course directly. There is no navigating to find it.
- Work through it and answer the questions at the end Get one wrong and it will show you the right answer, which is the part that does the teaching.
This is not a one-off. Short courses continue to arrive through the year, spaced out so they never land as a big block, and the gap analysis is repeated periodically so your training keeps up with what you have learned. A few minutes every so often is the whole commitment.
Course emails will chase you if you ignore them. If you are mid-deadline, do the course when you surface rather than clicking through it without reading, but do not let it sit for weeks, because outstanding training is what shows up as a red figure on your company's report.
Ongoing
Simulated phishing emails #
From time to time we send realistic but completely harmless fake phishing emails to everyone. It is the part of the programme people are most wary of, so it is worth being straight about what it is.
Knowing the theory and catching a convincing fake in a busy inbox on a Friday afternoon are two different skills. Simulations are how the second one gets practised. They look like the real thing, whether that is a delivery notice, a shared document or a password expiry warning, but nothing behind them is real.
What happens if you click one
You land on a page telling you it was a simulation, with a short explanation of what you could have spotted. That is it. No email goes to your manager, nobody reads out a list at the next team meeting, and it does not go on your record.
You may be enrolled on a short course about that particular trick, because clicking is the clearest possible signal about where the gap is. That is the system doing its job, not a punishment.
Do
- Report anything suspicious the way you normally would, simulation or not.
- Hover over links to see where they really go before clicking.
- Check the sender's full address, not just the display name.
- Tell us if you clicked something you now think was real.
Do not
- Shout across the office that a test is going round.
- Assume anything odd must be a test. Some of it will be real.
- Feel embarrassed about clicking one. They are designed to be convincing.
- Reply to a suspicious email to ask if it is genuine.
Do not delete it and say nothing. Contact us straight away on 0118 38 42 175, especially if you entered a password or opened an attachment. The first twenty minutes matter far more than whether it was your fault, and nobody is ever in trouble for reporting quickly.
The point of it all
Why this is worth your time #
Attackers stopped trying to break through firewalls a long time ago. It is far easier to send a convincing email and wait for one person to click.
The large majority of security incidents at businesses your size start with a person, not a piece of technology failing: an invoice with changed bank details, a password reused on a site that got breached, a fake login page that looked right. We can put every technical control in place, and one convincing email on a busy day can still walk straight past all of it.
That is why the training is short, frequent and specific to you rather than annual and generic.
| What it protects | Why it matters |
|---|---|
| Your colleagues | One compromised mailbox is normally used to attack everyone else in the address book, from a trusted internal address. |
| Your customers | Invoice fraud run from a real supplier mailbox is convincing precisely because it comes from the real supplier. |
| The business itself | Recovering from a serious incident costs weeks, not hours, and the disruption lands on everybody. |
| Your insurance | Cyber insurers increasingly ask whether staff are trained, and can query a claim if the answer is no. |
| Your certifications | Cyber Essentials and similar schemes expect ongoing awareness training with evidence behind it. |
It is roughly ten minutes for the gap analysis, then a few minutes here and there. Against that, being the person who spots the fake invoice is genuinely one of the more useful things you can do for the business this year. The people who complete it are also, in our experience, the people who ring us early when something looks wrong, which is worth more than everything else combined.
Support
If something goes wrong #
Most issues are one of the following.
I never got the gap analysis email
Check your junk or clutter folder first, and search your mailbox for uSecure. If it is
genuinely not there, contact us. We can see whether your account synced across from Microsoft 365
and resend the invitation.
The sign in link says it has expired or been used
That is by design. Links are single use and time limited. Request a new one from the uSecure sign in page with your work email address, or simply open the most recent uSecure email in your inbox.
It is asking me to create an account or set a password
Stop, and contact us. Your account is created automatically from Microsoft 365 and uses sign in links rather than passwords, so you should never be asked to set one up. Send us the link you were sent so we can check it is genuine.
I got halfway through the gap analysis and lost it
Open the invitation email again and it will pick up where you left off. If it starts from the beginning, it is quicker to work through it again than to chase it, since your earlier answers were not submitted.
None of the answers describe how we do things here
That is expected. The questions are written to cover every kind of business. Choose the option that is the most appropriate of the ones offered, rather than trying to find one that matches your workplace exactly, and carry on.
I have been given a course on something I already know
Work through it anyway. They are short, and the assignment came from an answer you gave. If a whole set of courses looks wrong for your role, tell us and we can look at how your account is grouped.
A new starter has not received anything
Sync from Microsoft 365 is not instant, so allow a little time after their mailbox is created. If nothing has arrived after a couple of working days, let us know and we will check they were picked up.
Someone has left and is still getting training emails
That usually means their Microsoft 365 account is still active. Tell us and we will confirm the offboarding has gone through properly, since a live account for a leaver is a bigger problem than the emails.
Can my manager see my score?
Your organisation gets reporting on completion and overall risk across the business, and whoever owns security internally can see individual progress. It exists to show the programme is working and to satisfy insurers and auditors, not to rank people. Nobody at Coffee Cup Solutions is producing a league table.
Getting help
Coffee Cup Solutions runs uSecure on your behalf. If you are not receiving emails, a sign in link will not work, or you think a real phishing message has got through, get in touch and we will sort it.