Six months after a new practice management system goes live, half the staff still email files to themselves, a few keep a spreadsheet on the side “just in case,” and the help desk answers the same five questions every week. The software works. The rollout didn’t, because technology training for employees stopped at go-live.
Targeted training fixes that by teaching each person the tools and habits their job needs, instead of one generic session for everyone. It is also one of the cheapest security controls you have.
Key takeaways
- Train by role and real task, using your own systems and folders where you can.
- Security habits are part of technology training, and HIPAA and the FTC Safeguards Rule require it.
- Tell people why a change is happening. Train them before the new system goes live, then again a few weeks later.
- Keep records of who was trained, on what and when.
What poor technology training for employees costs
The cost rarely arrives as one bill. It shows up as small daily losses:
- Time spent hunting for features, redoing work after a sync conflict, or waiting on the help desk for a one-minute fix.
- Mistakes such as bad data entered into a new system, a file shared with “anyone with the link,” or a client sent the wrong version of a document.
- Quiet resistance, where people go back to the old way and you pay for the new tool while living with the old problems.
- Shadow IT, when people swap a hard approved tool for personal cloud storage, free file-transfer sites or consumer AI apps, moving company data where you can’t see it.
None of this means your team isn’t capable. Usually nobody showed them how the tool fits their work, or explained why the change was happening.
Security habits are part of the job
Verizon’s 2026 Data Breach Investigations Report found the human element in 62% of breaches, up slightly from 60% the year before. Phishing was the way in for 16% of breaches and pretexting, a believable story often told by phone or text, for another 6%.

The same report found that phone and mobile lures got clicked about 40% more often than email lures in simulations, so training can’t stop at checking the sender’s address. Filtering, MFA and endpoint protection catch most attacks before a person sees them. Training covers what slips past, such as the urgent call from “the bank” or the shared link that shouldn’t be public.
For our clients, phishing simulations run continuously and automatically. A click triggers a short micro-training lesson right away and is reported to the client, so you can see who needs more help. Our guide to employee cybersecurity training goes deeper on simulations, and our cybersecurity program covers the controls around them.
Find your team’s skill gaps
You don’t need a formal skills matrix to start. Read your help desk tickets for repeat questions about the same feature. Run a short, no-blame survey asking what slows people down and which tool they avoid. Spend ten minutes watching someone share a file or process an invoice. Then fix the gaps that cause downtime, security exposure or client-facing errors first.
Train by role
Everyone needs the basics: spotting and reporting phishing, using MFA and a password manager, and knowing where files belong. Beyond that, train by job.
| Role | What to focus on |
|---|---|
| Front desk and intake | Verifying callers, handling forms with personal information, and what never goes in an email |
| Billing and finance | Confirming any payment or bank-change request by phone, using a number you already have |
| Managers and partners | They are the most impersonated people in the building and approve the exceptions |
| Everyone on Microsoft 365 | When to use OneDrive, SharePoint or Teams, co-authoring instead of emailing attachments, and setting sharing links correctly |
Microsoft 365 training people will use
Our clients get Microsoft 365 training through their client portal, which includes a library of short courses, so staff can look up a short lesson when they need it. For teams that learn better in a room together, paid classroom-style training is available too, built around your own folders and workflows.
Microsoft Learn also offers free self-paced modules that work well as refreshers. Our Microsoft 365 tips are a good place to start, and our Microsoft 365 page covers setup and support.
Make the change stick
88%
of projects with excellent change management met or exceeded their objectives, compared with 13% of those with poor change management, in Prosci research with more than 2,600 change practitioners.
For a small organization, good change management is mostly plain communication:
- Explain why the change is happening and what it fixes for the people using it.
- Train before go-live, then again two to four weeks after, when people have real questions.
- Name a go-to person in each department.
- Hand out short reference guides for the five tasks people do most.
- Retire the old way on a set date so nobody runs two systems indefinitely.
The same applies to AI tools. Tell people which ones are approved and what data stays out of them, as our post on shadow AI explains.
Training that compliance rules require
The HIPAA Security Rule requires covered entities and business associates to run a security awareness and training program for all workforce members, including management. The FTC Safeguards Rule requires covered financial businesses, including many tax preparers, accountants and lenders, to give staff security awareness training that is updated as the risks in their risk assessment change. Attorneys have a duty to make reasonable efforts to protect client information, and the staff who handle it are part of how a firm meets that duty.
Keep records of who was trained, on what and when. Auditors, insurers and regulators will ask. Our compliance services page covers how training fits into a written security program.
Bring the last rollout your staff still work around. Book an intro call and we’ll help you sort out where training would pay off first, as part of our managed IT services.
FAQ
Frequently asked questions
Why is IT training important for employees?
People who haven’t been shown how a tool fits their work go back to the old way, build workarounds or move files into personal apps you can’t see. Training is also a security control: Verizon’s 2026 Data Breach Investigations Report found the human element in 62% of breaches. HIPAA and the FTC Safeguards Rule both require security awareness training for staff.
How do I know if training is working?
Watch for fewer repeat help desk questions, more people reporting phishing simulations, and fewer workarounds such as personal file-sharing apps.
Sources: Verizon 2026 Data Breach Investigations Report; PhishingBox: Verizon 2026 DBIR human risk findings; Prosci: The correlation between change management and project success; eCFR: 45 CFR 164.308, HIPAA administrative safeguards; eCFR: 16 CFR 314.4, FTC Safeguards Rule elements; Microsoft Learn: Training.




