The financial gains associated with ransomware have made it a popular and serious cybersecurity threat, while organizations may have become more vulnerable to this type of attack due to their dependence on digital infrastructure. Ransomware’s association with phishing as a commonly used attack vector, which may require organizations to consider employee awareness training alongside technical security measures. Small and medium-sized enterprises (SMEs) can be more vulnerable to ransomware because of resource constraints and limited cybersecurity knowledge. That is why this thesis aims to investigate how cybersecurity awareness training can help SMEs in Europe to support employees in identifying and responding to phishing attempts in the context of ransomware risk. This was done through a systematic literature review, where previous research was retrieved from five different databases. This was done with a specified search term to find articles used to answer this thesis research question. The literature selection process resulted in 35 articles being included in the final review and analyzed with thematic coding. Findings from the analysis suggest that cybersecurity awareness training may help SMEs to support employees to identify and respond to phishing attempts. However, the findings suggest that awareness training may be more useful for SMEs when it is practical, continuous, and connected to employees’ daily tasks, reporting procedures, and incident response routines.