GlossarySecurity awareness

Security awareness training

Short answer

Security awareness training teaches employees to recognise and respond to threats such as phishing, social engineering and data handling mistakes, so that they act as a line of defence rather than an entry point. Effective programmes are continuous, practical and measured, not a single annual course.

What a good programme covers

Recognising phishing and spear phishing, verifying payment and access requests through a second channel to stop BEC, using a password manager and MFA, handling sensitive data, using AI tools safely, physical security and, above all, how and when to report something suspicious.

Phishing simulations

Simulated phishing emails show who clicks, who enters credentials and, most importantly, who reports. Used well, they are a learning tool with immediate feedback, not a way to catch people out. The reporting rate is often a better indicator than the click rate.

Making it stick

Short, frequent sessions work better than a long yearly course. Content adapted to each role (finance, IT administrators, executives, new joiners) is more relevant, and real examples from the company's own sector make it credible. Results should be tracked and reported to management.

Where it shows up in compliance

ISO 27001 requires information security awareness, education and training (Annex A 6.3), and the ENS and NIS2 include equivalent obligations. NIS2 also requires members of management bodies to receive cybersecurity training. Our article on security awareness under ISO 27001 explains what auditors look for.

Related terms

Keep reading on this topic

Turning employees into an active line of defence: awareness training, phishing simulation, device and identity hygiene, and SaaS access control.

Go to the topic hub