1.12 Security Awareness & Training
Security Awareness & Training at a glance
Security technology alone cannot protect an organisation. People make security decisions every day — opening emails, handling information, approving payments, using passwords, reporting incidents and operating critical systems.
A security awareness, education and training programme helps people understand security risks, develop appropriate skills and make safer decisions as part of their everyday work.
Awareness
Keep security risks and responsibilities visible.
What should I KNOW?Training
Develop practical security skills for particular activities.
What should I DO?Education
Develop deeper understanding and professional knowledge.
WHY does it work?Why security awareness matters
Many security controls depend on people behaving appropriately.
Employees may encounter:
An organisation deploys sophisticated email filtering.
A convincing phishing message still reaches an employee and asks them to approve a fraudulent payment.
Technology reduces the risk, but the employee's ability to recognise and report the attack remains important.A mature programme aims to influence real behaviour and create a culture where people understand their security responsibilities and know how to act when something suspicious occurs.
1 Awareness vs Training vs Education Three related but different learning goals
Security Awareness
Awareness focuses attention on security and helps people recognise important risks and responsibilities.
A short campaign reminds employees how to recognise suspicious QR codes and where to report them.
Security Training
Training develops practical knowledge and skills needed to perform security-related tasks correctly.
Service-desk staff learn how to verify a caller's identity before resetting an account.
Security Education
Education develops broader and deeper understanding that may support professional judgement, analysis and future security responsibilities.
A security architect studies cryptography, risk management and secure architecture so they can evaluate different design approaches.
Easy distinction
Know it. Do it. Understand it.
Security Learning Programme lifecycle
2 Building the Programme Start with risk and learning needs
Security learning should reflect the organisation's actual risks, technologies, workforce and operating environment.
Useful inputs include:
An organisation experiences several incidents involving employees entering credentials into fake Microsoft 365 login pages.
Rather than adding another generic annual security module, the organisation creates targeted learning around authentication phishing, browser indicators and reporting.
Training is addressing an observed organisational risk.Security training should help reduce relevant organisational risk rather than existing only to satisfy a compliance checkbox.
3 Understand the Audience Different roles face different risks
Not everyone in an organisation requires exactly the same security training.
Basic security awareness, phishing, information handling, incident reporting and acceptable use.
Secure coding, software supply chain, secrets management and application-security practices.
Privileged access, secure configuration, logging and operational security.
Fraud, payment manipulation, business-email compromise and verification procedures.
Targeted social engineering, organisational risk, crisis response and high-value information.
Advanced technical, governance, risk and incident-response skills.
Personal data, insider-risk indicators and personnel-security processes.
Relevant organisational security policies and access responsibilities.
General awareness provides a security foundation, while role-based training addresses risks specific to someone's responsibilities.
📅 When should training occur? Learning should not happen only once a year
Establish security expectations when people join.
Refresh important knowledge and introduce updated risks.
Provide training when responsibilities or privileges change.
Explain security implications of new systems and services.
Use lessons learned to address identified knowledge gaps.
Provide timely awareness when new attack techniques become relevant.
The organisation introduces generative AI tools for employees.
Rather than waiting until the next annual training cycle, employees receive targeted guidance about confidential data, approved services and appropriate AI use before rollout.
4 Awareness and Training Methods Use multiple ways to reinforce security
Security awareness does not need to rely entirely on long online courses.
Organisations can use multiple techniques:
A five-minute reminder may be useful for awareness.
A developer learning secure coding may require detailed practical training instead.
5 Social Engineering Awareness Attack the human rather than the technology
What is social engineering?
Social engineering uses deception or manipulation to persuade someone to disclose information, provide access or perform an action that benefits the attacker.
Fraudulent messages attempt to make recipients reveal information or perform unsafe actions.
More targeted phishing designed for a particular individual or group.
Social engineering performed through voice calls.
Phishing delivered through SMS or messaging.
The attacker invents a believable scenario to obtain information or action.
Pretending to be a trusted employee, supplier or authority.
Offering something attractive to encourage unsafe behaviour.
Following an authorised person into a restricted physical area.
Attackers may exploit urgency, fear, authority, curiosity, helpfulness or familiarity rather than a software vulnerability.
🚩 Social Engineering warning signs Help users recognise suspicious situations
"Do this immediately or your account will be disabled."
"The CEO needs this payment approved now."
"Don't tell anyone else about this request."
"Verify your password using this link."
A document arrives without expected context.
Bank details unexpectedly change.
Someone asks you to ignore normal verification procedures.
Employees should know exactly how to verify suspicious requests and where to report them.
6 Phishing Awareness and Simulations Practice recognising realistic attacks
Simulated phishing campaigns can provide employees with practical experience recognising suspicious messages in a controlled environment.
A useful programme may assess:
Employees receive a simulated message claiming that their cloud account will expire unless they log in immediately.
Employees who identify the message can report it using the organisation's normal phishing-reporting process.
A phishing click rate can provide useful information, but the organisation should consider context, scenario difficulty, reporting behaviour and longer-term trends when evaluating effectiveness.
📣 Build a Reporting Culture People should know how — and feel able — to report
Awareness should make reporting security concerns simple and familiar.
Employees may need to report:
An employee accidentally enters their password into a phishing page.
They realise the mistake thirty seconds later.
Rapid reporting allows security teams to reset credentials, invalidate sessions and investigate the attack quickly.Training should tell people what to do after a mistake, not only how to avoid making one.
7 Security Champions Extend security knowledge into the wider organisation
Security champions are individuals outside the central security team who help promote good security practices within their own teams or communities.
A security champion might:
- share relevant security information;
- encourage secure practices;
- help colleagues find security guidance;
- raise security questions during projects;
- help connect teams with security specialists;
- promote awareness campaigns;
- provide feedback about local security challenges.
Each software-development squad has a developer who receives additional application-security training and acts as a security champion.
The champion helps bring security thinking into day-to-day development discussions.
They help distribute security awareness and create stronger links between specialist security teams and the wider organisation.
8 Gamification Make learning more engaging
Gamification introduces game-like elements into security learning to increase participation and engagement.
Development teams compete in a secure-coding challenge where they identify vulnerabilities in a deliberately insecure application.
Participants earn points for identifying and correctly explaining each vulnerability.
The game should support useful learning and behaviour rather than becoming an activity that people complete without understanding the security lesson.
🌱 Security Culture Move from rules toward everyday behaviour
A strong security culture exists when secure behaviour becomes a normal part of how people work rather than something considered only during annual training.
Managers demonstrate that security is genuinely important.
People understand what is expected of them.
Security advice is easy to find and understand.
People report suspicious activity quickly.
Secure behaviour is made easy rather than unnecessarily difficult.
Relevant security learning occurs throughout the year.
In one organisation, an employee receiving a suspicious request thinks: "Security isn't my job."
In another, the employee thinks: "This doesn't look right — I'll report it."
Awareness programmes should help move organisations toward the second behaviour.9 Emerging Technology and Trends Training content must evolve
Security awareness content should be periodically reviewed as technology and attacker techniques change.
The current CISSP outline specifically highlights areas such as:
🤖 Artificial Intelligence
Employees may need guidance on appropriate use of generative AI services.
Topics might include:
- handling confidential information;
- approved and unapproved AI services;
- verification of AI-generated output;
- AI-assisted phishing and impersonation;
- deepfake or synthetic-media awareness;
- organisation-specific AI policies.
₿ Cryptocurrency
Relevant awareness topics may include cryptocurrency-related fraud, ransomware payment demands, wallet scams and social-engineering campaigns.
⛓️ Blockchain
Where blockchain technologies are used, relevant personnel may need to understand associated security responsibilities such as protecting keys and recognising fraudulent transactions or services.
A security awareness programme should evolve as the organisation's technologies, risks and attacker techniques change.
🎭 Modern Impersonation and Deepfakes Old social-engineering principles with new technology
New technologies can make traditional social engineering more convincing.
A finance employee receives a voice message that appears to come from a senior executive requesting an urgent transfer.
The voice may sound completely genuine.
Employees should rely on approved verification processes rather than trusting a request simply because a voice, image or message appears authentic.Verify sensitive requests using trusted processes and independent channels.
📜 Training should support policy People need to understand organisational requirements
Security awareness helps turn written policies into practical behaviour.
How organisational technology may be used.
How sensitive data should be protected.
How authentication requirements should be followed.
When and how security events should be reported.
Security expectations outside normal offices.
Which AI tools and information-handling practices are permitted.
Awareness and training help them understand what the rule means in practical situations.
👍 Make secure behaviour easier Training cannot fix unusable security processes
If organisational security procedures are unnecessarily difficult, people may look for shortcuts.
Employees are told never to use consumer file-sharing services.
However, the organisation provides no approved method for sending large files to customers.
Awareness alone is unlikely to solve the problem. Employees also need a practical secure alternative.Security education should support effective controls, not compensate indefinitely for badly designed processes.
10 Evaluate Programme Effectiveness Did the learning actually work?
The current CISSP objective explicitly requires understanding programme effectiveness evaluation.
Organisations therefore need to measure more than whether employees clicked "Complete".
Possible measurements include:
Did the intended audience complete required learning?
Can learners demonstrate understanding?
Has real security behaviour changed?
Are suspicious events being reported appropriately?
Are relevant human-related incidents changing over time?
Can personnel perform security-sensitive responsibilities correctly?
📊 Useful Security Awareness Metrics Measure outcomes, not just activity
"99% of employees completed annual security training."
"Employees correctly answered 90% of questions relating to confidential-data handling."
"The proportion of simulated phishing messages reported by employees increased over successive campaigns."
"Incidents caused by users entering credentials into phishing sites declined following targeted authentication-phishing training."
High completion proves that training was delivered.
It does not by itself prove that people learned anything or changed their behaviour.
🎣 Interpreting Phishing Metrics Context matters
Phishing simulation results can provide useful information, but a single click rate should not automatically be treated as the complete measure of security awareness.
Consider:
Campaign A has a 5% click rate.
Campaign B has a 15% click rate.
It would be tempting to conclude immediately that security awareness became worse.
But Campaign B may have been significantly more convincing than Campaign A, so scenario difficulty should also be considered.Awareness improvement cycle
11 Periodic Content Review Keep the programme relevant
Training content should be reviewed periodically and when significant changes occur.
Review triggers may include:
Attackers begin using new techniques.
Employees begin using different systems or services.
Events reveal gaps in knowledge or behaviour.
Organisational expectations change.
New obligations require different behaviour.
Metrics show particular topics require more attention.
Annual awareness training still focuses heavily on avoiding unknown USB drives but contains nothing about cloud sharing, MFA phishing, QR-code phishing or generative AI.
The programme may no longer reflect how employees actually work or how modern attacks occur.🚨 Learn from Security Incidents Incidents reveal real learning needs
Incident investigations can identify weaknesses in awareness, procedures or role-specific training.
Several help-desk employees reset accounts after attackers provide convincing but fraudulent identity information.
Investigation finds that the existing verification procedure is poorly understood.
Targeted help-desk training and improvements to the verification process may both be required.An incident may expose weaknesses in training, processes, technology or organisational design.
👔 Leadership and Management Security culture needs visible support
Management behaviour influences whether employees treat security requirements seriously.
Employees are told never to share passwords.
Their manager then asks the team to share one account because creating individual accounts would take too long.
Leadership behaviour has undermined the security message.Leadership can support awareness by:
- following security policies themselves;
- supporting training participation;
- encouraging incident reporting;
- supporting security champions;
- providing time and resources for learning;
- reinforcing that security supports business objectives.
🛡️ Training as a Security Control Useful, but not the answer to everything
Awareness and training can reduce risk, but organisations should not use training as a substitute for technical controls that can reasonably prevent a problem.
"Train employees never to accidentally email confidential data to the wrong external recipient."
Provide data-handling training while also using access controls, recipient warnings, classification and DLP where appropriate.
Awareness should work alongside technical, administrative and physical controls.
⚠️ Common mistakes Awareness-programme assumptions that reduce effectiveness
Completion measures delivery, not necessarily knowledge, behaviour or risk reduction.
Effective awareness can use ongoing campaigns, simulations, champions, targeted learning and other methods throughout the year.
General awareness is useful, but people with specialist or privileged responsibilities often require role-based training.
Scenario difficulty, reporting behaviour and trends should also be considered.
The primary goal of simulated phishing should be improving behaviour and reducing risk rather than creating fear around training.
Secure behaviour depends on awareness, usable processes, appropriate technology and clear organisational expectations.
Technology, organisational processes and attack techniques evolve. Training content should therefore be reviewed.
Employees in many roles may interact with AI services or receive AI-assisted phishing, impersonation or fraudulent content.
Champions help promote security within other teams but do not replace specialist security expertise.
Where a risk can reasonably be prevented or reduced through technical or process controls, training should form part of a layered approach rather than becoming the only defence.
Think behaviour, risk and continuous improvement
CISSP questions in this area are likely to favour a structured, risk-based programme rather than treating security awareness as a once-a-year compliance exercise.
💡 Awareness clues
🛠️ Training clues
🎣 Social engineering clues
👥 Engagement clues
🔄 Review clues
📊 Effectiveness clues
📝 Practice scenarios Apply security-awareness thinking
Scenario 1
All employees have completed mandatory annual security training.
Phishing-related incidents continue increasing.
What should the organisation do?
Evaluate whether the training is producing the desired knowledge and behaviour, identify the underlying causes and adjust the programme.
Scenario 2
Developers receive the same general 20-minute security awareness course as every other employee.
Secure coding weaknesses are repeatedly discovered.
What is missing?
Appropriate role-based security training for developers.
Scenario 3
An employee receives a suspicious email appearing to come from the CEO and asking for an urgent payment.
What should awareness training encourage?
Recognise the social-engineering indicators, independently verify the request and report the suspicious message.
Scenario 4
A simulated phishing campaign has a much higher click rate than the previous campaign.
What should be considered before concluding that employees became worse at recognising phishing?
The relative difficulty and context of the different phishing scenarios.
Scenario 5
The organisation introduces generative AI tools for employees.
What should happen?
Security-learning content should be reviewed and updated to address relevant AI-related security and information-handling risks.
Scenario 6
Each development team has a developer who receives additional application-security learning and promotes secure practices within the team.
Which concept does this describe?
Security champions.
Scenario 7
Employees earn points and badges for completing interactive cybersecurity challenges.
Which awareness technique is being used?
Gamification.
Scenario 8
An employee clicks a phishing link and immediately realises the mistake.
What should the programme have taught them?
How to report the incident quickly so security teams can respond.
Scenario 9
Security training teaches employees not to use public file-sharing services, but the organisation provides no approved way to exchange large customer files.
What is the problem?
Training alone cannot compensate for the absence of a practical secure business process.
Scenario 10
Management asks for the best single measurement of awareness-programme effectiveness.
What should security explain?
Effectiveness is better evaluated using multiple measures of learning, behaviour, reporting, risk and trends rather than relying on one metric.
Scenario 11
A finance employee receives a convincing voice message from the CFO instructing them to transfer money to a new account.
What principle remains important even if the voice sounds authentic?
Independently verify sensitive requests using established trusted procedures.
Scenario 12
Training material still teaches threats from five years ago and has never been reviewed.
Which CISSP 1.12 requirement is missing?
Periodic content review to incorporate emerging technology, trends and changing risks.
Scenario 13
Security notices are written using highly technical language that non-technical employees do not understand.
What should improve?
Training and awareness should be designed for the intended audience.
Scenario 14
Phishing reports from employees increase substantially after a new awareness campaign.
Is this necessarily a bad result?
No. Increased reporting may indicate that employees are becoming better at recognising and reporting suspicious messages.
Security Awareness thinking flow
Quick memory aid
Know. Practice. Measure. Improve.
Social Engineering memory aid
Don't trust pressure. Verify the request.
Programme effectiveness memory aid
Completion is the beginning, not the result.
Key takeaways
Security awareness, training and education help people understand security risk and perform their responsibilities securely.
Awareness focuses attention on security issues and expected behaviour.
Training develops practical security skills.
Education develops deeper understanding and professional knowledge.
Security learning should reflect the organisation's actual risks, technologies, incidents and workforce.
Different roles require different levels and types of security learning.
Social-engineering awareness should help users recognise attacks such as phishing, impersonation and pretexting and know how to respond.
Phishing simulations can provide useful practical learning, but their results should be interpreted in context rather than relying only on a single click-rate metric.
Security champions can extend security knowledge and engagement into teams outside the central security function.
Gamification can increase engagement when game mechanics support genuine learning objectives.
Awareness content should be periodically reviewed to reflect changes in threats, business processes and technologies.
The current CISSP outline specifically highlights emerging areas such as artificial intelligence, cryptocurrency and blockchain.
Security programmes should evaluate effectiveness using relevant measures of knowledge, behaviour, reporting and risk.
Training completion alone does not demonstrate that behaviour changed.
Security awareness works best when secure behaviour is supported by usable processes and appropriate technical controls.
Incidents, assessments and programme metrics should feed back into future learning.
Most importantly: the goal is not to make people pass a training module — it is to help them make better security decisions when it actually matters.
Security and Risk Management
You have reached the end of CyberPrepHub's Security and Risk Management learning section.
Domain 1 connects security technology with ethics, governance, law, business continuity, people, risk and organisational decision-making.
Cybersecurity is not simply about choosing technical controls.
Effective security means understanding the organisation, its people, objectives, obligations and risks — and using that understanding to make informed security decisions.
📚 Sources & Further Reading Authoritative references
- ISC2 — CISSP Certification Exam Outline
View official CISSP exam outline - NIST SP 800-50 Rev. 1 — Building a Cybersecurity and Privacy Learning Program
View NIST learning-program guidance - NIST SP 800-171 Rev. 3 — Awareness and Training
View NIST publication - NIST — Phish Scale User Guide
View NIST phishing-awareness guidance - NIST — Awareness, Training & Education
View NIST awareness and training resources
