TechKnowSurge
NIST 800-53 AT-2 NIST 800-53 AT-3 NIST NICE K0638 ISC2 CC 2.3 CompTIA A+ Core 2 2.4 Cisco CCST IT 5.2 NIST NICE K1087
VideoSecurityFree

Administrative Controls - Security Awareness Training

Security awareness training ensures that organizational policies, standards, and procedures are understood and followed by the people responsible for them. Effective programs go beyond formal training to include simulations, communications, and ongoing testing that build real-world recognition of threats like social engineering and phishing.

Complete this video to capture a CTF flag worth 1 point.

About this video

A security awareness program begins with the recognition that publishing a policy is not the same as communicating it. Every person responsible for following organizational policies, standards, procedures, and guidelines must be made aware of them through deliberate, ongoing outreach. That outreach takes many forms — email notifications, employee handbooks, internal messaging platforms, team meetings, and, where necessary, direct one-on-one conversations with individuals who have repeatedly failed to comply. Gamification and contests can also be used to make the experience more engaging and improve retention across a broader workforce. Training and awareness are distinct concepts that work together but should not be conflated. Formal training is a foundational element of any awareness program, but completing a training module does not guarantee that an employee will recognize or respond correctly to a real threat. Awareness is built over time through repeated reinforcement across multiple touchpoints. The topics covered in a program should be driven by a combination of internal policy changes and external threat intelligence, including news sources, vulnerability reports, and guidance from cybersecurity organizations. Social engineering consistently emerges as a priority area, and effective training goes beyond cataloging specific attack types to build situational awareness — helping employees recognize the psychological tactics attackers use, such as manufactured urgency and impersonation of authority figures. Phishing simulation campaigns are one of the most widely used tools for measuring whether awareness efforts are working. After training employees to identify phishing emails, organizations send controlled test messages designed to mimic real attacks and track which employees click links, submit information, or otherwise fall for the simulation. Those results identify individuals who need follow-up and reveal gaps in the training content itself. This testing-and-refinement cycle is what transforms a one-time training event into a sustained, adaptive security awareness program with a measurable impact on organizational risk.

What you'll learn

What's covered

Security Awareness & Training

Aligned to

NIST 800-53
AT-2 Literacy Training and Awareness
AT-3 Role-Based Training
NIST NICE
K0638 Knowledge of security awareness programs
K1087 Knowledge of social engineering tools and techniques
ISC2 CC
2.3 Understand security awareness
CompTIA A+ Core 2
2.4 Explain common social-engineering attacks, threats, and vulnerabilities
Cisco CCST IT
5.2 Recognize how to avoid becoming a victim of social engineering attacks

Key terms

Security Policy
A formal document that defines an organization's security goals, rules, and responsibilities.
Social Engineering
A manipulation technique that exploits human psychology to trick individuals into revealing confidential information.
Phishing
A social engineering attack that uses deceptive emails or messages to trick users into revealing sensitive information.
Spear Phishing
A targeted phishing attack directed at a specific individual or organization using personalized information.
Security Awareness
The ongoing effort to ensure employees understand security policies, recognize threats, and apply safe behaviors through multiple communication methods beyond formal training alone.
Simulated Phishing Campaign
A controlled test in which an organization sends fake phishing emails to employees to assess and reinforce their ability to recognize and report phishing attempts.
Anomalous Behavior
Activity that deviates from normal or expected patterns and may indicate a social engineering attempt or security threat.

Topics

Security Awareness Training Social Engineering Phishing Simulation Administrative Controls End User Security Cybersecurity

Transcript

Why awareness matters

Imagine if I created a policy for my organization and then never told anybody — it just sat there in paper form, it never got out to everybody who is in charge of whatever that policy is about. Well, if I did that, then no one would really know what it is, and it really is ineffective. So making people aware of that document is going to be extremely important. Making people aware of those policies is extremely important, and it's a huge component to making sure that these policies are even successful as we roll them out.

If we expect somebody to follow our policies, standards, procedures and guidelines, they need to be aware of them, so we need to make sure that that's communicated. How do we communicate that, and what does that look like? A big step in a security program is making sure that people are aware of those policies and procedures, and then holding them accountable after we've rolled something out, after we've made some changes, after we've put these policies into place.

Training and awareness are not the same thing

One thing to realize is that training and awareness are two different concepts. We can do training, but that doesn't necessarily create awareness. Training is a huge part, which is why we separate it out, and it creates awareness. But just because you train somebody doesn't mean that they are suddenly aware.

For instance, as you go through training and as you are listening to videos, or maybe you're doing some sort of activities, do you 100% pick it all up? And if you pick up 100% of it, do you even implement 100% of that? The fact is that no, that's not the case. We go through something like phishing training to identify phishing emails, and then I do some tests with my users and they still fall for phishing emails. So this can be problematic: just because you do training doesn't mean that you've created awareness — although training is a huge step in creating awareness.

So how else do we create awareness? I mentioned training. We could send out emails. We could have meetings about these things. We could have employee handbooks that have this all written out. I like to run things like contests and gamification to make it a fun experience. We can run simulations. We can just communicate policies, or have them sign policies. There are messaging platforms we can send it out on. We can have inme persons, especially if somebody continues to step over the line, which I've had before, and I've had to go to them and train them specifically or direct them specifically. So all of these activities would fall under this awareness, not just training, although it's a huge component; all of these would work together to make sure that people are aware of what needs to happen.

Choosing the topics

So how do we come up with the topics that we are going to make people aware of? Number one is just when we make policy changes, we need to communicate that out. But there are also a lot of hot topics out there that we need to make sure our users are trained on, to identify things like social engineering attacks. So we're going to look at news articles, blog posts, top vulnerability reports, training materials, cyber security organizations. We're going to look at all those and see what the top concerns are, especially around social engineering. That way we're going to form the content of our training, and then that develops into the awareness for our employees and for our internal users.

Social engineering and situational awareness

Like I mentioned, the big one here is going to be social engineering, teaching them how to identify social engineering. A lot of times we get into the very specifics of "here is what an attack would look like." But the problem is that if they are just looking at specific attacks that are prevalent out there — which we need to do — we also need to get them to look at the big picture of what is it that you're going to see out there. Things like how a scammer will get into their minds.

So we need to create situational awareness, so that they understand that this is how a scammer is going to make you feel. They're going to create a sense of urgency that you have to do something, and maybe they do it through something like imitation. They're going to imitate your boss, and your boss has a certain authority over you, so they are now imitating an authority figure and you're going to feel compelled to do whatever it is that they're going to do. So if you are a person in the company and you're experiencing, "why is the CEO reaching out to me via text message? He's never done that before and that doesn't really make sense," then you should question it — this is probably a scammer. And I've had people fall for those types of things before.

So, creating situational awareness. Anomalous behavior recognition — things that are just out of the ordinary, like I had mentioned, the text message from the CEO would be suspicious activity. Or malicious and compromised content, identifying sites that we shouldn't visit or emails that are being sent to us. We need to have them be able to identify those things in order to combat the social engineering.

A big one is going to be phishing campaigns: people being able to recognize that there are phishing emails out there, and then be able to report those phishing emails. That's a huge one that we see consistently come up as something that you need to have in your security awareness training.

Develop, deliver, test

There's a whole process here. We're going to develop the training, we're going to deliver the training, and then we need to go into tests.

I mentioned a couple of times doing phishing campaigns. What I mean by that is that after I would train the users of my systems to identify phishing emails, then I would send out phishing tests — things that look like they were coming from maybe HR or somebody within the company, but it was really coming from me. Trying to trick them to click on the link, or try to fill out information, or reply to the email, or whatever the case may be. And when they fall for those tricks, then I can record which users have fallen for those tricks, and then do some sort of follow-up and make sure that they are aware of what they did and what needs to change.

So I'm going to be testing my users to make sure that they are aware, and monitoring this. There are systems that allow you to do this testing and monitoring, and then I can either go to them directly or further develop my training to make sure that we're teaching them in the right areas. So there's a whole training life cycle as well when we are delivering training and awareness.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →