TechKnowSurge
NIST 800-53 AT-2 NIST CSF PR.AT-01 ISC2 CISSP 1.12 CompTIA Security+ 5.6 NIST 800-53 AT-3 NIST CSF PR.AT-02 NIST NICE K0638 NIST NICE S0379
VideoSecurityFree

Training

Security awareness training is a foundational component of any organizational security program, covering who needs training, when it should occur, and how to develop, deliver, test, and monitor it effectively. Understanding the full training lifecycle helps organizations reduce risk and maintain compliance across their workforce.

Complete this video to capture a CTF flag worth 1 point.

About this video

Security awareness training is a cornerstone of organizational security, designed to ensure that everyone who works within or alongside a company understands core security principles and can apply them in their daily roles. The scope of training extends beyond full-time employees to include contractors and vendors, with security training requirements often written directly into third-party contracts to ensure consistent standards across all relationships. The training audience and its obligations may vary depending on the nature of each working relationship, but the goal remains the same: building and sustaining a culture of security awareness throughout the organization. Training is not a one-time event. It begins at onboarding and continues through recurring sessions — monthly, quarterly, or annual — with some organizations opting for a continuous model that delivers information steadily throughout the year. Ad hoc training fills the gaps when specific circumstances arise, such as onboarding a new client with unique security requirements or responding to an emerging threat. Ongoing training is necessary because the threat landscape evolves, internal policies change, and people require regular reinforcement to retain and correctly apply what they have learned. The training process follows a structured lifecycle: content is developed, delivered to the appropriate audience, tested for comprehension and behavioral follow-through, and then monitored for sustained effectiveness. Every stage of this process should be tracked meticulously, as that documentation becomes essential evidence during audits and compliance reviews. Reporting drawn from tracking data allows security leaders to demonstrate program activity and outcomes to stakeholders across the organization. Training assignments are not always uniform — some content is mandatory for all staff, while role-based risk profiles and individual assessment results determine who receives specialized or remedial training, ensuring that higher-risk positions and underperforming employees receive the additional attention their situations require.

What you'll learn

What's covered

Security Awareness Training

Aligned to

NIST 800-53
AT-2 Literacy Training and Awareness
AT-3 Role-Based Training
NIST CSF
PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind.
PR.AT-02 Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind.
ISC2 CISSP
1.12 Establish and maintain a security awareness, education, and training program
CompTIA Security+
5.6 Given a scenario, implement security awareness practices.
NIST NICE
K0638 Knowledge of security awareness programs
S0379 Skill in verifying participation in a security awareness program

Key terms

Security Policy
A formal document that defines an organization's security goals, rules, and responsibilities.
Risk
The potential for loss or harm resulting from a threat exploiting a vulnerability.
Role-Based Access Control
RBAC
An access control model that assigns permissions based on a user's role within an organization.
Security Awareness Training
An ongoing program that educates employees about cybersecurity threats, safe practices, and organizational policies to reduce human-based risk. Effective training covers topics like phishing recognition, password hygiene, and social engineering.
Onboarding Training
Initial security training delivered to employees when they first join an organization to establish a baseline of security awareness.
Recurring Training
Scheduled security training conducted on a regular basis—monthly, quarterly, or annually—to reinforce security knowledge and address new threats or policies.
Ad Hoc Training
Unscheduled, event-driven training delivered in response to a specific emerging need, new client requirement, or security topic.

Topics

Security Awareness Training Cybersecurity Risk Management Compliance Workforce Security Role Based Training

Transcript

One of the best ways we can promote security awareness is through security training.

Who Gets Trained

Creating security awareness for the people of an organization is one of the most critical parts of a security program and security operations, and one of the best ways to do that is through training.

So then the question is, who do we want to do this training? It's really anybody within our organization, or working with our organization, that we want to be up to speed and understand what security principles are, and to create that security awareness.

A lot of times, if we're using some sort of vendor, we're not necessarily going to require them to go through our security training, but we are hoping that they have their own security training. In fact, we probably write that into the contract, that requires them to go through some sort of type of training to be a part of that. And then other contractors that you work with, if they're individuals, it might just depend on what that relationship is and what it looks like as to whether you're going to require them to do this or not.

When Training Happens

When should we do this training? Anytime you have an employee you should be doing some sort of ongoing training with them. There's going to be one when they're onboarded — you're going to do some sort of initial training with them — but then there's going to be some sort of recurring training. That recurring training might happen on a monthly basis, or might happen on a quarterly basis, or a yearly, annual basis. So you're going to have to have some sort of training.

There are also some departments, some organizations, that will do continuous training, making sure that they're trickling in information throughout the whole year. So that could be something that you do as well.

And then there's also ad hoc training, just when something comes up. Maybe you bring on a new client and they require you to train on some new security concept or something. Ad hoc just means that you're going to do this one-time training, setting it up and making it happen for a specific topic at the time.

Why Ongoing Training Matters

There are a few reasons why we really should have ongoing training.

  • Number one is because there are new threats that are coming out, new things that we should train people on.
  • We might also be creating some new policies, and we need to keep people up to speed on what those are.
  • There's also this reinforcement that's happening. Unfortunately we don't always remember things, so we either forget things or we don't quite recall things the way we should even to begin with, and so we need continuous reinforcement for some of these topics in order to make sure that we maintain that level of awareness that we want to create for the company.

The Training Process

What does this training process look like? What you're going to do is develop training, you're going to deliver it, you're going to test to make sure that people are following through with this training — and there are several different ways we could test for this — and then we're going to monitor to make sure that we are successful.

During this whole process we're going to want to track the information. We're going to want to track what it is that we're developing or what we're delivering, we're going to want to track who shows up, and we're going to want to track the test and monitoring part of this. That's also an important part especially when it comes to audits, to show that we do in fact have the security awareness and training in place. Based off of that tracking, we're probably going to have to pull reports. There's going to be reports throughout here that we might have to pull to give to certain people.

Assigning Different Training to Different People

Not everybody's necessarily going to go through the same training. There is going to be some training that you're going to want everybody in your company to take, but there's going to be other training that you might assign. You might assign it because of the particular role that they have — they have a certain role that maybe is riskier, so maybe it's based off of risk level. Or perhaps you have some people within your company that seem to be failing the test, and you're going to give them some reoccurring training because of their failures. There are different things that we'll identify within the company as to why we give somebody certain training and not others within the company.

An Example: Moving to a Remote Workforce

Just as an example, let's say that our company is transitioning from being in person — we have an office that people report into — to being more of a remote workforce. By making that transition we adopt some risk, we take on some risk. So this would be a good time to develop some training around this work from home and how to reduce risk. We would deliver that training to everyone, we would test them on this to make sure that they understand the material, and we would monitor to see if they're following through with what we've tested them on.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →