TechKnowSurge
NIST 800-53 AT-2 CompTIA Security+ 5.6 ISC2 CISSP 1.12 NIST NICE K0638 EC-Council CEH 4.2 CompTIA Security+ 2.2 NIST NICE K1087 NIST NICE K0658
VideoSecurityFree

Security Training Content

Security awareness training content should be driven by current threat intelligence and risk levels, covering topics like social engineering, phishing recognition, password management, and insider threats.

Complete this video to capture a CTF flag worth 1 point.

About this video

Developing security awareness training requires an ongoing research process to ensure content reflects the most current and relevant threats facing an organization. Training topics should be selected based on risk level, informed by sources such as industry news, vulnerability databases, and guidance from established cybersecurity organizations. Because the threat landscape shifts over time, training content must be regularly revisited and updated to address emerging risks rather than relying on a static curriculum. Social engineering represents one of the highest-priority areas for employee training, given how frequently attackers exploit human behavior rather than technical vulnerabilities. Employees need to understand how social engineering works — particularly the use of emotional manipulation, such as manufactured urgency, to pressure individuals into divulging sensitive information or taking harmful actions. Building situational awareness is central to this training, helping employees recognize anomalous behavior that falls outside normal patterns and respond appropriately, including reporting suspected incidents to IT or through dedicated reporting tools. Beyond social engineering and phishing, a comprehensive program covers a range of additional topics: identifying and handling insider threats, managing passwords securely through password managers, understanding the risks associated with removable media and external devices, adhering to operational security procedures, and navigating the specific security considerations of hybrid and remote work environments.

What you'll learn

What's covered

Security Awareness Training

Aligned to

NIST 800-53
AT-2 Literacy Training and Awareness
CompTIA Security+
5.6 Given a scenario, implement security awareness practices.
2.2 Explain common threat vectors and attack surfaces.
ISC2 CISSP
1.12 Establish and maintain a security awareness, education, and training program
NIST NICE
K0638 Knowledge of security awareness programs
K1087 Knowledge of social engineering tools and techniques
K0658 Knowledge of cognitive biases
EC-Council CEH
4.2 Social Engineering

Key terms

Social Engineering
A manipulation technique that exploits human psychology to trick individuals into revealing confidential information.
Phishing
A social engineering attack that uses deceptive emails or messages to trick users into revealing sensitive information.
Anomalous Behavior
Activity that deviates from normal or expected patterns and may indicate a social engineering attempt or security threat.
Insider Threat
A security risk that originates from individuals who have authorized access to an organization's systems — such as employees, contractors, or partners — and misuse that access either maliciously or through negligence.
Password Management
The practice of securely creating, storing, and maintaining passwords, often assisted by a dedicated password manager tool.
Removable Media
Portable storage devices such as USB flash drives, SD cards, and optical discs that can be detached from a computer and used to transport, distribute, or back up data.

Topics

Security Awareness Training Social Engineering Phishing Recognition Insider Threats Password Management Threat Intelligence Cybersecurity

Transcript

If we're developing content for security awareness and training, what is it that we're going to include in this training?

Developing the Training

One of the first steps in this process is that we need to develop our training. Ultimately, a lot of these topics are going to be whatever the hottest topics are of the time, and so we're going to have to do some research to figure out what it is that we need to really watch out for. What are our risk levels, and deliver training based off of those risk levels and whatever is the highest risk at that time.

So we're going to take a look at things like news articles and blog posts, top vulnerability lists, training material that others have, and cyber security organizations out there that post this type of information. We're going to see what exactly are the hot topics and what is the content we should be delivering.

Social Engineering

One of the main topics is going to be around social engineering. It's one of the biggest risks when it comes to our employees: somebody using social engineering to trick the employees into divulging some sort of information or doing something nefarious.

What we need to do is teach our employees about situational awareness, how they can identify that somebody is trying to use social engineering. So we're going to show different techniques, and really drive home the point that a lot of social engineering is going to be to evoke some sort of emotion, something like urgency. They're going to evoke some sort of urgency for them to perform something or do something, and that is the type of behavior that they're going to look out for.

We call it anomalous behavior, so we're looking for that anomalous behavior, things that are out of the ordinary — things that seem risky or unexpected or unintentional, things that they don't usually encounter. If they do encounter it, there should be a little warning bells going off.

Phishing

A lot of social engineering comes through phishing and emails, so recognizing phishing emails and what those look like, and being able to identify them so they can ignore them or report them. A lot of companies are going to ask you to report them, either reporting them to your IT department, or maybe a lot of systems will have a little phishing button that you click on to report spam and also these phishing emails.

Other Topics

Other topics could include:

  • How to identify insider threats and what to do about insider threats.
  • How to manage passwords and how to use password management.
  • Removable media and cables: what you're connecting to your device and what that looks like, and being able to identify issues with things that you're connecting there.
  • Operational security: maybe you're changing your procedures and your policies, and now you need to train people on how to do that.
  • Hybrid and remote work, and how to deal with that.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →