What is Security awareness training?
Also known as: cybersecurity awareness training, SAT
Security awareness training is regular training that teaches employees to recognise phishing, social engineering and other threats and to respond correctly. The modern approach combines short courses, phishing simulations and measured results.
A once-a-year lecture does not change behaviour. An effective programme is continuous: short courses, simulations, follow-up training for whoever slipped, and a report for management. Awareness training is required directly by ISO 27001 (control A.6.3), NIS2 and DORA.
How to spot it
- Training that exists only on paper
- Nobody knows how many employees would click a phishing link
What to do
- Start with a baseline phishing test
- Assign short, regular courses
- Measure results by department
Related courses
- Identifying phishingThe phishing foundation course: how to spot a fake email, sender and link, and what to do when something looks off.
- Social engineeringSocial engineering techniques and defence: verifying calls, emails and identities, and checking links.
- Cybersecurity myths"Nobody wants my data", "the technology will protect me", "it won't happen to me": three myths that put companies at risk.
- Information security policiesPolicy types, passwords, data, devices, procedures, documentation, monitoring and review.
Terms on this topic
More topics
Start with your team's risk baseline
15-30 employees, one phishing simulation and a one-page report for management. No annual commitment.