Security Awareness Training

Security awareness training cycle and compliance evidence explained

Security awareness training is the control that treats people as part of the system, and it is the one most often reduced to a video nobody watched and a certificate nobody read.

  • Glossary
  • Compliance

The short answer

Security awareness training is a recurring programme that teaches staff to recognise and report the attacks aimed at them, then measures whether it worked. Every major framework requires it, usually at onboarding and at least annually. What auditors sample is not the course content but the completion records, the reminder trail for people who did not finish, and evidence that the programme was reviewed.

The reason it stays on every framework is uncomfortable but simple. Most breaches start with someone being asked to do something reasonable-looking by someone who is not who they claim to be. No technical control removes that entirely.

The security awareness training cycle

Security awareness training runs as five stages on a repeating schedule. Teams that stop after stage two have a training record. Teams that run all five have a control.

1. Baseline Measure before you teach anything 2. Train Role-relevant, short, recorded 3. Simulate Test behaviour, not recall 4. Remediate Follow up with who needs it 5. Evidence Records the auditor samples Repeats at onboarding and at least annually, plus after any significant change. Stage 1 is the one people skip. Without a baseline there is no way to show the programme changed anything.

What security awareness training must cover

TopicWhy it earns a place
Phishing and social engineeringThe starting point for most intrusions, and the only topic worth testing rather than just teaching
Business email compromisePayment and payroll redirection requests that carry no malware and pass every email filter
Credentials and MFAPassword reuse and MFA fatigue prompts, which is how a stolen credential becomes a session
Data handlingWhat counts as sensitive, where it may go, and how data loss usually happens by accident
Device and physical securityScreen locking, unmanaged devices, and the risk in working from shared spaces
ReportingHow to raise a suspicion in seconds, which is the behaviour that shortens incident response more than any other
Role-specific contentSecure coding for engineers, payment verification for finance, and privacy obligations for anyone handling personal data

Where frameworks require security awareness training

FrameworkStatusWhat it expects
SOC 2RequiredCommitment to competence and internal communication of security responsibilities, evidenced across the observation window
ISO 27001RequiredAn Annex A control covering awareness, education and training, plus competence evidence in the management system
PCI DSSRequiredSecurity awareness training at hire and at least annually, with acknowledgement from personnel
HIPAARequiredA security awareness and training programme for all workforce members, including periodic reminders
DPDP ActImpliedReasonable security safeguards, which in practice includes staff who understand their obligations for personal data
RBI and SEBI frameworksRequiredPeriodic awareness programmes for staff, with board-level visibility of the arrangement for regulated entities

The wording differs. The expectation does not: everyone gets trained on joining, everyone gets trained again each year, and you can prove both.

What auditors ask for

ArtefactWhat it has to show
Completion recordsNamed individuals, dates, and the version of the content they took
Coverage against headcountThe training list reconciled to the current staff list, including contractors
Onboarding trailTraining completed within a defined window of a start date, sampled against recent joiners
Reminder and escalation recordsWhat happened to people who did not complete it, which is where most programmes come apart
Simulation resultsClick and report rates over time, plus what followed for repeat clickers
Content reviewEvidence that the material was reviewed and updated, not carried over untouched for three years

The sample is always the leavers and joiners

Auditors rarely check the whole population. They take a handful of recent starters and ask when each completed training, and they take the completion report and reconcile it against headcount. A programme at 88 percent completion with no record of chasing the missing 12 percent is a finding, even when the content is excellent.

Why security awareness training fails

FailureWhat it looks like
Annual and forgottenOne long module in January, no reinforcement, no measurement of whether behaviour changed
Generic contentThe same module for engineers, finance and support, so nobody sees their own risk in it
Punitive simulationsNaming people who clicked, which reliably stops reporting and makes the next real incident slower to surface
No contractor coverageThird parties with system access left out of the training list entirely
Records in three placesA learning tool, a spreadsheet and an email thread, so reconstructing evidence takes days
No reporting channelStaff taught to spot phishing with no obvious way to report it in under thirty seconds

How Osto runs security awareness training

Security awareness training runs inside the platform rather than in a separate learning tool, which matters mainly for the evidence. Completion records sit alongside the rest of the control evidence and map to SOC 2, ISO 27001, PCI DSS, HIPAA and the DPDP Act from one place, so nobody is exporting spreadsheets the week before an audit.

Training also sits next to the controls it talks about. Inbound email security filters what it can, MFA and access management limit what a successful lure achieves, and the training covers the gap that neither one closes. That combination is what the GRC evidence base has to show: a technical control, a human control, and a record of both.

Platform walkthrough

Training that produces evidence

Awareness training runs in the same platform as the controls it teaches, so completion records land in the audit evidence automatically. One owner, one dashboard.

Book a demo

200+ frameworks mapped · Evidence from your own stack · One platform, everything

Frequently asked questions

What is security awareness training?

A recurring programme that teaches staff to recognise and report the attacks aimed at them, then measures whether behaviour changed. It covers phishing, credentials, data handling and reporting, and it produces the completion records that frameworks require as evidence.

How often is security awareness training required?

At onboarding and at least annually under most frameworks, plus after any significant change to systems or threat landscape. Many teams add short quarterly reinforcement, because one long annual module measurably decays over the year.

Do contractors need security awareness training?

Yes, if they have access to systems or data. Auditors reconcile the training list against everyone with access, not against the payroll. Contractors and part-time staff missing from that list is one of the most common findings.

Are phishing simulations necessary?

Not universally mandated, but they are the only practical way to measure behaviour rather than recall, and several frameworks expect evidence that the programme is effective. Run them to find where reinforcement is needed, not to identify people to embarrass.

What evidence do auditors want?

Completion records with names and dates, the training list reconciled to current headcount, proof that recent joiners were trained inside the defined window, and a record of what happened to anyone who did not complete it. Content quality is rarely sampled. Coverage always is.