{"id":1139,"date":"2026-09-10T10:12:50","date_gmt":"2026-09-10T10:12:50","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=1139"},"modified":"2026-09-10T10:12:50","modified_gmt":"2026-09-10T10:12:50","slug":"security-awareness-training","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/security-awareness-training\/","title":{"rendered":"Security Awareness Training"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: SECURITY AWARENESS TRAINING\n     Live osto.one glossary stylesheet. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">Security awareness training is the control that treats people as part of the system, and it is the one most often reduced to a video nobody watched and a certificate nobody read.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Compliance<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>Security awareness training is a recurring programme that teaches staff to recognise and report the attacks aimed at them, then measures whether it worked. Every major framework requires it, usually at onboarding and at least annually. What auditors sample is not the course content but the completion records, the reminder trail for people who did not finish, and evidence that the programme was reviewed.<\/p>\n<\/div>\n\n<p>The reason it stays on every framework is uncomfortable but simple. Most breaches start with someone being asked to do something reasonable-looking by someone who is not who they claim to be. No technical control removes that entirely.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#cycle\">The security awareness training cycle<\/a><\/li>\n    <li><a href=\"#topics\">What security awareness training must cover<\/a><\/li>\n    <li><a href=\"#frameworks\">Where frameworks require security awareness training<\/a><\/li>\n    <li><a href=\"#evidence\">What auditors ask for<\/a><\/li>\n    <li><a href=\"#fails\">Why security awareness training fails<\/a><\/li>\n    <li><a href=\"#osto\">How Osto runs security awareness training<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"cycle\">The security awareness training cycle<\/h2>\n\n<p>Security awareness training runs as five stages on a repeating schedule. Teams that stop after stage two have a training record. Teams that run all five have a control.<\/p>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 198\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"The five-stage security awareness training cycle: baseline, train, simulate, remediate and evidence.\">\n  <defs><marker id=\"satA\" markerWidth=\"8\" markerHeight=\"8\" refX=\"6.5\" refY=\"4\" orient=\"auto\"><path d=\"M0,0 L8,4 L0,8 z\" fill=\"#4a52a8\"\/><\/marker><\/defs>\n\n  <rect x=\"10\" y=\"26\" width=\"132\" height=\"76\" rx=\"13\" fill=\"#e9ecfa\"\/>\n  <text x=\"76\" y=\"53\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#4a52a8\">1. Baseline<\/text>\n  <text x=\"76\" y=\"73\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Measure before<\/text>\n  <text x=\"76\" y=\"86\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">you teach anything<\/text>\n  <line x1=\"146\" y1=\"64\" x2=\"162\" y2=\"64\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#satA)\"\/>\n\n  <rect x=\"168\" y=\"26\" width=\"132\" height=\"76\" rx=\"13\" fill=\"#cfd5f2\"\/>\n  <text x=\"234\" y=\"53\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#4a52a8\">2. Train<\/text>\n  <text x=\"234\" y=\"73\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Role-relevant,<\/text>\n  <text x=\"234\" y=\"86\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">short, recorded<\/text>\n  <line x1=\"304\" y1=\"64\" x2=\"320\" y2=\"64\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#satA)\"\/>\n\n  <rect x=\"326\" y=\"26\" width=\"132\" height=\"76\" rx=\"13\" fill=\"#1c267a\"\/>\n  <text x=\"392\" y=\"53\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#ffffff\">3. Simulate<\/text>\n  <text x=\"392\" y=\"73\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#b9c1e6\">Test behaviour,<\/text>\n  <text x=\"392\" y=\"86\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#b9c1e6\">not recall<\/text>\n  <line x1=\"462\" y1=\"64\" x2=\"478\" y2=\"64\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#satA)\"\/>\n\n  <rect x=\"484\" y=\"26\" width=\"132\" height=\"76\" rx=\"13\" fill=\"#cfd5f2\"\/>\n  <text x=\"550\" y=\"53\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#4a52a8\">4. Remediate<\/text>\n  <text x=\"550\" y=\"73\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Follow up with<\/text>\n  <text x=\"550\" y=\"86\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">who needs it<\/text>\n  <line x1=\"620\" y1=\"64\" x2=\"636\" y2=\"64\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#satA)\"\/>\n\n  <rect x=\"642\" y=\"26\" width=\"108\" height=\"76\" rx=\"13\" fill=\"#e3f0e9\"\/>\n  <text x=\"696\" y=\"53\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#3a6f5d\">5. Evidence<\/text>\n  <text x=\"696\" y=\"73\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Records the<\/text>\n  <text x=\"696\" y=\"86\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">auditor samples<\/text>\n\n  <rect x=\"10\" y=\"118\" width=\"740\" height=\"30\" rx=\"11\" fill=\"#f0e6f3\"\/>\n  <text x=\"380\" y=\"138\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#6b4576\">Repeats at onboarding and at least annually, plus after any significant change.<\/text>\n\n  <rect x=\"10\" y=\"156\" width=\"740\" height=\"32\" rx=\"11\" fill=\"#fbe9dc\"\/>\n  <text x=\"380\" y=\"177\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#a2603a\">Stage 1 is the one people skip. Without a baseline there is no way to show the programme changed anything.<\/text>\n<\/svg>\n<\/div>\n<\/figure>\n\n<h2 id=\"topics\" class=\"c-sage\">What security awareness training must cover<\/h2>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Topic<\/th><th>Why it earns a place<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Phishing and social engineering<\/td><td>The starting point for most intrusions, and the only topic worth testing rather than just teaching<\/td><\/tr>\n    <tr><td>Business email compromise<\/td><td>Payment and payroll redirection requests that carry no malware and pass every <a href=\"https:\/\/www.osto.one\/resources\/glossary\/email-security\/\">email filter<\/a><\/td><\/tr>\n    <tr><td>Credentials and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">MFA<\/a><\/td><td>Password reuse and MFA fatigue prompts, which is how a stolen credential becomes a session<\/td><\/tr>\n    <tr><td>Data handling<\/td><td>What counts as sensitive, where it may go, and how <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dlp\/\">data loss<\/a> usually happens by accident<\/td><\/tr>\n    <tr><td>Device and physical security<\/td><td>Screen locking, unmanaged devices, and the risk in working from shared spaces<\/td><\/tr>\n    <tr><td>Reporting<\/td><td>How to raise a suspicion in seconds, which is the behaviour that shortens <a href=\"https:\/\/www.osto.one\/resources\/glossary\/incident-response\/\">incident response<\/a> more than any other<\/td><\/tr>\n    <tr><td>Role-specific content<\/td><td>Secure coding for engineers, payment verification for finance, and privacy obligations for anyone handling personal data<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"frameworks\" class=\"c-sky\">Where frameworks require security awareness training<\/h2>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Framework<\/th><th>Status<\/th><th>What it expects<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a><\/td><td><span class=\"pill p-req\">Required<\/span><\/td><td>Commitment to competence and internal communication of security responsibilities, evidenced across the observation window<\/td><\/tr>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a><\/td><td><span class=\"pill p-req\">Required<\/span><\/td><td>An <a href=\"https:\/\/www.osto.one\/resources\/glossary\/annex-a-controls\/\">Annex A control<\/a> covering awareness, education and training, plus competence evidence in the management system<\/td><\/tr>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/pci-dss\/\">PCI DSS<\/a><\/td><td><span class=\"pill p-req\">Required<\/span><\/td><td>Security awareness training at hire and at least annually, with acknowledgement from personnel<\/td><\/tr>\n    <tr><td>HIPAA<\/td><td><span class=\"pill p-req\">Required<\/span><\/td><td>A security awareness and training programme for all workforce members, including periodic reminders<\/td><\/tr>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/dpdp-act\/\">DPDP Act<\/a><\/td><td><span class=\"pill p-imp\">Implied<\/span><\/td><td>Reasonable security safeguards, which in practice includes staff who understand their obligations for personal data<\/td><\/tr>\n    <tr><td>RBI and SEBI frameworks<\/td><td><span class=\"pill p-req\">Required<\/span><\/td><td>Periodic awareness programmes for staff, with board-level visibility of the arrangement for regulated entities<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>The wording differs. The expectation does not: everyone gets trained on joining, everyone gets trained again each year, and you can prove both.<\/p>\n\n<h2 id=\"evidence\" class=\"c-plum\">What auditors ask for<\/h2>\n\n<table class=\"h-plum\">\n  <thead>\n    <tr><th>Artefact<\/th><th>What it has to show<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Completion records<\/td><td>Named individuals, dates, and the version of the content they took<\/td><\/tr>\n    <tr><td>Coverage against headcount<\/td><td>The training list reconciled to the current staff list, including contractors<\/td><\/tr>\n    <tr><td>Onboarding trail<\/td><td>Training completed within a defined window of a start date, sampled against recent joiners<\/td><\/tr>\n    <tr><td>Reminder and escalation records<\/td><td>What happened to people who did not complete it, which is where most programmes come apart<\/td><\/tr>\n    <tr><td>Simulation results<\/td><td>Click and report rates over time, plus what followed for repeat clickers<\/td><\/tr>\n    <tr><td>Content review<\/td><td>Evidence that the material was reviewed and updated, not carried over untouched for three years<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">The sample is always the leavers and joiners<\/p>\n  <p>Auditors rarely check the whole population. They take a handful of recent starters and ask when each completed training, and they take the completion report and reconcile it against headcount. A programme at 88 percent completion with no record of chasing the missing 12 percent is a finding, even when the content is excellent.<\/p>\n<\/div>\n\n<h2 id=\"fails\" class=\"c-apri\">Why security awareness training fails<\/h2>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Failure<\/th><th>What it looks like<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Annual and forgotten<\/td><td>One long module in January, no reinforcement, no measurement of whether behaviour changed<\/td><\/tr>\n    <tr><td>Generic content<\/td><td>The same module for engineers, finance and support, so nobody sees their own risk in it<\/td><\/tr>\n    <tr><td>Punitive simulations<\/td><td>Naming people who clicked, which reliably stops reporting and makes the next real incident slower to surface<\/td><\/tr>\n    <tr><td>No contractor coverage<\/td><td>Third parties with system access left out of the training list entirely<\/td><\/tr>\n    <tr><td>Records in three places<\/td><td>A learning tool, a spreadsheet and an email thread, so reconstructing evidence takes days<\/td><\/tr>\n    <tr><td>No reporting channel<\/td><td>Staff taught to spot phishing with no obvious way to report it in under thirty seconds<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"osto\">How Osto runs security awareness training<\/h2>\n\n<p>Security awareness training runs inside the platform rather than in a separate learning tool, which matters mainly for the evidence. Completion records sit alongside the rest of the control evidence and map to <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/pci-dss\/\">PCI DSS<\/a>, HIPAA and the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dpdp-act\/\">DPDP Act<\/a> from one place, so nobody is exporting spreadsheets the week before an audit.<\/p>\n\n<p>Training also sits next to the controls it talks about. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/email-security\/\">Inbound email security<\/a> filters what it can, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">MFA<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iam\/\">access management<\/a> limit what a successful lure achieves, and the training covers the gap that neither one closes. That combination is what the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/grc\/\">GRC<\/a> evidence base has to show: a technical control, a human control, and a record of both.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Platform walkthrough<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Training that produces evidence<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Awareness training runs in the same platform as the controls it teaches, so completion records land in the audit evidence automatically. One owner, one dashboard.<\/p>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 32px;border-radius:12px;margin:0;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Book a demo<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:18px 0 0;\">200+ frameworks mapped &middot; Evidence from your own stack &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is security awareness training?<\/summary>\n  <p>A recurring programme that teaches staff to recognise and report the attacks aimed at them, then measures whether behaviour changed. It covers phishing, credentials, data handling and reporting, and it produces the completion records that frameworks require as evidence.<\/p>\n<\/details>\n\n<details>\n  <summary>How often is security awareness training required?<\/summary>\n  <p>At onboarding and at least annually under most frameworks, plus after any significant change to systems or threat landscape. Many teams add short quarterly reinforcement, because one long annual module measurably decays over the year.<\/p>\n<\/details>\n\n<details>\n  <summary>Do contractors need security awareness training?<\/summary>\n  <p>Yes, if they have access to systems or data. Auditors reconcile the training list against everyone with access, not against the payroll. Contractors and part-time staff missing from that list is one of the most common findings.<\/p>\n<\/details>\n\n<details>\n  <summary>Are phishing simulations necessary?<\/summary>\n  <p>Not universally mandated, but they are the only practical way to measure behaviour rather than recall, and several frameworks expect evidence that the programme is effective. Run them to find where reinforcement is needed, not to identify people to embarrass.<\/p>\n<\/details>\n\n<details>\n  <summary>What evidence do auditors want?<\/summary>\n  <p>Completion records with names and dates, the training list reconciled to current headcount, proof that recent joiners were trained inside the defined window, and a record of what happened to anyone who did not complete it. Content quality is rarely sampled. Coverage always is.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/email-security\/\">Email Security<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">MFA<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iam\/\">IAM<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/incident-response\/\">Incident Response<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/grc\/\">GRC<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/pci-dss\/\">PCI DSS<\/a><\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Security awareness training is the control that treats people as part of the system, and it is the one most\u2026<\/p>\n","protected":false},"author":8,"featured_media":1140,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[542,103,541,543],"class_list":["post-1139","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-phishing-simulation","tag-security-awareness-training","tag-security-awareness-training-requirements","tag-security-training-compliance"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1139","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=1139"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1139\/revisions"}],"predecessor-version":[{"id":1141,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1139\/revisions\/1141"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/1140"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=1139"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=1139"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=1139"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}