## Purpose

Use this matrix to identify additional cybersecurity training required for employees with higher-risk responsibilities.

Core awareness training should apply to everyone. Role-based training should focus on risks specific to the person’s work.

|Role / Team|Key Risks|Additional Training|
|---|---|---|
|Executives and Leadership|Executive impersonation, account takeover, sensitive information, high-value decisions, extortion|Executive phishing, MFA, secure communications, incident decision authority, fraud verification|
|Finance / Accounts Payable|Invoice fraud, supplier impersonation, payment diversion, business email compromise|Payment verification, bank-detail changes, high-risk transactions, fraud escalation|
|Payroll|Payroll diversion, employee impersonation, sensitive employee data|Identity verification, payroll changes, data protection, account compromise|
|HR|Employee information, onboarding/offboarding, insider risk|Sensitive data handling, access lifecycle, impersonation, insider threat escalation|
|IT Administrators|Privileged account compromise, ransomware, configuration errors|Privileged access, secure administration, logging, incident containment, evidence preservation|
|MSP-Facing Staff|Third-party access and responsibility gaps|Vendor access, MSP responsibility matrix, incident escalation, privileged access|
|Developers|Source code, credentials, application vulnerabilities, dependencies|Secure coding, secrets management, dependency security, application security|
|Sales / Customer Service|Customer impersonation, data disclosure, phishing|Identity verification, data sharing, social engineering, customer information protection|
|Procurement|Vendor impersonation, supplier compromise, payment changes|Vendor verification, fraud indicators, third-party security, payment change process|
|Vendor Managers|Third-party access and data exposure|Vendor security assessment, vendor access control, incident notification, offboarding|
|Managers|Excessive access, delayed reporting, employee changes|Access approval, role changes, offboarding, reporting culture|
|Remote Workers|Device theft, public networks, data exposure|Secure remote work, device security, public Wi-Fi, data privacy|
|Employees Handling Sensitive Data|Unauthorized disclosure and excessive sharing|Data classification, secure sharing, external access, reporting exposure|

## Training Record

Employee / Team: ____________________

Role: ____________________

Core training completed: ____________________

Required role-based training: ____________________

Training owner: ____________________

Due date: ____________________

Completion date: ____________________

Evidence: ____________________

Refresher required: ____________________

Next review: ____________________

## Review Triggers

**Role-based training should be reconsidered when:**

- An employee changes roles
- Responsibilities materially change
- New systems are introduced
- A significant incident occurs
- A new fraud or attack pattern becomes relevant
- A control weakness repeatedly appears

## Practical Rule

People with greater access, authority, or financial responsibility should receive training that reflects the additional risk they carry.
