Role Based Training Matrix

Purpose

Use this matrix to identify additional cybersecurity training required for employees with higher-risk responsibilities.

Core awareness training should apply to everyone. Role-based training should focus on risks specific to the person’s work.

Role / Team Key Risks Additional Training
Executives and Leadership Executive impersonation, account takeover, sensitive information, high-value decisions, extortion Executive phishing, MFA, secure communications, incident decision authority, fraud verification
Finance / Accounts Payable Invoice fraud, supplier impersonation, payment diversion, business email compromise Payment verification, bank-detail changes, high-risk transactions, fraud escalation
Payroll Payroll diversion, employee impersonation, sensitive employee data Identity verification, payroll changes, data protection, account compromise
HR Employee information, onboarding/offboarding, insider risk Sensitive data handling, access lifecycle, impersonation, insider threat escalation
IT Administrators Privileged account compromise, ransomware, configuration errors Privileged access, secure administration, logging, incident containment, evidence preservation
MSP-Facing Staff Third-party access and responsibility gaps Vendor access, MSP responsibility matrix, incident escalation, privileged access
Developers Source code, credentials, application vulnerabilities, dependencies Secure coding, secrets management, dependency security, application security
Sales / Customer Service Customer impersonation, data disclosure, phishing Identity verification, data sharing, social engineering, customer information protection
Procurement Vendor impersonation, supplier compromise, payment changes Vendor verification, fraud indicators, third-party security, payment change process
Vendor Managers Third-party access and data exposure Vendor security assessment, vendor access control, incident notification, offboarding
Managers Excessive access, delayed reporting, employee changes Access approval, role changes, offboarding, reporting culture
Remote Workers Device theft, public networks, data exposure Secure remote work, device security, public Wi-Fi, data privacy
Employees Handling Sensitive Data Unauthorized disclosure and excessive sharing Data classification, secure sharing, external access, reporting exposure

Training Record

Employee / Team: ____________________

Role: ____________________

Core training completed: ____________________

Required role-based training: ____________________

Training owner: ____________________

Due date: ____________________

Completion date: ____________________

Evidence: ____________________

Refresher required: ____________________

Next review: ____________________

Review Triggers

Role-based training should be reconsidered when:

  • An employee changes roles
  • Responsibilities materially change
  • New systems are introduced
  • A significant incident occurs
  • A new fraud or attack pattern becomes relevant
  • A control weakness repeatedly appears

Practical Rule

People with greater access, authority, or financial responsibility should receive training that reflects the additional risk they carry.