Role Based Training Matrix
Purpose
Use this matrix to identify additional cybersecurity training required for employees with higher-risk responsibilities.
Core awareness training should apply to everyone. Role-based training should focus on risks specific to the person’s work.
Training Record
Employee / Team: ____________________
Role: ____________________
Core training completed: ____________________
Required role-based training: ____________________
Training owner: ____________________
Due date: ____________________
Completion date: ____________________
Evidence: ____________________
Refresher required: ____________________
Next review: ____________________
Review Triggers
Role-based training should be reconsidered when:
- An employee changes roles
- Responsibilities materially change
- New systems are introduced
- A significant incident occurs
- A new fraud or attack pattern becomes relevant
- A control weakness repeatedly appears
Practical Rule
People with greater access, authority, or financial responsibility should receive training that reflects the additional risk they carry.