## Purpose

This policy defines how the company provides cybersecurity awareness and training to employees, contractors, managers, administrators, and other users.

The objective is to make sure people understand the cyber risks relevant to their work, know the company’s security expectations, and know what to do when something suspicious occurs.

Training should be practical, understandable, and proportionate to the user’s role.

## Scope

**This policy applies to:**

- Employees
- Managers
- Executives
- Contractors and temporary workers
- IT administrators
- Finance and payroll personnel
- HR personnel
- Developers and technical teams
- Other users with access to company systems or information

Third parties may also receive relevant training or security instructions where appropriate.

## Training Ownership

The company should assign a Security Awareness Owner.

Security Awareness Owner: ____________________

Backup: ____________________

**Responsibilities include:**

- Planning cybersecurity training
- Assigning required training
- Tracking completion
- Coordinating role-based training
- Organizing simulations and exercises
- Reviewing training effectiveness
- Updating training following incidents, significant threats, or business changes

## Core Training

**All users should receive basic cybersecurity awareness covering:**

- Phishing and suspicious messages
- Password and password manager use
- MFA
- Unexpected MFA prompts
- Data handling and sharing
- Device security
- Remote working
- Approved software, SaaS, and AI tools
- Payment and impersonation fraud
- Security incident reporting
- Lost or stolen devices
- Reporting mistakes quickly

## New Employee Training

New employees and contractors should receive cybersecurity guidance as part of onboarding.

**Training should explain:**

- How to protect accounts
- How to use MFA
- Where company data should be stored
- Which tools are approved
- How to identify common attacks
- How to report suspicious activity
- What to do after making a security mistake

Core training should be completed within an appropriate period after joining.

## Refresher Training

Cybersecurity awareness should be reinforced periodically.

For many SMEs, annual formal training combined with shorter reminders during the year provides a reasonable baseline.

**Additional training should be considered when:**

- Threats change significantly
- A serious incident occurs
- Repeated weaknesses are identified
- New technology is introduced
- Policies change
- Employees move into higher-risk roles

## Role-Based Training

Employees with higher-risk responsibilities should receive additional training appropriate to their role.

**Examples include:**

- Finance and payroll
- Executives
- HR
- IT administrators
- Developers
- Customer service
- Procurement
- Vendor managers
- Employees handling sensitive data

Role-based training should focus on realistic scenarios those employees may encounter.

## Phishing and Social Engineering Exercises

The company may use phishing simulations or other awareness exercises to help employees practice identifying and reporting suspicious activity.

Exercises should be used primarily for learning and improvement.

**Results should be used to identify:**

- Training gaps
- Reporting weaknesses
- Repeated risk patterns
- Teams requiring additional support

Simulation results should not be treated as a complete measure of employee security performance.

## Incident Reporting Culture

Employees should be encouraged to report suspicious activity quickly.

The company should avoid creating a culture where employees delay reporting because they fear embarrassment or punishment for an honest mistake.

**Employees should understand that rapid reporting can significantly reduce the impact of:**

- Phishing
- Credential compromise
- Data exposure
- Payment fraud
- Malware
- Lost devices

## Training Records

The company should maintain appropriate evidence of training.

**Records may include:**

- Training date
- Training topic
- Employee or audience
- Completion status
- Role-based requirements
- Exercise participation
- Follow-up training
- Training owner
- Evidence location

## Non-Completion

Required training that is not completed should be followed up.

Repeated or significant non-completion may be escalated to the employee’s manager or appropriate leadership.

## Training Effectiveness

The company should consider whether training changes behavior rather than measuring completion alone.

**Useful indicators may include:**

- Training completion
- Employee reporting rates
- Speed of incident reporting
- Phishing simulation reporting
- Repeated mistakes
- Role-based training completion
- Employee questions
- Results of tabletop exercises
- Real incident lessons

## Review

**Review the training program at least annually and after significant:**

- Cybersecurity incidents
- Business changes
- Technology changes
- Threat changes
- Policy changes

## Practical Rule

Cybersecurity training should teach employees what risks they are likely to encounter, what action they should take, and how to ask for help quickly.
