Knowledge Base
Engineer Login
Back to Knowledge Base

Security Awareness Training: Building a Program

Security & antivirus security awareness training phishing simulation staff By Cade · Updated 03/05/26 07:51 AM
Security awareness training educates employees about cyber threats and the behaviors that protect against them. Human error is involved in over 80% of breaches — making training the highest-ROI security investment for most organizations. An effective program includes: quarterly or monthly online training modules (15-20 minutes), regular phishing simulation campaigns (send fake phishing emails and track who clicks), and ad-hoc security tips via email or team chat. Platforms: KnowBe4, Proofpoint Security Awareness, Mimecast Awareness Training, and the free Google Phishing Quiz. Measure effectiveness with click rates on phishing simulations over time — the goal is declining click rates as the culture improves. Recognize and celebrate improvement without shaming individuals who click. Use near-miss events (real phishing emails that were reported before damage) as teachable moments for the whole organization. Tailor training to roles: finance staff should receive training on BEC (Business Email Compromise); executives on spear phishing; all staff on password hygiene and social engineering.