Guide
Security awareness training: what works, and what to evidence
Almost every organisation runs security awareness training. Most of them cannot show it changed anything, and a good number cannot show it happened. Both problems are fixable, and they are not the same problem.
Why the standard approach underperforms
- It happens once a year
- A single long session sets a compliance date and little else. Retention decays within weeks, and there is nothing between sittings to rebuild it.
- It is watched, not practised
- Recognising a phishing email in a slide is a different task from recognising one in your own inbox at 4pm. Passive content does not rehearse the decision.
- It is identical for everyone
- Finance faces payment fraud. Engineering faces credential theft and unsafe tooling. A single generic module serves neither well.
- It is punitive when it lands
- Programmes that name and shame people who click suppress reporting. The employee who quietly hides a mistake is the expensive outcome.
- The record is an afterthought
- Training usually happens. What is missing at audit is who completed it, when, and against which version of the content.
What changes behaviour instead
The pattern that works is unremarkable and hard to run manually: make it short, make it frequent, make people decide instead of watch, and make finishing feel like an achievement instead of an obligation. Five minutes that someone completes beats forty minutes they skim.
Frequency matters more than duration. A team that practises one decision a day for a month retains more than a team that sits through a single annual session, and the organisation ends up with thirty data points about where its weak areas are, not one completion tick.
Tone matters more than most programmes assume. The objective is that someone who clicks a malicious link tells you within minutes. Any programme that makes that admission embarrassing is working against its own purpose.
The evidence problem
Awareness findings in audits are rarely about the absence of training. They are about the absence of a record that survives scrutiny. A named list, dates, the content version each person was assessed against, and coverage across the whole population, not just the subset who happened to finish.
What each standard asks for differs in the detail. These break it down clause by clause:
- ISO/IEC 27001Awareness and trainingGlobal
- PCI DSSSecurity awareness programmeGlobal
- SEBI CSCRFAwareness and trainingIndia
- SOC 2Personnel and internal communicationGlobal
- HIPAAAwareness and training safeguardGlobal
How AwareSprint approaches it
Short challenges on a regular cadence, built as decisions and not slides, with a company leaderboard that rewards finishing and never exposes who scored lowest. Everything produces a completion register you can hand to an auditor.
That email address did not work. Check it and try again.
Work email only. Nothing to install and no card required.
Your spot is saved today. Onboarding opens in September and the challenge starts 1 October 2026.
Registering your whole company?Use the company form