Skip to content
AwareSprint

Guide

Security awareness training: what works, and what to evidence

Almost every organisation runs security awareness training. Most of them cannot show it changed anything, and a good number cannot show it happened. Both problems are fixable, and they are not the same problem.

Why the standard approach underperforms

It happens once a year
A single long session sets a compliance date and little else. Retention decays within weeks, and there is nothing between sittings to rebuild it.
It is watched, not practised
Recognising a phishing email in a slide is a different task from recognising one in your own inbox at 4pm. Passive content does not rehearse the decision.
It is identical for everyone
Finance faces payment fraud. Engineering faces credential theft and unsafe tooling. A single generic module serves neither well.
It is punitive when it lands
Programmes that name and shame people who click suppress reporting. The employee who quietly hides a mistake is the expensive outcome.
The record is an afterthought
Training usually happens. What is missing at audit is who completed it, when, and against which version of the content.

What changes behaviour instead

The pattern that works is unremarkable and hard to run manually: make it short, make it frequent, make people decide instead of watch, and make finishing feel like an achievement instead of an obligation. Five minutes that someone completes beats forty minutes they skim.

Frequency matters more than duration. A team that practises one decision a day for a month retains more than a team that sits through a single annual session, and the organisation ends up with thirty data points about where its weak areas are, not one completion tick.

Tone matters more than most programmes assume. The objective is that someone who clicks a malicious link tells you within minutes. Any programme that makes that admission embarrassing is working against its own purpose.

The evidence problem

Awareness findings in audits are rarely about the absence of training. They are about the absence of a record that survives scrutiny. A named list, dates, the content version each person was assessed against, and coverage across the whole population, not just the subset who happened to finish.

What each standard asks for differs in the detail. These break it down clause by clause:

How AwareSprint approaches it

Short challenges on a regular cadence, built as decisions and not slides, with a company leaderboard that rewards finishing and never exposes who scored lowest. Everything produces a completion register you can hand to an auditor.

Work email only. Nothing to install and no card required.

Your spot is saved today. Onboarding opens in September and the challenge starts 1 October 2026.

Registering your whole company?Use the company form

FAQ

Questions

The questions that decide whether a programme is worth running.

How often should security awareness training happen?

Most standards set an annual minimum and then describe awareness as ongoing. The minimum is a floor, not a target. Short, frequent sessions retain far better than one long annual sitting, and they produce a continuous evidence trail instead of a single dated record.

Does security awareness training actually reduce risk?

Training changes measurable behaviours. How often people report suspicious messages, how they handle credentials, whether they verify unusual requests. It does not eliminate human error, and any vendor claiming it prevents breaches is overselling. Treat it as one control among many.

What should awareness training cover?

At minimum: phishing and its variants across email, SMS, voice and QR; credentials, password managers and MFA; data classification and sharing; device and remote working hygiene; ransomware response; and how to report an incident internally.

What evidence do auditors ask for?

A completion register naming individuals and dates, the content version each person was assessed against, participation across the whole population including everyone who did not finish, and an audit trail showing the record has not been altered.

Is simulated phishing necessary?

It is a useful measurement, not a requirement in most standards. Its value is showing you a reporting rate before and after. Its risk is that punitive use damages trust and suppresses reporting, which is the opposite of what you want.