How often should security awareness training be conducted?
At least annually for compliance, quarterly for genuine behaviour change, plus a baseline module for every new starter within their first two weeks. The strongest programmes run short modules continuously rather than one long annual session.
The gap between those cadences is the gap between passing audits and changing outcomes. Annual training exists because frameworks wrote it down decades ago; memory research and phishing results both show the effect decaying within weeks. Quarterly micro-modules (ten minutes, one topic) hold attention without burning goodwill, and they map cleanly onto the rotating topic lists in our topics and templates pack. The full programme logic lives in the complete guide.
How often should you run phishing tests?
Quarterly as the baseline, monthly for high-risk teams such as finance and executives, and always unannounced. Less than quarterly and staff never build the reflex; more than monthly and simulations become background noise people resent.
Cadence matters less than consistency and follow-through: a simulation without instant coaching for clickers is a statistic, not training. Rotate template styles so the lesson is scrutiny rather than pattern-matching, and read the trend across campaigns rather than any single result. The mechanics, template choices and metrics are covered step by step in the phishing simulation guide, and a first unannounced campaign via the free phishing test gives you the honest baseline to measure everything else against.
Is security awareness training mandatory?
For many organisations, effectively yes: payment card handling, health data, government supply chains and a growing share of cyber insurance policies all carry training expectations. Even where no law names it, contracts and insurers increasingly do.
| Framework | What it expects | Cadence signal |
|---|---|---|
| PCI DSS | Formal awareness programme for anyone handling card data | On hire + at least annually |
| ISO 27001 | Personnel aware of the policy and their security responsibilities | Ongoing, evidence required |
| SOC 2 | Training as a control supporting the trust criteria | Typically annual + onboarding |
| HIPAA | Security awareness programme for all workforce members | Periodic, plus reminders |
| ACSC guidance (AU) | Ongoing awareness alongside the Essential Eight controls | Ongoing, tailored to role |
| Cyber insurance | Proposal forms increasingly ask for training and phishing testing | Evidence at renewal |
Primary sources if you need chapter and verse: the PCI Security Standards Council and the ACSC publish theirs openly; ISO sells its text but the awareness clause summary above is faithful. Our standards page maps how train2secure covers each, and insurance-grade evidence handles the renewal-form conversation.
What must training include to satisfy auditors?
Three things: relevant content (phishing, data handling, reporting at minimum), records proving who completed what and when, and a written policy showing the cadence is deliberate rather than accidental. Content without records fails audits; records without a policy fails diligence.
The policy is the piece most small companies are missing, and it takes ten minutes with a decent starting point: our free policy template covers purpose, scope, cadence, phishing simulation rules and evidence retention in two pages of plain English. Pair it with platform-generated completion exports and the audit conversation becomes a five-minute email.
Common questions
Is annual security awareness training enough?
It satisfies the letter of most frameworks and the behaviour of almost nobody. Annual training fades within weeks; short quarterly modules with phishing simulations between them keep the reflex alive. Treat annual as the compliance floor, not the target.
Do new employees need training immediately?
Within the first couple of weeks, yes. New starters are prime phishing targets because they do not yet know what normal internal email looks like, and most frameworks expect security training during onboarding. Auto-assigning a baseline module at account creation solves it permanently.
Who has to take security awareness training?
Everyone with access to systems or data: employees, contractors, part-timers and executives. Leadership exemptions are the classic mistake, since executives are the most impersonated and most targeted people in the building.
What evidence do auditors and insurers actually want?
Completion records with dates and names, certificates, phishing simulation results over time, and a policy showing the cadence is deliberate. Screenshots assembled the week before an audit convince nobody; platform-generated exports do.
Can the cadence be automated?
Fully. A platform should auto-assign onboarding training, schedule refreshers, chase stragglers with reminders, run phishing campaigns on a calendar and export the evidence. train2secure does all five, which turns this whole page into configuration rather than a project.
Set the cadence once and let it run: see plans or grab the free policy template.
