What topics should security awareness training cover?
Twelve topics cover the field: phishing, passwords and MFA, social engineering, payment fraud, ransomware, data handling, remote work, mobile devices, physical security, AI-era scams, incident reporting and safe browsing. Phishing and reporting deserve the most repetition, because that is where incidents start and end.
| Topic | What to teach |
|---|---|
| Phishing | Spotting hooks, checking senders and links before clicking |
| Passwords & MFA | Password managers, unique passwords, why MFA matters |
| Social engineering | Pretexting calls, impersonation, urgency pressure |
| Invoice & payment fraud | BEC, changed bank details, verification callbacks |
| Ransomware basics | How it arrives, why backups matter, first response |
| Data handling | Classification, safe sharing, privacy obligations |
| Remote & travel security | Public Wi-Fi, shoulder surfing, VPN habits |
| Mobile & BYOD | App permissions, updates, lost-device response |
| Physical security | Tailgating, clean desks, visitor handling |
| AI-era scams | Deepfake voice calls, cloned video, AI-written lures |
| Incident reporting | What to report, where, and why speed beats shame |
| Safe browsing & updates | Patches, extensions, download hygiene |
The AI-era row is the one most 2020s course libraries are missing: staff now need to hear a cloned voice scam described before they receive one. Rotate one topic a month, keep modules to ten minutes, and let phishing simulations carry the practice between modules; the cadence rules are on the requirements page.
What do good training examples look like?
Like the scams your staff actually receive. The three below are composites of the most common real patterns: a delivery text, a gift card ask from the boss, and an MFA fatigue push. Walk teams through what the target saw, what the tell was, and what the right move looked like.
The delivery text: a parcel needs a small customs fee, pay at the link, the link is a card-harvesting page. Tell: couriers do not collect fees by text link; move: go to the courier's site directly. The boss ask: an email or text from the CEO's name needs gift cards for a client, urgently and confidentially. Tell: urgency plus secrecy plus an unusual payment method; move: verify on a known channel, never the one the message arrived on. The MFA push storm: repeated approval prompts at 11pm until the target taps approve. Tell: prompts you did not initiate; move: deny, change the password, report it. Every one of these is trainable in five minutes and testable with a simulation.
Free security awareness training policy template
A two page, plain English policy covering purpose, scope, roles, training cadence, phishing simulation ground rules, reporting culture and audit evidence. Replace the bracketed text, delete what does not apply, and adopt it under your document control. Enter your email and the download link arrives immediately.
The template pairs with the requirements page for choosing your cadence, and with insurance-grade evidence when the renewal form asks what your programme looks like. It is deliberately platform-neutral: it will serve you whether or not you ever become a customer.
Common questions
How do you make security awareness training engaging?
Short beats long, stories beat rules, and relevance beats volume. Ten minute modules tied to scams your staff actually receive, phishing simulations that coach rather than punish, and the occasional leaderboard do more than any hour-long compliance video.
Should training topics rotate monthly?
A monthly topic rotation works well: pick one topic from the list, run a short module or a simulation themed on it, and cycle the list across the year. Phishing earns more repeats than anything else because it is where incidents actually start.
Can I run training from a PowerPoint instead of a platform?
You can start there, and it beats nothing. What slides cannot do is track completion, run phishing simulations, chase stragglers or export evidence for auditors and insurers, which is why most teams graduate to a platform the first time someone asks for proof.
Is the policy template really free?
Yes: one email with the download link, no mailing list attached, adapt it however you like. We ask for an email because teams that want a training policy are usually teams about to want a training platform, and we would like the introduction.
Should the training topics differ by role?
The core dozen apply to everyone; add depth where the risk is. Finance gets payment fraud and verification callbacks, IT gets privileged access, executives get impersonation and whaling, and new starters get the basics before anything else.
Want the topics delivered as ready-made courses? See what the platform includes or start with the free phishing test.
