1. Training Purpose
Information security is not only the responsibility of the IT or Security team.
Every employee, contractor, consultant, and authorized user can affect the organization’s security.
This training helps personnel understand:
- Their information security responsibilities
- Common cybersecurity threats
- How to protect organizational information
- How to identify suspicious activity
- How to use systems securely
- How to protect customer and personal information
- How to report security incidents
- How to work securely from remote locations
- How to use AI and SaaS applications safely
Core Message
Security is everyone’s responsibility.
2. Who Should Complete the Training?
Security awareness training should apply to personnel whose activities can affect information security, including:
- Employees
- Contractors
- Consultants
- Interns
- Temporary workers
- Remote workers
- Third-party users with organizational access
Additional role-based training may be required for:
- Developers
- IT administrators
- Cloud administrators
- Security personnel
- HR
- Finance
- Customer support
- Procurement
- Management
- Privileged users
3. Learning Objectives
After completing this training, participants should be able to:
- Recognize common security threats.
- Protect passwords and authentication information.
- Identify phishing and social-engineering attempts.
- Handle organizational information according to its classification.
- Use email, cloud, SaaS, and collaboration tools securely.
- Work securely from home and public locations.
- Protect company devices.
- Use AI tools responsibly.
- Report security incidents quickly.
- Understand their individual security responsibilities.
4. Security Fundamentals
Information security protects three primary characteristics:
Confidentiality
Only authorized people should have access to information.
Example: Customer information should not be accessible to employees who do not need it.
Integrity
Information should remain accurate and protected from unauthorized modification.
Example: An employee should not modify a financial record without authorization.
Availability
Information and systems should be available when needed.
Example: A SaaS application should remain available to authorized customers.
Remember
Confidentiality + Integrity + Availability = CIA
5. Why Security Awareness Matters
Security incidents can result from:
- Phishing
- Weak passwords
- Stolen credentials
- Malware
- Accidental data sharing
- Misconfigured cloud services
- Lost devices
- Unauthorized applications
- Social engineering
- Insider mistakes
- Vulnerable software
- Unsafe use of AI tools
A technically secure environment can still be compromised through a simple human mistake.
Example
An employee receives an email:
“Your Microsoft 365 account will be disabled today. Click here to verify.”
The employee clicks the link and enters their password.
An attacker obtains the credentials and attempts to access company systems.
Lesson: Technology alone cannot prevent every attack. User awareness is an important security control.
6. Password Security
Employees must protect authentication information.
Good Practices
- Use strong, unique passwords.
- Use an approved password manager where provided.
- Enable MFA.
- Never share passwords.
- Never write passwords in unsecured locations.
- Do not reuse corporate passwords for personal services.
- Do not enter credentials into suspicious websites.
- Report suspected credential compromise immediately.
Never Share
Do not share:
- Passwords
- API keys
- AWS access keys
- Authentication tokens
- Recovery codes
- Private keys
- MFA codes
Important
IT support should not ask you to disclose your password.
7. Multi-Factor Authentication
MFA provides an additional layer of protection.
Authentication may involve:
- Something you know — password
- Something you have — security key or phone
- Something you are — biometric authentication
Example
Password + Authenticator Approval = MFA
If an attacker obtains your password, MFA may still prevent unauthorized access.
MFA Fatigue
Attackers may repeatedly send MFA approval requests hoping the user eventually accepts one.
If you receive an unexpected MFA request:
Do not approve it. Report it.
8. Phishing
Phishing is an attempt to trick users into revealing information, clicking malicious links, opening files, transferring money, or performing another unauthorized action.
Common phishing messages may contain:
- Urgent requests
- Fake login pages
- Suspicious links
- Unexpected attachments
- Payment requests
- Password-reset requests
- Fake HR communications
- Fake IT support messages
- Fake customer requests
9. How to Identify Phishing
Before clicking a link or opening an attachment, ask:
Sender
Do I recognize the sender?
Context
Was I expecting this message?
Urgency
Is someone trying to pressure me?
Link
Does the destination actually belong to the expected organization?
Attachment
Was I expecting this file?
Request
Is the sender asking for:
- Password?
- MFA code?
- Money?
- Confidential information?
- Customer data?
- Unusual access?
Rule
Stop → Check → Verify → Report
10. Phishing Example
You receive:
Subject: Urgent: Customer Contract Payment Required
The email asks you to immediately transfer money to a new bank account.
What should you do?
Do not transfer the money immediately.
Instead:
- Verify the request through an independent communication channel.
- Check whether the request follows the organization’s payment process.
- Report suspicious activity.
- Do not reply to the suspicious email with sensitive information.
11. Business Email Compromise
Attackers may impersonate:
- CEO
- CFO
- Manager
- Customer
- Supplier
- Lawyer
- HR
- IT support
Example:
“I am in a meeting. Please urgently purchase gift cards and send me the codes.”
Remember
Urgency does not equal authorization.
For financial or sensitive requests:
Verify → Authorize → Execute
12. Social Engineering
Social engineering manipulates people into performing actions that compromise security.
Attackers may use:
- Authority
- Fear
- Urgency
- Curiosity
- Trust
- Familiarity
- Helpfulness
Example
Someone calls claiming:
“I am from IT. We detected a problem with your account. Please tell me your MFA code.”
The correct response is:
Do not provide the code. Verify the request through an approved IT channel.
13. Information Classification
Employees must understand how organizational information is classified.
A simple classification model may include:
| Classification | Example |
|---|---|
| Public | Published website content |
| Internal | Internal procedures |
| Confidential | Customer information |
| Restricted | Passwords, API keys, production credentials |
Remember
Classification determines how information should be handled.
Do not send Confidential or Restricted information through unauthorized channels.
14. Protecting Customer Information
Customer information must be handled carefully.
Employees should:
- Access only information needed for their role.
- Use approved systems.
- Verify recipients before sharing.
- Avoid unnecessary downloads.
- Avoid personal email.
- Avoid personal cloud storage.
- Report accidental disclosure immediately.
Example
If a customer sends a confidential document, do not forward it to your personal Gmail account simply because it is easier to access from home.
15. Personal Data and Privacy
Employees may handle personal information relating to:
- Customers
- Employees
- Applicants
- Suppliers
- Partners
Personal information should be:
- Collected for legitimate purposes.
- Accessed only when authorized.
- Shared only when permitted.
- Stored securely.
- Retained only as required.
- Deleted securely when no longer required.
If you are unsure whether information can be shared:
Stop → Ask → Verify
16. Email Security
Before sending sensitive information:
- Verify the recipient.
- Check the email address carefully.
- Confirm attachments.
- Use approved secure sharing mechanisms.
- Avoid unnecessary recipients.
- Use encryption where required.
- Do not use personal email for organizational information.
Common Mistake
Autocomplete may select the wrong recipient.
Always check the recipient before sending sensitive information.
17. Secure Use of Cloud and SaaS Applications
Employees should use only approved business applications.
Do not connect corporate accounts to unauthorized applications without approval.
Examples of risks include:
- Unapproved file-sharing applications
- Unauthorized AI tools
- Personal cloud storage
- Browser extensions
- Free online conversion tools
- Unapproved project-management platforms
Rule
If the business needs a new application, follow the organization’s approval process.
18. AI Security Awareness
AI tools can create security and privacy risks.
Employees must not enter the following into unauthorized AI tools:
- Passwords
- API keys
- Customer confidential information
- Production database information
- Restricted security information
- Confidential contracts
- Sensitive employee information
- Proprietary source code
- Security incident details
Before using an AI tool, ask:
- Is the tool approved?
- What information am I providing?
- Is the information confidential?
- Does the provider retain the information?
- Could the information be used for model training?
- Do I have authorization?
- Does the output require human review?
Principle
Protect the data → Verify the output → Keep humans accountable
Follow the organization’s AI Acceptable Use Policy.
19. Secure Use of Company Devices
Employees should:
- Lock their screen when away.
- Install required updates.
- Use approved security software.
- Avoid unauthorized software.
- Protect laptops from theft.
- Avoid sharing corporate devices.
- Report lost or stolen devices.
Simple Rule
If you would not leave a company laptop unattended in the office, do not leave it unattended in a public place.
20. Remote Working Security
When working remotely:
- Use approved devices.
- Use MFA.
- Protect your home Wi-Fi.
- Avoid sensitive work on unsecured public networks.
- Prevent others from viewing your screen.
- Lock your device when unattended.
- Store information only in approved systems.
- Report lost devices immediately.
For personal devices, follow the organization’s BYOD Policy.
21. Public Places
Be careful when working from:
- Airports
- Hotels
- Cafés
- Coworking spaces
- Conferences
- Public transport
Risks include:
- Shoulder surfing
- Device theft
- Eavesdropping
- Unsecured Wi-Fi
- Lost documents
Practical Rule
If someone sitting next to you could easily see or hear sensitive information, move to a more secure location.
22. Clean Desk and Clear Screen
Employees should:
- Lock screens.
- Secure physical documents.
- Avoid leaving confidential papers unattended.
- Dispose of sensitive documents securely.
- Avoid displaying confidential information where unauthorized people can see it.
This applies both in offices and remote locations.
23. Removable Media
USB drives and other removable media can introduce security risks.
Employees should:
- Use only approved removable media.
- Avoid copying confidential information unnecessarily.
- Encrypt sensitive information where required.
- Scan removable media where required.
- Report lost media immediately.
Do not plug unknown USB devices into corporate computers.
24. Software and Applications
Employees must use approved software.
Do not install:
- Pirated software
- Cracked applications
- Unauthorized browser extensions
- Unapproved remote-access tools
- Unknown security utilities
Software may introduce:
- Malware
- Vulnerabilities
- Data leakage
- Licensing issues
- Unauthorized access
If you need software for work:
Request → Review → Approve → Install
25. Security Updates
Security vulnerabilities can be exploited when software is not updated.
Employees should:
- Install approved security updates promptly.
- Restart devices when required.
- Avoid disabling update mechanisms.
- Report repeated update failures.
Remember
An update notification may be a security control, not an inconvenience.
26. Physical Security
Information security also includes physical security.
Protect:
- Laptops
- Mobile devices
- Documents
- USB drives
- Access cards
- Security keys
- Printed customer information
Never leave sensitive equipment or documents unattended in public areas.
27. Incident Reporting
Employees are often the first people to notice security incidents.
Report:
- Phishing
- Malware
- Lost devices
- Stolen devices
- Accidental data disclosure
- Suspicious login alerts
- Unauthorized access
- Unexpected MFA requests
- Lost documents
- Suspected credential compromise
- Suspicious emails
- Unusual system behavior
Important
Report quickly. Do not wait until you know exactly what happened.
Early reporting can reduce impact.
28. What to Do If You Click a Suspicious Link
If you accidentally click a suspicious link:
- Do not panic.
- Stop entering information.
- Close the page if safe to do so.
- Do not continue interacting with the attacker.
- Report the incident immediately.
- Follow IT/Security instructions.
- Change credentials if instructed.
- Do not delete relevant evidence unless instructed.
Important
Reporting a mistake quickly is better than hiding it.
29. What to Do If You Entered Your Password on a Fake Website
Immediately:
Report → Secure Account → Review Activity → Follow Security Instructions
Security personnel may:
- Reset the password.
- Revoke sessions.
- Revoke tokens.
- Check authentication logs.
- Check for unauthorized activity.
- Enable additional controls.
- Investigate related activity.
30. Cloud Security Awareness
Employees should understand that cloud security is a shared responsibility.
Do not:
- Share cloud credentials.
- Create unauthorized cloud accounts.
- Make storage publicly accessible without authorization.
- Disable logging.
- Modify security settings without authorization.
- Store secrets in source code.
- Share privileged accounts.
For AWS environments, examples of security controls include:
- IAM
- MFA
- CloudTrail
- CloudWatch
- KMS
- Secrets Manager
- Security Groups
- S3 access controls
Employees should follow the organization’s approved cloud-security procedures.
31. Secure Development Awareness
Developers should receive additional training relevant to their roles.
Key practices include:
- Secure coding
- Code review
- Dependency management
- Secret management
- Authentication
- Authorization
- Input validation
- API security
- Vulnerability management
- Secure CI/CD
- Infrastructure-as-Code security
- Logging and monitoring
Critical Rule
Never commit passwords, API keys, tokens, or private keys to source code.
32. Access Control Awareness
Employees must:
- Use their own accounts.
- Never share accounts.
- Use only authorized systems.
- Follow least-privilege requirements.
- Protect MFA devices.
- Request access through approved processes.
- Report unnecessary or excessive access.
Joiner → Mover → Leaver
Access should change when:
- An employee joins.
- An employee changes role.
- An employee leaves.
33. Password Manager Awareness
Where an approved password manager is provided:
- Use it for unique passwords.
- Protect the master credential.
- Enable MFA.
- Do not share vault credentials.
- Do not store secrets in unsecured documents.
Do not create a personal workaround if an approved organizational solution is available.
34. Data Loss Prevention
Employees should understand that data can be lost through:
- Messaging applications
- Cloud storage
- Screenshots
- Copy/paste
- USB devices
- Printing
- AI tools
- Personal devices
- Misconfigured sharing links
Before sharing information:
Need → Recipient → Classification → Channel → Authorization
35. Security at Home
Employees working from home should:
- Secure the home Wi-Fi network.
- Keep devices updated.
- Use screen locks.
- Protect confidential conversations.
- Prevent unauthorized household access.
- Secure printed documents.
- Use approved corporate applications.
- Report security incidents.
36. Third-Party and Supplier Security
Employees may interact with:
- Customers
- Suppliers
- Consultants
- Partners
- Contractors
Do not provide sensitive information to third parties unless:
- The recipient is authorized.
- There is a legitimate business purpose.
- Appropriate approvals are in place.
- Contractual requirements are satisfied.
- Secure transfer methods are used.
37. Security and Social Media
Employees should avoid publicly sharing:
- Internal security information
- Customer information
- Confidential projects
- Credentials
- Internal architecture
- Security incidents
- Unreleased products
- Internal screenshots
Do not assume that information shared in a private group is automatically secure.
38. Security Incident Example
Scenario
An employee receives a fake Microsoft 365 login email.
They click the link and enter their credentials.
Within minutes, the attacker attempts to access corporate email.
Correct Response
Detect → Stop → Report → Secure Account → Investigate → Recover → Learn
Lesson
The employee should report the incident immediately, even if they are unsure whether the credentials were actually compromised.
39. Another Scenario — Accidental Data Sharing
An employee accidentally sends a customer report to the wrong external recipient.
What should the employee do?
Do not hide the mistake.
Immediately:
- Report it.
- Provide the relevant details.
- Identify the information involved.
- Follow instructions from Security/Privacy/Legal.
- Help determine whether the information can be recalled or deleted.
- Preserve relevant evidence.
Lesson
Fast reporting allows the organization to reduce potential impact.
40. Security Awareness: What Employees Should Remember
STOP
Stop before clicking, sharing, downloading, or approving.
CHECK
Check the sender, recipient, link, attachment, request, and context.
VERIFY
Verify unusual requests independently.
PROTECT
Protect information, credentials, devices, and systems.
REPORT
Report suspicious activity quickly.
41. Role-Based Security Awareness
General awareness training should be supplemented with role-specific training where necessary.
| Role | Additional Awareness |
|---|---|
| All Employees | Phishing, passwords, data protection, incidents |
| HR | Employee data, privacy, onboarding/offboarding |
| Finance | Payment fraud, BEC, financial information |
| Developers | Secure coding, secrets, dependencies |
| IT | Endpoint, identity, infrastructure security |
| Cloud Admins | IAM, privileged access, logging |
| Security Team | Incident response, threat intelligence |
| Procurement | Supplier security |
| Customer Support | Customer data and social engineering |
| Management | Risk, incidents, business impact |
42. Security Awareness Campaigns
Security awareness should not be limited to one annual presentation.
The organization can use:
- Short security newsletters
- Phishing simulations
- Security tips
- Posters
- Security quizzes
- Incident lessons learned
- Security alerts
- Short videos
- Team discussions
- Awareness campaigns
- Role-specific workshops
Example Monthly Topics
| Month | Topic |
|---|---|
| January | Passwords & MFA |
| February | Phishing |
| March | Data Classification |
| April | Remote Working |
| May | Secure SaaS Usage |
| June | Privacy |
| July | AI Security |
| August | Social Engineering |
| September | Incident Reporting |
| October | Security Awareness Month |
| November | Cloud Security |
| December | Lessons Learned |
The schedule is an example and should be adapted to organizational risk.
43. Phishing Simulation
Where appropriate, the organization may conduct controlled phishing simulations.
The objective should be:
- Improve awareness
- Identify training needs
- Measure improvement
- Reinforce reporting behavior
The objective should not be to embarrass employees.
Useful metrics may include:
- Simulation participation
- Click rate
- Credential-submission rate
- Reporting rate
- Time to report
- Repeat failure rate
- Improvement over time
Results should be handled appropriately and consistently.
44. Measuring Training Effectiveness
Training effectiveness can be measured through:
Knowledge
- Quiz results
- Assessment scores
Behaviour
- Phishing reporting rate
- Security incident reporting
- MFA adoption
- Policy violations
Outcomes
- Reduction in repeated mistakes
- Faster incident reporting
- Improved phishing detection
- Reduced unauthorized application usage
Example
Before awareness campaign:
Phishing reporting rate: 42%
After campaign:
Phishing reporting rate: 76%
This provides more useful evidence of effectiveness than simply recording that employees attended training.
45. Security Awareness Training Records
Training records may include:
- Employee name/identifier
- Department
- Training topic
- Training date
- Training method
- Completion status
- Assessment result
- Trainer/provider
- Next training date
- Exceptions
- Follow-up training
Records should be protected appropriately because they may contain employee information.
46. New Joiner Security Awareness
Security awareness should be incorporated into onboarding.
Before or shortly after receiving system access, new personnel should understand:
- Information security responsibilities
- Acceptable use
- Password/MFA requirements
- Information classification
- Incident reporting
- Remote working
- BYOD requirements
- Privacy
- AI usage
- Customer information handling
- Physical security
Joiner Flow
Join → Awareness → Access → Use → Monitor → Review
47. Refresher Training
Refresher training should be provided periodically and when significant changes occur.
Additional training may be triggered by:
- Security incidents
- New threats
- New systems
- New regulations
- New customer requirements
- New AI tools
- Major technology changes
- Repeated policy violations
- Changes in employee responsibilities
48. Management Responsibilities
Management should:
- Support security awareness.
- Allocate appropriate resources.
- Participate in awareness initiatives.
- Reinforce security expectations.
- Review awareness metrics.
- Support corrective actions.
- Encourage prompt incident reporting.
Management should demonstrate that security is part of normal business operations.
49. Employee Responsibilities
Every employee is responsible for:
- Protecting organizational information.
- Following security policies.
- Completing required training.
- Protecting credentials.
- Using systems appropriately.
- Reporting suspicious activity.
- Participating in awareness activities.
- Asking questions when unsure.
Remember
You do not need to be a cybersecurity expert to make a security-conscious decision.
50. Security Awareness Quick Reference
Before You Click
Check the sender.
Check the link.
Check the request.
Check the context.
Before You Share
Check the information classification.
Check the recipient.
Check authorization.
Use an approved channel.
Before You Approve
Verify the request.
Verify the person.
Verify the transaction.
When Something Goes Wrong
Stop → Report → Follow Instructions
51. Knowledge Check
Question 1
You receive an unexpected MFA approval request.
A. Approve it
B. Ignore it permanently
C. Deny it and report it
D. Send the MFA code to IT
Answer: C
Question 2
You accidentally send confidential customer information to the wrong person.
A. Delete the email and say nothing
B. Wait to see what happens
C. Report the incident immediately
D. Ask the recipient to ignore it and close the matter
Answer: C
Question 3
Can you enter a customer database into any AI tool if it makes your work easier?
A. Yes
B. Only if the AI tool is free
C. Only if the data is confidential
D. No, unless the tool and use case are specifically approved and appropriate controls are in place
Answer: D
Question 4
What should you do if your company laptop is stolen?
A. Wait until the next day
B. Report it immediately
C. Buy a replacement yourself
D. Ignore it if the laptop had a password
Answer: B
Question 5
Should employees share passwords with IT support?
A. Yes
B. Only over phone
C. Only for urgent incidents
D. No
Answer: D
Question 6
What is the safest response to an unusual request from a senior executive?
A. Do it immediately because they are senior
B. Verify the request through an independent trusted channel
C. Forward it to everyone
D. Provide your credentials
Answer: B
52. Security Awareness Completion Checklist
| Requirement | Status |
|---|---|
| New personnel receive security awareness training | ☐ |
| Refresher training is provided periodically | ☐ |
| Role-based training is provided where required | ☐ |
| Phishing awareness is covered | ☐ |
| Password and MFA security is covered | ☐ |
| Information classification is covered | ☐ |
| Privacy and personal data protection are covered | ☐ |
| Remote working is covered | ☐ |
| BYOD is covered | ☐ |
| AI security is covered | ☐ |
| Incident reporting is covered | ☐ |
| Physical security is covered | ☐ |
| Secure cloud/SaaS use is covered | ☐ |
| Training completion is recorded | ☐ |
| Training effectiveness is measured | ☐ |
| Awareness gaps are addressed | ☐ |
| Lessons learned are incorporated | ☐ |
53. Audit Evidence
For ISO 27001 purposes, useful evidence may include:
- Security awareness policy/program
- Training materials
- Training calendar
- Attendance/completion records
- Knowledge assessments
- Phishing simulation results
- Awareness campaigns
- Security newsletters
- Role-based training records
- New-joiner training records
- Refresher training records
- Incident-related awareness activities
- Training effectiveness metrics
- Corrective training records
- Management review of awareness results
The organization should be able to demonstrate not only that training was delivered, but also that personnel received information relevant to their roles and that awareness effectiveness is evaluated where appropriate.
54. Startup-Friendly Security Awareness Program
A startup can operate an effective awareness program without creating excessive administration.
A practical model is:
At Joining
Security Awareness → Policy Acknowledgement → Access
Monthly
One Short Security Topic → 5–10 Minute Awareness Activity
Quarterly
Security Quiz / Phishing Exercise / Role-Based Session
Annually
Comprehensive Security Awareness Training
After Significant Incidents
Lessons Learned → Targeted Awareness → Follow-up
This provides continuous reinforcement without requiring employees to sit through lengthy security presentations every month.
55. ISO 27001 Connection
Security awareness supports the organization’s information security management system by ensuring that personnel understand relevant:
- Information security policies
- Responsibilities
- Security procedures
- Threats and risks
- Information handling requirements
- Incident reporting requirements
- Access-control responsibilities
The organization should retain appropriate evidence demonstrating that relevant personnel have received security awareness and that training is maintained as roles, risks, technology, and business requirements change.
Awareness should also connect with the organization’s:
- Information Security Policy
- Acceptable Use Policy
- Employee IT Usage Policy
- Information Classification Policy
- Access Control Policy
- Remote Working Policy
- BYOD Policy
- AI Acceptable Use Policy
- Incident Response Plan
- Security Incident Management Procedure
- Data Protection/Privacy Policy
- Secure Development Policy
56. Final Principle
An effective security awareness program should follow:
Educate → Reinforce → Test → Measure → Report → Learn → Improve
The objective is not simply:
“Did the employee attend security training?”
The more important question is:
“Can the employee recognize a security risk, make a safe decision, protect information, and report a problem quickly?”
Security awareness turns policies and technical controls into everyday secure behaviour.
