Security Awareness
Launch a Security Awareness Training Program
Start with a short team conversation and free resources. A training platform is optional.
Content review: 2026-09-22 · Estimated effort: Low
Priority and effort are editorial starting points, not calculated risk or mandatory deadlines. Adapt to business impact, vendor instructions, available licenses, and applicable obligations. Test changes before broad rollout.
Before you start
Before starting: provide a clear, non-punitive reporting route and name someone to respond. Do not use real credentials or personal information in training examples.
Put it into practice
- Use free CISA material to discuss suspicious messages, MFA, updates, and password managers at onboarding and in short refreshers.
- Demonstrate how to report suspicious messages or lost devices, including what to do after clicking a link or sharing information.
- Teach finance staff to verify changed payment details through a known separate channel. Tailor administrator and manager guidance to their decisions.
- Practice with clearly identified examples. If using simulations later, obtain authorization, protect privacy, and coach rather than shame. Click rates alone do not measure security.
- Verify: ask staff to locate the reporting route and explain how they would verify an unexpected payment request. Check that reports receive a useful response.
Make a start
Tools and templates
Start with what you already have. “Included” means part of an existing eligible product or subscription, not a free standalone service. Options reviewed 2026-09-22; check current vendor terms before choosing.
Start without another software subscription
Use free CISA materials and the discussion worksheet with the team’s real reporting route.
Where this stops: A paid training platform is optional. Free materials do not provide managed campaigns or prove safe behavior; someone must maintain the content and respond to reports.
See the official sources and eligibility details below. Free software can still require equipment, storage and staff time.
CISA Secure Our World materials
Free public education resources
Choose a tip sheet about phishing, MFA, passwords or updates. Use the worksheet to run a short discussion and practice your actual reporting route.
Limits: Some linked campaign material is archived; check dates and adapt examples. These resources are not a managed training platform or proof of staff competence.
Your information: Read or download public resources without uploading staff records. Keep attendance and training notes limited to what your organization needs.
Official instructions: CISA Secure Our World materials ↗Download a working template
Free to download and adapt for your team. Open CSV files in Microsoft Excel using your existing Office license; Markdown files open in a text editor such as Notepad. Save an Excel Workbook (.xlsx) copy if you add formatting. These are manual worksheets, with no macros, scoring or automatic verification.
- Security awareness session worksheet (Markdown) ↓
Use the short facilitator agenda and clearly fictional payment-change example. Fill in your reporting route before the session.
Fictional worked example
Illustration only. This is not a customer story, lab result, or evidence that your environment is protected. Replace the example entries and record your own observations.
A facilitator discusses a fictional supplier email requesting a change of payment details.
Use the Security awareness session worksheet template.
What to enter before testing
- Facilitator / backup
- Fill in the session leader and alternate
- Where staff report suspicious messages or lost devices
- Fill in the team’s approved reporting contact
- Question or gap (Record useful follow-up table)
- Confirm how to verify supplier changes using a trusted existing contact
How to verify
Tell participants the message is fictional. Ask them to describe the reporting route and independently verify a payment-change request using a known contact, not contact details supplied in the message. Check that the designated responder knows what happens next.
If the result is unexpected
If staff cannot find the route or the responder is unclear, fix those details and repeat the discussion. Do not shame participants, collect passwords or run surprise phishing. Attendance and a correct answer do not demonstrate behavior during a real attack.
Save completed worksheets privately. They can describe security gaps, systems and people. Do not include passwords, recovery keys or confidential message content. This site does not receive your edits; a cloud editor or synced folder may send them to its provider.
Sources and review approach
Original small-team guidance with selected NIST CSF 2.0 alignments, not an official crosswalk or a complete framework implementation. These instructions are a starting point, not a claim of testing in your environment.
- NIST CSF 2.0: PR.AT-01, PR.AT-02: general and role-specific learning
- https://www.nist.gov/publications/nist-cybersecurity-framework-csf-20 ↗
- https://www.cisa.gov/secure-our-world ↗