# Security awareness session worksheet

Purposeful Security | Template version 1.0 | 2026-09-22

Free to download and adapt for your team. Open in a text editor. This is a short discussion worksheet, not a phishing simulation or certification. Use fictional examples and do not collect passwords or personal browsing histories.

- Facilitator / backup: [fill in]
- Session date and audience roles: [fill in]
- Where staff report suspicious messages or lost devices: [verified route]
- Alternative reporting route during an email outage: [fill in]
- Who acknowledges reports and expected coverage: [fill in]
- Public resource selected and date checked: [fill in]

## Before the session

- [ ] Confirm that the reporting route reaches someone who can respond.
- [ ] Choose one relevant public tip sheet; check its date and applicability.
- [ ] Prepare a clearly labeled fictional example with no working malicious links.
- [ ] Explain that reporting a mistake promptly is encouraged.

## Facilitator agenda

1. Show the reporting route and describe what information is useful: what happened, when, and a safe way to contact the reporter. Follow your organization's process for preserving a suspicious message.
2. Explain that an unexpected request for passwords, MFA approvals or payment changes deserves verification using a known separate channel.
3. Discuss the fictional example below. Do not send a surprise message or collect credentials.
4. Ask someone to locate the reporting route and explain the next step after clicking an unexpected link.
5. Record unresolved questions and assign a follow-up owner.

## Fictional example: changed supplier bank details

A message claims a regular supplier has changed bank accounts and requests payment today. It includes a new phone number for confirmation.

Discussion prompts:
- Which details would you verify before payment?
- Where would you find a previously verified supplier contact, independent of this message?
- Who can approve payment changes in your organization?
- How would you report concern without replying to the suspicious message?

Suggested response: pause the change, verify through a previously established contact route, follow internal approval rules and report the suspicious request. Familiar branding or an urgent tone is not proof of authenticity.

## Record useful follow-up

| Question or gap | Owner | Target date | How to verify | Actual outcome |
| --- | --- | --- | --- | --- |
| [fill in] | [fill in] | [fill in] | [fill in] | Not checked |

Collect only training records your organization needs; keep them restricted. Attendance or a correct answer in this session does not prove resistance to phishing.

Public resources: https://www.cisa.gov/secure-our-world
Related guide: https://purposefulsecurity.com/remediations/security-awareness-training
