Playbook · Worldwide

Security Awareness Training Program Blueprint

Annual click-through training satisfies nobody. This blueprint builds a role-based program with a twelve-month calendar, realistic simulations, and the metrics that show behavior actually changed. It maps to ISO/IEC 27001 Annex A 6.3, SOC 2 common criteria, GDPR Article 39, and HIPAA workforce training requirements.

Role-based curriculum

  • All staff: phishing and social engineering, data handling, device hygiene, and incident reporting.
  • Executives and finance: business email compromise, payment fraud verification, and deepfake voice attempts.
  • Engineers: secure coding, secret management, dependency risk, and safe use of AI coding assistants.
  • IT and cloud administrators: privileged access hygiene, change discipline, and identity attack paths.
  • Human resources and recruiting: candidate fraud, credential handling, and sensitive record protection.
  • Customer support: identity verification before account changes, and pretexting resistance.
  • Privacy-facing roles: data subject rights handling and cross-border transfer rules.
  • New joiners: security onboarding completed within the first week of system access.

Twelve-month calendar

  1. 01Quarter one: onboarding refresh for all staff, plus a baseline phishing simulation with no prior warning.
  2. 02Quarter one: executive and finance session on payment fraud and voice impersonation.
  3. 03Quarter two: engineering deep dive on secrets, dependencies, and AI assistant guardrails.
  4. 04Quarter two: simulated credential harvesting campaign with immediate teachable moments.
  5. 05Quarter three: privacy and data handling module tied to your regulatory footprint.
  6. 06Quarter three: tabletop exercise for department leads on incident escalation.
  7. 07Quarter four: annual compliance module, policy re-acknowledgement, and program metrics review.
  8. 08Continuous: monthly short communications tied to real incidents and current threat activity.

Metrics that show behavior change

  • Phishing simulation failure rate, tracked separately for privileged users.
  • Reporting rate, since the goal is faster reporting rather than only fewer clicks.
  • Median time from simulated phishing delivery to first employee report.
  • Repeat-failure population and the targeted coaching applied to it.
  • Training completion within the required window, by department.
  • Real-world incident volume attributable to human error, tracked quarter over quarter.

Evidence to retain

  • Completion records with dates for every worker, including contractors.
  • Signed policy acknowledgements linked to the current policy version.
  • Simulation campaign reports and the remediation applied to repeat failures.
  • Onboarding training evidence tied to account provisioning dates.
  • Program plan, curriculum, and management review of the annual metrics.

Want an awareness program that changes behavior?

Dephiant designs the curriculum, runs the simulations, and reports program outcomes in language your leadership and auditors both accept.