Simple explanation
Technology alone doesn't secure an organization — people do, or fail to. This lesson covers how organizations train, test, and reinforce good security behavior in their workforce.
Technical explanation
Phishing campaigns — organizations run simulated phishing emails against their own employees to measure and improve susceptibility over time, distinct from actual malicious phishing.
Recognizing phishing and responding to reported suspicious messages — training people to spot red flags (urgency, mismatched sender domains, unexpected attachments) AND making sure there's an easy, low-friction way to report something suspicious.
Anomalous behavior recognition: risky (behavior that increases risk even if not malicious, like disabling security software "to get work done faster"), unexpected (behavior outside someone's normal role/pattern), unintentional (a genuine mistake, like accidentally emailing a file to the wrong recipient).
User guidance and training topics: policies/handbooks, situational awareness, insider threat awareness, password management, removable media and cable security, social engineering recognition, operational security (protecting information about operations that could aid an attacker), and considerations specific to hybrid/remote work environments (home network security, physical security of a home office).
Reporting and monitoring: both initial training (onboarding) and recurring training (ongoing, since threats and reminders both need refreshing over time).
Development and execution — building a training program that's actually engaging and measurable, not just a checkbox annual video nobody retains.
Synonyms / related terms
| Term | Means | |---|---| | Security awareness training | The umbrella term for this whole practice area | | Simulated phishing | Internal phishing campaigns used for training/measurement |
Concept Check
"An employee disables their laptop's antivirus because it's slowing down a presentation, intending to re-enable it afterward but forgetting." This is best categorized as risky behavior rather than purely unintentional — the decision to disable a security control was a conscious choice, even though leaving it disabled afterward was a mistake. The distinction matters because the training intervention is different: risky behavior needs behavioral/policy reinforcement, not just a reminder.
Interview-style Q&A
Q: Why run recurring security awareness training instead of just training once at hire? A: "Two reasons: threats evolve — phishing techniques from three years ago don't reflect what employees will actually face today — and retention naturally decays over time even for unchanging material. Recurring, periodically refreshed training keeps both the content current and the awareness itself from fading."
Memory trick
"Report, Recognize, Reinforce, Repeat" — the four Rs of a security awareness program: make reporting easy, teach recognition, reinforce with simulated phishing, and repeat the cycle regularly rather than treating it as a one-time event.