A chain is only as strong as its weakest link. In most organizations the firewall has a budget line, the endpoint agent has a budget line, and the email gateway has a renewal date in the calendar. The person deciding whether to click has an induction slide deck from three years ago.
That is not a failure of your people. It is the one link in the defence nobody funded, and it is the link involved in 62% of breaches.*
It is also the only control that every major security and privacy framework names explicitly. SOC 2, ISO 27001, PCI DSS, HIPAA, CCPA, CMMC, NIST, PIPEDA and GDPR all require it by name. The clause references are set out at the foot of this page.
Yes, and it is one of the very few security controls with a measurable before and after. Run a simulated phishing campaign before you train anyone, then run the same measurement once a continuous program is underway. Organizations that combine regular training with regular simulation typically cut their click rate roughly in half within the first few months, and it keeps falling from there.
The shape of that curve matters more than the number. Most of the improvement arrives between the third month and the twelfth, and it holds after that. Which tells you something useful about how not to run it. A single annual course, completed in November because the audit is in December, produces almost none of that gain. It satisfies the requirement and changes nothing.
Training is the only control on your stack that gets stronger every quarter instead of depreciating.
There is a second effect that rarely gets measured and matters more. A workforce that has been trained does not merely click less. It reports faster. Every reported message is early warning your email gateway did not give you, on the specific lure that got through your filtering, from inside your own organization. That is a detection capability you cannot buy.
Most organizations do not fail at buying a training platform. They fail at operating one. The campaign scheduled once and never repeated. The twelve people who never finished the course. The report nobody could produce when the auditor asked. So we offer it both ways, and most clients choose the first.
We operate the entire program. Your team does not spend its time on scheduling, chasing or reporting. Our specialists do that work, and your management receives the evidence on a schedule.
We run it as a training program, not a trap. The number we report on is the report rate, not the click rate, because a workforce that reports quickly is worth more than one that merely clicks less. Anyone who clicks gets a short piece of training immediately and privately, not a message to their manager. And we will tell you if a campaign you have asked for crosses a line your people will remember longer than the lesson.
If you would rather run it in house, we provision and configure the platform for your organization, sync your users, and hand you the keys.
You can start on the platform and move to fully managed later. Most organizations that try to run it in house end up moving.
Ready built campaign kits with new scenarios added every month, drawn from the lures actually circulating: invoice fraud, credential harvesting, delivery notices, internal impersonation. Send times and message content are randomized across your user base so people are not warning each other in the hallway. Campaigns can be customized, including attachments, or built from scratch for a scenario specific to your organization.
Short animated video lessons with a quiz at the end, not an hour long slide deck. Dozens of courses covering phishing, passwords and credential hygiene, data handling, physical security, remote working and role specific risk, available in multiple languages.
Training and simulations can be sent from a custom domain your staff recognize, and simulated phishing is delivered in a way that survives your own email filtering. A campaign should measure how your people respond, not how your gateway performs.
Users and groups sync from your directory rather than being maintained by hand. Campaigns can be scheduled up to a year ahead, so the annual obligation is planned in one sitting. Reports distribute themselves on the cadence you choose.
Organization level metrics for the board conversation, showing how the click rate and the report rate are moving quarter over quarter. Individual level detail for the operational one: who clicked, who reported it, who opened the training and stopped halfway. The first is what you present. The second is what you act on.
There is a second reason to run this properly, and it arrives the day an auditor asks. Nobody asks whether you bought a training platform. They ask for the completion record and the dates. On the fully managed program your leadership receives, monthly:
Cyber insurers now ask the same question at renewal. We coordinate with your carrier and provide the completion records they ask for.
Twelve months of dated completion records is the difference between a control that works and a licence that sits unused.
Directory sync, groups mapped to departments and roles, platform branded to your organization. We agree the training cadence and who receives the reports.
Baseline phishing simulation, run before any training. This is your starting number and the one everything afterwards is measured against. No announcement, because a baseline people were warned about is not a baseline.
First training assignment goes out and the baseline results are reviewed with you. We agree what happens with repeat clickers before the situation arises rather than after.
A new simulation with different lures and randomized timing. Training continues on your monthly or quarterly schedule. Report to management. New joiners enrolled as they arrive.
Program review against your current framework obligations and the threats actually reaching your organization, plus the dated evidence pack for your audit or your insurance renewal.
At minimum on hire and once every twelve months, which is the floor in PCI DSS and the practical expectation in ISO 27001 and HIPAA. Annual only training is compliant and close to useless, because retention falls off within weeks. Quarterly is the cadence we recommend, and monthly micro training works well in organizations with high turnover or a heavy regulatory load.
Expect a measurable drop in the click rate by the end of the first quarter, with the largest share of the improvement arriving between the third month and the twelfth. It holds from there as long as the program keeps running. This is the reason we do not recommend an annual only course. The gain comes from repetition, not from the content itself.
Every major one. SOC 2, ISO 27001, PCI DSS, HIPAA, CCPA, CMMC, NIST CSF, PIPEDA, Quebec Law 25 and GDPR all name it as a control, with the clause references set out in the table at the foot of this page.
Yes. Simulated messages are delivered so that your own gateway does not quarantine them before anyone sees them. Otherwise you would be measuring your filter rather than your people, and your filter is not the thing the framework is asking about.
Yes. Your own content can be uploaded alongside the standard library and assigned like any other module, so induction, an acceptable use policy or an industry specific briefing all sit in the same completion record.
The course library is available in multiple languages and users can be assigned content by group. Tell us which languages you need and we will confirm coverage before you commit.
Carriers increasingly ask whether awareness training runs and how completion is tracked. The reporting is built to answer that directly. We coordinate with your carrier and supply the documentation they request. We are not on carrier panels and we do not place coverage.
Most IT Directors know training is expected. Fewer can point to the clause when a board member asks why it is in the budget. Here it is, framework by framework.
| Framework | Control | What it requires |
|---|---|---|
| SOC 2 | CC2.2 | Common criteria require the organization to internally communicate information, including security responsibilities, so personnel can carry out their duties. |
| ISO/IEC 27001:2022 | Annex A 6.3 | Personnel receive appropriate information security awareness, education and training, and regular updates to organizational policy, relevant to their role. |
| PCI DSS v4.0.1 | 12.6.3 and 12.6.3.1 | A formal security awareness program delivered on hire and at least once every twelve months, reviewed annually and updated as threats change, covering phishing and related social engineering and acceptable use of end user technologies. |
| HIPAA | Sec. 164.308(a)(5) and Sec. 164.530(b)(1) | The Security Rule requires a security awareness and training program for all workforce members, including periodic security reminders and malicious software protection. The Privacy Rule requires workforce training on the policies governing protected health information. |
| CCPA and CPRA | 11 CCR 7100 | Training for all individuals responsible for handling consumer privacy inquiries and rights requests, covering the requirements of the Act and how to direct consumers to exercise their rights. Narrower in scope than the security frameworks above. |
| CMMC | AT domain | Inherits the NIST SP 800-171 Awareness and Training family, which requires role based training and insider threat awareness for personnel handling controlled unclassified information. |
| NIST CSF 2.0 | PR.AT | Personnel are provided with awareness and training so they possess the knowledge to perform their security relevant duties. |
| PIPEDA | Principle 4.1.4 | Organizations must train staff on the policies and practices protecting personal information, as part of the accountability principle. |
| Quebec Law 25 | Governance | Documented governance policies and practices for the protection of personal information, with staff made aware of them. |
| GDPR | Art. 39(1)(b) | Awareness raising and training of staff involved in processing operations, monitored by the data protection officer. |
Every one of these asks for the same two things: that training happened, and that you can prove who did it. The second is where most organizations fail the audit.
If the honest answer is no, that is the gap, and it is not the training itself. Book a preparedness call and we will show you what your framework requires, what the evidence needs to look like, and where your click rate sits today.
* Verizon 2026 Data Breach Investigations Report: 62% of breaches involved the human element.