Join our Newsletter — 33% off our NHI Course

What should teams do first when building a security awareness training program?

The first step is to build a training plan tied to real risk. Identify the roles, devices, and behaviours that create the greatest exposure, then choose topics for phishing, passwords, privacy, mobile use, malware, and social engineering. From there, track analytics, test understanding, and refine the program as threats and employee needs change.

Start with the risk the training is meant to reduce

A useful awareness programme starts with the behaviours and roles that create the most exposure, not with a generic annual slide deck. That means mapping who handles sensitive data, who approves payments, who works on mobile, who manages credentials, and where phishing or social engineering would cause the most harm. For teams dealing with credentials and secrets, the exposure is often larger than it looks, as NHIMG’s Ultimate Guide to NHIs, What are Non-Human Identities notes that 96% of organisations store secrets outside secrets managers in vulnerable locations.

The practical goal is to prioritise topics by impact, not by familiarity. A finance team may need stronger simulation and coaching around invoice fraud and account takeover, while engineering teams may need sharper guidance on secret handling, package trust, and device hygiene. Awareness only changes behaviour when the training reflects the actual attack paths people face.

Build the first version around the highest-value behaviours

Once the exposure map is clear, choose a small set of behaviours that are most likely to reduce risk quickly. For most programmes, that includes phishing recognition, password and MFA hygiene, privacy handling, safe mobile use, malware avoidance, and basic social engineering resistance. The training should explain not only what to do, but why the behaviour matters in the specific workflow the employee owns.

That first version should be operationally simple. Focus on one or two high-risk habits per audience, then reinforce them with short, repeatable learning moments and scenario-based testing. If the content is too broad on day one, teams usually remember the message but not the action.

Measure whether the programme changes decisions, not just attendance

A training programme should be treated like a control, so the first build needs a measurement plan from the start. Track completion, quiz performance, simulation outcomes, repeat failure patterns, and whether specific teams are improving on the behaviours that matter most. If phishing remains the dominant exposure, the benchmark is not training volume, it is fewer risky clicks, fewer credential submissions, and faster reporting.

Use those signals to refine the curriculum. If a topic produces little behavioural change, shorten it or change the format. If one group keeps failing the same scenario, treat that as a control gap that may need manager involvement, process changes, or more targeted coaching rather than more generic awareness material.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.OC-01 — Organizational Context Awareness topics should reflect the organisation's highest-risk roles and workflows.
PR.AT-01 — Awareness and Training The question is about establishing an effective awareness training program.
Recommendation — Map training priorities to the organisation's risk context and critical business behaviours. Define and deliver role-based security awareness training with periodic reinforcement.
CIS Controls v8 14 — Security Awareness and Skills Training This control directly addresses building a security awareness program and measuring participation.
Recommendation — Implement role-based awareness training and track participation, testing, and improvement.
NIST SP 800-63 IAL2 — Identity Assurance Level 2 Training on phishing and account protection is closely tied to stronger identity proofing and safer access decisions.
Recommendation — Use stronger identity assurance processes where risky access decisions depend on user identity confidence.

Practitioner Guidance

What to prioritise: Start with the audiences and behaviours that would create the largest loss if they were exploited, because that is what makes the programme defensible as a security control rather than an HR activity. For identity-heavy environments, it is often worth pairing user awareness with the controls that govern secrets, access, and escalation paths, since training alone will not absorb all the risk.

What to verify: Before scaling content, verify that each topic maps to a real threat scenario the audience actually encounters, and that managers can explain the expected behaviour in plain terms. If you cannot tie a module to an observable risk or a measurable behaviour, it probably belongs in a later phase.

Practitioner takeaway: The first build should be risk-led and behaviour-led, with measurement in place from the start, because awareness only matters when it changes the decisions people make under pressure.