Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› How should security teams structure awareness training before…
Governance, Ownership & Risk

How should security teams structure awareness training before moving to advanced phishing simulations and BEC scenarios?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 26, 2026 Domain: Governance, Ownership & Risk

Start with foundational topics such as phishing, ransomware, security essentials, and internal policy basics before moving to advanced simulations. A staged approach helps close knowledge gaps, improves assessment quality, and reduces wasted user time. Teams should also tailor onboarding and refresher modules so every user gets the basics first, then more advanced exercises only where needed.

Why phased awareness training works better than jumping straight to advanced simulations

Advanced phishing simulations and BEC scenarios are most useful when users already recognise the basics of deception, urgency, spoofing, and policy boundaries. If the training starts too high, the exercise measures guesswork rather than resilience. A staged model lets security teams establish baseline literacy first, then use harder scenarios to test judgment instead of simply exposing gaps in terminology or process.

That sequencing also improves signal quality. When foundational knowledge is in place, failures in a simulation are more likely to reflect real weaknesses in reporting behaviour, approval discipline, or verification habits, rather than a user never having learned the warning signs. For that reason, the training path should move from general awareness to role-specific scenarios only after the baseline is consistent.

Foundation-first programs work best when they cover phishing, ransomware, common social engineering patterns, secure handling of internal policies, and the practical meaning of reporting and escalation. The point is not to teach every exploit class up front, but to create shared vocabulary and common expectations before introducing more deceptive content.

How to structure the training path by audience and risk

Start with a core module for all users, then layer content by role, exposure, and business impact. New joiners usually need the basics of email safety, password hygiene, policy compliance, and how to verify requests before they are asked to make decisions under pressure. More experienced users can move sooner into scenarios that involve supplier fraud, invoice interception, payroll diversion, executive impersonation, or help-desk compromise.

A useful structure is to separate awareness from simulation readiness. Awareness modules teach the control points, while simulations test whether those control points are actually used under pressure. That distinction matters because a user who has not yet learned the expected process may fail a scenario for the wrong reason, which weakens both trust in the program and the quality of follow-up coaching.

Refresher content should be targeted, not repetitive. If a team already shows strong performance on obvious phishing, the next round should focus on higher-value behaviours such as contact verification, invoice approval discipline, and escalation paths for unexpected payment or account-change requests. Security teams can reinforce those patterns with phishing-resistant authentication guidance where login protection is part of the broader training message, but the simulation curriculum should still be driven by user readiness rather than tool availability.

What separates a useful simulation program from wasted effort

The most effective programs are calibrated to the learner’s current maturity. Early exercises should verify recognition and reporting habits. Later ones can assess whether the user pauses, verifies, and escalates when the message is unusually urgent, confidential, or business critical. This is especially important for BEC, where the failure mode is often not clicking a link but trusting a request that appears to come from a legitimate executive, finance contact, or supplier.

Security teams should also watch for fatigue. If advanced simulations are introduced before the workforce has the basics, users learn to treat the program as a trick rather than a learning tool. That leads to lower reporting quality, more frustration, and less cooperation with future exercises. A clearer progression usually creates better engagement because people can see why the harder scenarios matter.

Where teams need benchmark content or supporting practitioner material, SANS Security Resources can help reinforce practical awareness themes, while CISA cyber threat advisories are useful for connecting training scenarios to current phishing, ransomware, and fraud patterns. Those references work best when they support an already staged program, not when they are used to replace one.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-14 — Security Awareness and Skills TrainingAwareness training is the primary subject and CIS prescribes staged user training and reinforcement.
CIS-17 — Security Awareness and Skills TrainingUseful for measuring readiness through repeated exercises and improving training quality over time.
Recommendation — Sequence awareness training from baseline phishing education to role-based simulations. Use recurring exercises to validate whether training changes user behaviour.
NIST CSF 2.0PR.AT-01 — All users understand and perform their cyber roles and responsibilitiesThe question is about user readiness before advanced simulations and BEC exercises.
Recommendation — Verify baseline user understanding before introducing advanced fraud scenarios.
NIST SP 800-53 Rev 5AT-2 — Awareness TrainingTraining structure, onboarding, and refreshers are directly governed by awareness training controls.
AT-3 — Role-Based TrainingRole-specific progression is central to tailoring advanced phishing and BEC exercises.
Recommendation — Deliver foundational awareness training before moving to higher-fidelity simulations. Tailor advanced scenarios to role exposure after baseline training is complete.

Practitioner Guidance

What to prioritise: Build the baseline first. If users cannot reliably identify phishing cues, report suspicious messages, and follow policy for verification, advanced BEC simulations will mostly measure immaturity rather than control effectiveness.

What to measure: Track reporting rate, repeat-failure rate, and time-to-report separately for basic phishing and advanced business fraud scenarios. If users perform well on the simple cases but fail on approval or verification steps, the gap is procedural, not just awareness-based.

Common mistake: Do not assume a harder simulation is a better simulation. The right next exercise is the one that tests a skill the user has already been trained to recognise, not one that surprises them before they understand the baseline rules.

Practitioner takeaway: A staged program should prove that users can recognise, verify, and escalate before it asks them to resist sophisticated deception, because advanced scenarios only produce useful data after the basics are stable.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 26, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org