Security Awareness Training
Part of Security Operations, alongside Cyber Security Solutions, Network Operations Center (NOC) Services, Penetration Testing, and Vulnerability Assessments.
Security awareness training is the basic cybersecurity or privacy training program for everyone on staff. TTS Cyber offers it on its own or together with managed IT. Training runs monthly. Employees get short online lessons, and TTS Cyber sends fake phishing emails to staff. These are test messages made to look like scams, also called phishing simulations. The content is tailored to your business, and new hires get training too.
What should a good training program include?
The National Institute of Standards and Technology (NIST) wrote a 2024 guide on security and privacy training programs for federal agencies and other organizations. For a private business it is voluntary guidance, not a legal requirement.
NIST describes three typical parts of a program: awareness activities, experiential learning and practical exercises, and training. It gives phishing simulations as one example of a practical exercise. It says phishing exercises should not be punitive, and no employee should be called out. It also suggests a report-phishing button, telling staff that exercises happen at random and that results guide learning, and having your legal team review how exercises are designed.
Which rules require staff training?
Some rules require it, but only for the groups they cover.
- The Federal Trade Commission (FTC) Safeguards Rule applies to financial institutions under FTC jurisdiction, such as mortgage lenders and tax preparation firms. It requires security awareness training, updated as necessary to reflect risks found in the risk assessment.
- The Health Insurance Portability and Accountability Act (HIPAA) Security Rule applies to covered entities and business associates. It requires a security awareness and training program for all members of the workforce, including management. The U.S. Department of Health and Human Services proposed changes to the rule in January 2025, so check the current text.
- The Cybersecurity Maturity Model Certification (CMMC) program applies to Department of Defense contractors that handle certain federal government information. Its Level 2 requirements include awareness training.
TTS Cyber is not a law firm, and this is general information, not legal advice. If you are unsure whether a rule applies to you, ask your attorney or compliance contact.
What do cyber insurers and Ohio law say about training?
Some cyber insurers ask about training. Ohio law also offers an optional defense to businesses that write and follow a security program based on a recognized framework.
A 2022 Beazley ransomware form asks how often you run interactive phishing training and phishing email simulations for all employees. A 2021 Capitol Specialty form asks whether simulated phishing exercises run at least annually and whether 90% or more of employees passed the latest test. Forms and policies differ, so read your own application.
Ohio Revised Code section 1354.02 gives a business that handles personal information an optional defense to certain data breach lawsuits (tort claims) brought under Ohio law or in Ohio courts. To qualify, among other conditions, the business must create, maintain and comply with a written program. It must have administrative, technical and physical safeguards and reasonably conform to the current version of a recognized framework. The statute does not name training, but training is part of frameworks such as the NIST Cybersecurity Framework. The defense does not make a business immune, and it does not address regulators or contract claims.
Does phishing training change what staff do?
Both sources below found little link between training and clicking. Verizon’s 2025 Data Breach Investigations Report (DBIR) compared industry-wide campaigns where staff had been trained in the last 30 days with campaigns where they had not. Trained staff reported simulated phishing emails at about 21%, versus a 5% base rate. Recent training had only about a 5% relative effect on click rates. The authors could not test cause. They say rewarding reports and making reporting as automated as possible is the practical path, since preventing every click is not realistic.
A 2025 randomized study of more than 19,500 employees at one health system found no significant link between recent annual training and failing a simulated phishing email. Over 56% of users clicked a phishing link at some point, trained or not. The authors say programs as commonly deployed offer limited practical value. They suggest that hardware multi-factor authentication (MFA) and password managers may give a better return. The study measured clicking only.
What’s included
- Short online lessons for employees
- Fake phishing emails sent to staff
- Training for new hires
- Training content tailored to your business
- Monthly training
- Available on its own or with managed IT
What it’s for
- Staff get security training every month.
- Training content that reflects your business.
- People who join partway through the year are included in training.
Frequently Asked Questions
Why train staff at all?
Some rules require staff training, and some insurer forms ask about it, as covered above. In Verizon’s 2025 data, recently trained staff reported simulated phishing emails more often. Verizon’s 2026 DBIR also reports that the non-intentional human element, its broad measure of unintended human involvement, was present in 62% of breaches across all industries. That does not count how many people clicked links. Social engineering, meaning tricking people into acting, was the third most common breach pattern at 16%.
How often should staff get security awareness training?
The FTC Safeguards Rule and the HIPAA Security Rule set no fixed interval for the groups they cover. Rules for other groups may differ. NIST says awareness activities should run on an ongoing basis throughout the year, and describes general-workforce training as often annual but preferably more frequent. Ask your insurance carrier or attorney whether a schedule meets a specific form or rule. TTS Cyber’s training runs monthly.
Do we need phishing tests, or is an annual course enough?
It depends on who is asking. NIST guidance and some insurer forms, both covered above, mention phishing simulations. Ask your insurance carrier or attorney whether a specific form or rule calls for them. TTS Cyber sends fake phishing emails to staff.
Does a low click rate mean our staff are safe?
Not on its own. In the health system study above, failure rates ranged from 1.8% to 30.8% depending on how convincing the fake email was. A low click rate on an easy test may say little about a convincing one. Verizon’s 2026 report also says voice and text-based social engineering need different training and simulation strategies than email phishing.
Does the training fit our business, and what about new hires?
TTS Cyber tailors the training content to your business, and new hires get training. Employees get short online lessons. This page does not list lesson topics, lesson length or how the tailoring works, so ask TTS Cyber about those details before you decide.
What proof of training do insurers or auditors ask to see?
It depends on who is asking. If HIPAA applies to you, the Security Rule requires written records of required actions and activities, kept for 6 years. NIST warns that training records can be sensitive employment data. Ask your insurer or auditor what they want to see.
Related services
Cyber Security Solutions
Security in layers, so a threat one control misses can still be caught by the next. It covers your data, systems and network, and aims to prevent, detect and respond to threats.
Microsoft 365 Management
TTS Cyber manages Microsoft 365 users, licenses, laptops and phones, sets up sign-in and email protection, and handles backup. Offered only with managed IT.
Virtual CISO (vCISO) Services
A Virtual CISO for teams without a security executive: SOC 2, ISO 27001 and CMMC work, vendor risk, incident response ownership, and reporting.
Further reading
From our blog
Industries