Courseiva
CISMChapter 11 of 17Objective 3.3

Security Awareness, Training, and Education

Security awareness, training, and education is the practice of systematically teaching people in an organisation how to protect information from threats. For a CISM, this matters because most security breaches start with a human mistake, not a broken firewall; you need a deliberate programme to turn every employee from a potential vulnerability into a human firewall.

12 min read
Intermediate
Updated Jul 23, 2026
Reviewed by Johnson Ajibi· Senior Network & Security Engineer · MSc IT Security

A simple way to picture Security Awareness, Training, and Education

The Fire Drill and Restaurant Kitchen Analogy

A busy restaurant kitchen on a Saturday night. The head chef knows the menu inside out, but the new prep cook has never used a mandoline slicer, the dishwasher doesn't know where the fire extinguisher is, and the sous chef just learned that the walk-in freezer door has a safety release from the inside.

The chef doesn't just shout, 'Be safe!' and hope for the best. Instead, he runs a specific, repeated programme. First, a new-hire orientation: everyone watches a video on knife safety, passes a quiz on the fire suppression system, and signs a sheet confirming they know the allergy station procedures. That is training — teaching someone exactly how to perform a task correctly.

Next, every Tuesday, the whole team huddles for a five-minute 'safety moment.' The chef points out that the mop bucket left in the aisle is a trip hazard, or reminds everyone to check the temperature log on the raw chicken. That is awareness — keeping the topic top-of-mind so people don't get complacent.

Finally, twice a year, the chef schedules a full fire drill. The team practises evacuating the dining room, using the Ansul system over the grill, and calling 911. That is education — building deep understanding and muscle memory for a complex scenario.

In information security, you do the same with your organisation's people. You train them on the specific tool (how to use the password manager), you raise awareness about current threats (phishing emails this quarter), and you educate a few key people (like IT staff or department heads) on the broader principles so they can make good decisions when something new happens.

How It Actually Works

Security awareness, training, and education is a three-layer programme designed to reduce the risk that your organisation's own people will accidentally cause a data breach. It is not a one-time lecture or a single email. It is a sustained, structured effort that covers three distinct levels of learning.

Layer 1: Security Awareness. Awareness is the baseline. Its goal is to make sure every employee knows that security exists and that it matters to their job. Awareness activities are short, frequent, and designed to keep the topic visible. Common examples include a monthly phishing simulation where a fake email is sent to test if people click on it, a poster in the break room reminding people not to leave their laptop unlocked, or a five-minute video at the start of a staff meeting about a new scam targeting the industry. Awareness does not teach someone how to configure a firewall. It simply keeps the idea of 'think before you click' front of mind.

Layer 2: Training. Training is more specific and task-oriented. It teaches a person how to perform a particular security-related action properly. For example, if your organisation uses a new encryption tool for email, you run a training session that walks everyone through the steps: open the email, click the lock icon, enter the recipient's secure key. Training has a clear start and end, and it is usually assessed — the employee must demonstrate they can do the task correctly. Other examples include training on how to spot a phishing link (hover over the URL, check the domain spelling), how to create a strong passphrase using a password manager, or how to properly dispose of physical documents containing customer data.

Layer 3: Education. Education is the deepest layer. It is about building understanding of the principles behind security, so a person can apply good judgement to situations they have never seen before. Education is typically reserved for people with special responsibilities — IT staff, security team members, department heads, or anyone who handles sensitive data regularly. An educated employee understands *why* a phishing email works psychologically, not just how to spot one. They understand the concept of the 'attack surface' and can recognise when a new cloud app introduces risk. Education often involves formal courses, certifications (like CISM itself), or structured reading and discussion.

Why three layers? Because a single approach fails. A one-time training session gets forgotten in a week. Continuous awareness without depth doesn't build real skill. And deep education for everyone is too expensive and time-consuming. The three-layer model ensures that the whole organisation gets the basic 'don't click on weird links' message repeatedly (awareness), that people with specific roles get the exact skills they need (training), and that the people who make security decisions understand the big picture (education).

What does a CISM actually measure in this domain? The exam expects you to know how to plan, develop, deliver, and evaluate these programmes. You need to understand the difference between awareness and training (the exam loves this distinction). You also need to know about measuring effectiveness — for example, tracking the 'phish-prone percentage' (the rate at which employees click on test emails) before and after a training campaign. You should be able to argue why a blended approach (awareness + training + education) is more effective than any single method. You will also be tested on the concept of 'learning objectives' — the idea that every training module should have a clear, measurable goal (e.g., 'by the end of this module, the learner will be able to identify three signs of a phishing email').

Real-world implementation details. A typical programme starts with a risk assessment. You identify which risky behaviours are most common in your organisation — maybe it's weak passwords, or employees sending sensitive files to personal email, or falling for CEO fraud scams. Then you design awareness content to address those specific risks. You schedule recurring training for high-risk groups (like finance staff who process wire transfers). You also establish a governance process: who approves the content? How often is it updated? How do you handle an employee who repeatedly fails phishing simulations?

The budget reality. Many organisations underfund this area because it is not a technology purchase. A CISM must advocate for budget by framing it as a risk reduction investment. The cost of a serious data breach caused by a single employee mistake can run into millions of pounds. Spending even 50,000 pounds per year on a comprehensive awareness and training programme is a fraction of that potential loss.

The legal and compliance angle. Many regulations explicitly require security awareness training. For example, the General Data Protection Regulation (GDPR) in Europe requires organisations to ensure their staff are trained on data protection. The Payment Card Industry Data Security Standard (PCI DSS) requires annual security awareness training for any employee handling credit card data. In healthcare, HIPAA in the United States has similar requirements. A CISM must ensure their programme meets these regulatory mandates, or the organisation faces fines.

Key distinction: awareness is NOT training. This is the most important distinction for the CISM exam. Awareness is about 'keeping it on the radar'. Training is about 'building a specific skill'. If someone watches a two-minute video about ransomware, that is awareness. If they then complete a 30-minute interactive module that teaches them how to properly report a ransomware incident using the organisation's incident response tool, that is training. The exam will test your ability to categorise activities correctly.

The three roles in a programme. A CISM must understand who does what. Senior leadership (board, executives) must approve the programme and allocate budget. The CISM or security manager designs the strategy and selects the content. Human resources (HR) often helps with scheduling and tracking completion. IT manages the technical platform (like the Learning Management System, or LMS). And every employee is a participant.

Evaluation is essential. A programme that no one ever evaluates is useless. Common metrics include completion rate (did everyone take the required training?), quiz scores (did they understand it?), phish-prone percentage (did behaviour change?), and time-to-report (how quickly do employees report a suspicious email to the security team?). The most mature organisations also do periodic 'red teaming' — for example, sending a fake USB stick with malware to see if employees plug it into their computers. The results then inform the next cycle of training.

The CISM exam focus. Expect multiple-choice questions that ask you to identify the correct sequence (awareness, then training, then education for specialists). Expect 'which of the following is an example of security awareness?' — the answer will be something like 'posting security tips on the company intranet', not 'conducting a classroom workshop on encryption'. Expect scenario questions where a manager wants to address a specific problem (e.g., employees are falling for phishing) and you must recommend the appropriate intervention (training, not just awareness). Also expect questions on metrics — for example, 'which metric best indicates the effectiveness of a security awareness programme?' The answer: 'a reduction in the number of users who click on simulated phishing emails'.

This flowchart shows the continuous cycle of designing, delivering, measuring, and improving a security awareness, training, and education programme.

Walk-Through

1

1. Assess the Risk

Identify which human behaviours pose the biggest risk to the organisation. Survey the workforce, review past incident logs, and interview department heads. For example, you might discover that the finance team frequently falls for fake wire transfer requests, while the IT team misconfigures cloud storage.

2

2. Define Learning Objectives

For each identified risk, write a clear, measurable objective. For example: 'After completing this module, the learner will be able to correctly identify three red flags in a CEO fraud email and follow the two-step verification process before approving any wire transfer.' This step ensures every training has a purpose you can test.

3

3. Select Delivery Methods

Choose the right format for each audience. For awareness across the whole organisation, use short videos, posters, and email newsletters. For specific skills (training), use interactive modules with simulations. For education, use workshops, formal courses, or online learning platforms. The method should match the content complexity and the audience's schedule.

4

4. Develop or Procure Content

Either build custom content in-house using an LMS or buy pre-built modules from vendors like KnowBe4, Proofpoint, or SANS. For most organisations, buying is faster and cheaper. Custom content is better when you have unique policies (e.g., a specific verification protocol). Ensure the content is reviewed by legal and HR for compliance.

5

5. Deliver and Track

Roll out the content according to your schedule. For awareness, push emails or post materials. For training, assign modules in the LMS with deadlines. Track completion rates in real time. For simulations, send test emails in waves. Use the LMS data to identify departments or individuals who are falling behind.

6

6. Measure Effectiveness

Run the same simulations before and after training to compare click rates. Review quiz scores. Calculate the phish-prone percentage and time-to-report metrics. Gather qualitative feedback from employees about what they found useful or confusing. This data tells you whether the programme actually changed behaviour.

7

7. Adjust and Repeat

Use the measurement data to refine the programme. If a department shows no improvement, change the delivery method or content. If a new threat (like a new type of deepfake scam) emerges, update the awareness materials. The programme is never finished; it cycles continuously to stay relevant to the current threat landscape.

What This Looks Like on the Job

A real-world scenario: A mid-sized law firm with 500 employees has a problem. Twice in the last six months, staff have fallen for 'CEO fraud' emails — where an attacker pretends to be a senior partner and asks the finance team to wire money urgently. Each incident cost the firm over 100,000 pounds before the fraud was caught. The partners hire a CISM to fix the problem.

Here is what the CISM actually does, step by step:

1.

Risk assessment. The CISM interviews the finance team, reviews the email logs from the two incidents, and identifies the exact behaviour that led to the loss: staff were not verifying wire transfer requests by phone or in person before acting. The root cause is not a lack of technology — the email system had spam filters. The root cause is a lack of awareness and specific training on the wire transfer verification procedure.

2.

Programme design. The CISM designs a three-layer plan. For awareness: a monthly email newsletter highlighting recent scams, plus a quarterly all-hands meeting where the IT director presents a 'scam of the quarter' example. For training: every finance team member must complete a 20-minute interactive module on the 'three-step verification protocol' for wire transfers. They must pass a test with 100% accuracy before being allowed to process payments. For education: the head of finance and the legal team attend a half-day workshop on the legal and financial risks of social engineering, so they can better assess new threats.

3.

Selection of delivery method. The CISM evaluates options. They could use a commercial training platform like KnowBe4 or Proofpoint, which offers pre-built modules and phishing simulation tools. Or they could build custom content using an internal Learning Management System. The CISM chooses the commercial platform because it provides ready-made phishing templates that can be customised to look like real CEO fraud attempts, and because it automatically tracks completion rates and phish-prone scores.

4.

Phishing simulation as assessment. The CISM sets up a baseline. Before any training, they send a fake CEO fraud email to the entire finance team. 60% of recipients click the link and attempt to 'approve' the fake wire transfer. This gives a measurable starting point. The CISM then launches the training module for the finance team. After the training, they run the same simulation again. The click rate drops to 5%. This proves the training is effective.

5.

Ongoing awareness campaigns. The CISM does not stop at the one-time fix. They schedule quarterly simulations targeting different departments with different attack scenarios — phishing for email credentials, fake voicemail notifications, USB drops in the car park. Each simulation is followed by a targeted awareness message: 'Remember: we just sent a test email and 10 people failed. Here is how to spot the real ones.'

6.

Governance and policy updates. The CISM works with HR and legal to update the company's Acceptable Use Policy to explicitly state that employees must complete mandated security training within 30 days of hire and annually thereafter. They also define a progressive discipline process: first failed simulation = reminder and re-training; second = written warning; third = loss of access to sensitive systems.

7.

Reporting to leadership. Every quarter, the CISM presents a one-page dashboard to the firm's management board. The dashboard shows: percentage of employees who completed required training, average quiz score, simulation click rates by department, and number of real incidents reported by employees (as opposed to detected by automated systems). The board sees that the click rate dropped from 60% to 5% in finance, and that no real wire transfer fraud has occurred since the programme launched. The budget for the programme is approved for the next year.

8.

Continuous improvement. After six months, the CISM notices that the engineering department has a higher click rate than other departments. They interview the engineers and learn that the engineers are too busy with deadlines to pay attention to the awareness emails. The CISM adjusts the delivery method for that department: instead of email, they now integrate a two-minute security tip into the engineers' weekly stand-up meeting. The click rate drops.

This scenario shows that a CISM's job is not just to run a training course. It is to analyse the specific human risks in an organisation, design a programme that addresses those risks, measure the results, adjust the approach based on data, and communicate the value to leadership in financial terms.

How CISM Actually Tests This

The CISM exam tests this domain with a mix of definitional questions, scenario-based decisions, and metric interpretation. Here is exactly what you need to know.

Question type 1: Definitional distinction. The exam will give you a list of activities and ask you to categorise each as 'awareness', 'training', or 'education'. The traps: they will include activities that sound similar but are different. For example: 'A monthly newsletter highlighting recent phishing trends' — that is awareness. 'A hands-on workshop teaching employees how to use the company's VPN client' — that is training. 'A semester-long university course on information security management' — that is education. Memorise the definitions rigidly.

Question type 2: Scenario — which intervention? The question will describe a problem: 'An organisation has experienced multiple data breaches due to employees misconfiguring cloud storage permissions.' The answer will be training (specifically, training on how to configure permissions correctly), not awareness (which would not teach the specific skill) or education (which is too broad). The trap: they might offer 'increase security awareness' as an option. Do not pick it. Awareness only works for problems of attention, not for problems of skill or knowledge.

Question type 3: Metrics and evaluation. The exam loves questions about how to measure the effectiveness of a programme. Memorise these: - Phish-prone percentage (or click rate) = the percentage of people who click on a simulated phishing email. A decreasing trend indicates improvement. - Completion rate = percentage of employees who completed mandatory training. This measures compliance, not effectiveness. - Quiz score = average test score after training. High scores suggest understanding. - Time to report = average time between a simulated email being sent and an employee reporting it to security. Shorter is better. - Number of real incidents reported by users = a leading indicator of a mature security culture.

Question type 4: Programme structure. They will test your knowledge of the correct sequence. The standard approach is: assess the risk, define learning objectives, select delivery method, deliver content, evaluate, adjust. They might present a sequence with steps out of order and ask you to identify the flaw.

Question type 5: Governance and legal. You may be asked which regulation requires security awareness training (GDPR, PCI DSS, HIPAA are the common ones). You may also be asked who should approve the security awareness programme budget (answer: senior management or the board).

Traps to watch out for: - Confusing 'awareness' with 'training' in a scenario where the problem is a lack of skill. The exam will set this trap deliberately. - Choosing 'education' when the audience is the entire organisation. Education is for specialists. Training and awareness are for everyone. - Picking a single solution when a blended approach is needed. The exam will sometimes offer a single method (e.g., 'a quarterly newsletter') as the whole solution. The correct answer will be 'a combination of awareness, training, and education'. - Ignoring evaluation. If a question asks what to do after delivering training, the answer is 'measure effectiveness' or 'run a simulation', not 'move on to the next topic'. - Thinking that one-time training is enough. The exam emphasises that security awareness and training must be continuous and recurring.

Key concepts to memorise verbatim: - Awareness = keeping security on the radar. - Training = teaching a specific skill. - Education = building deep understanding. - Learning objectives = measurable goals for each training module. - Blended approach = using multiple methods (videos, simulations, in-person) for best results. - Senior management must approve the programme budget. - The most effective metric for behaviour change is the phish-prone percentage trend.

Exam-relevant frameworks and standards: You do not need to memorise details of ISO 27001 or NIST for this specific domain, but you should know that both standards require a security awareness and training programme. The NIST Cybersecurity Framework (CSF) has a specific category under 'Protect' called 'Awareness and Training'. ISO 27001 clause 7.2 and 7.3 cover competence and awareness. The exam may reference these by name.

What the exam does NOT test: They will not ask you to design a specific curriculum. They will not ask you the exact cost of a specific training platform. They will not ask you to write a training script. The exam focuses on the management and governance of the programme, not its detailed execution.

Key Takeaways

Security awareness keeps security visible and top-of-mind; training teaches specific skills; education builds deep understanding for decision-makers.

The most effective security programmes use a blended approach combining awareness, training, and education tailored to different roles.

Behaviour change is the true measure of success, not completion rates or quiz scores — track metrics like phish-prone percentage over time.

One-time training is insufficient; security content must be updated and delivered continuously to address evolving threats.

Every person in the organisation, from the CEO to the janitor, is a potential target and must be included in the programme.

Awareness and training complement technical controls (like spam filters and firewalls); they do not replace them in a defence-in-depth strategy.

The CISM exam distinguishes between awareness (keeping it on the radar) and training (building a specific skill) — memorise this distinction.

Senior management must approve the programme budget and champion the initiative for it to succeed organisation-wide.

Easy to Mix Up

These come up on the exam all the time. Here's how to tell them apart.

Security Awareness

Goal is to keep security visible and top of mind

Delivery is short, frequent, and broad (posters, emails, newsletters)

Measured by engagement (views, reach) not skill demonstration

Security Training

Goal is to teach a specific, measurable skill

Delivery is structured, task-oriented (interactive modules, workshops)

Measured by assessment (quiz score, simulation pass rate)

Training (for all staff)

Focuses on 'how' to perform a specific task correctly

Audience is the entire workforce

Content is narrow and immediately applicable to the job

Education (for specialists)

Focuses on 'why' principles and underlying theory

Audience is security team, IT staff, and decision-makers

Content is broad, conceptual, and builds deep understanding

Phish-prone Percentage

Measures actual behaviour (clicking on simulated phishing emails)

A decreasing trend indicates real improvement in security culture

Harder to game or fake because it observes real actions

Training Completion Rate

Measures compliance (did everyone take the required module?)

A high number does not show whether learning occurred

Easy to inflate by pressing 'play' without paying attention

One-time Training

Single event, often during onboarding

Knowledge decays quickly after training

Usually lacks follow-up measurement or refreshers

Continuous Awareness Programme

Ongoing, with regular updates and fresh content

Reinforces learning through repetition and real-world examples

Includes periodic assessments and adjustments based on results

Watch Out for These

Mistake

Security awareness training is a one-time event you do during employee onboarding.

Correct

Effective security programmes are ongoing and continuous, with regular updates to reflect new threats. Onboarding is just the start.

Many people equate 'training' with a one-time course they took in school. In security, threats evolve daily, so knowledge becomes stale quickly. A single session cannot keep people protected.

Mistake

If people just watch a video and pass a quiz, they will definitely change their behaviour.

Correct

Learning and behaviour change are different. A quiz only tests recall, not whether someone will actually apply the knowledge under pressure or when distracted.

This mistake comes from over-trusting simple assessment. Humans know what they should do (e.g., not click a link) but still do the wrong thing due to fatigue, distraction, or social pressure. Real behaviour change requires repeated practice and feedback.

Mistake

Security awareness training is only for people who use computers regularly, like office workers.

Correct

Every person in an organisation, including executives, cleaning staff, and contractors, can be a target. Even a janitor can be tricked into letting an attacker into a secure area.

People assume that if you don't use a computer, you aren't a risk. But social engineering and physical security breaches target anyone. Attackers exploit the human element regardless of the person's role.

Mistake

Awareness and training are the same thing, just different words.

Correct

Awareness is about keeping security on people's minds (e.g., posters, newsletters). Training is about teaching a specific skill (e.g., how to use a password manager). They serve different purposes and require different approaches.

This confusion arises because in casual conversation, people use 'training' to mean any kind of learning. The CISM exam draws a sharp distinction, and mixing them up leads to wrong answers.

Mistake

If you have a good security awareness programme, you don't need technical controls like spam filters.

Correct

Awareness and training complement technical controls; they do not replace them. A layered defence (people + technology) is always stronger than any single measure.

This mistake comes from the belief that if you train people perfectly, they will never make a mistake. But humans are fallible. Technical controls catch the mistakes that slip through, and awareness reduces the number of mistakes. Both are needed.

Mistake

The success of a training programme is measured by how many employees completed it.

Correct

Completion rate is a measure of compliance, not effectiveness. True success is measured by behaviour change, such as a lower click rate on simulated phishing emails or faster reporting of suspicious activity.

Organisations often report completion rates because they are easy to measure and satisfy auditors. But a 100% completion rate means nothing if people still click on real phishing emails. CISM requires evaluating actual outcomes, not just inputs.

Do You Actually Know This?

Reveal each answer, then mark whether you got it right. Score 60%+ to unlock the next chapter.

Frequently Asked Questions

What is the difference between security awareness and security training?

Awareness is about keeping security on people's radar through short, frequent messages like posters or emails. Training is about teaching a specific skill, like how to use a password manager or how to identify a phishing link, and it usually involves an assessment to confirm the skill is learned.

Do I really need a security awareness programme if I have good antivirus software?

Yes. Antivirus software protects against known malware, but it cannot stop a person from voluntarily giving their password to a scammer on the phone. The human element is the weakest link in security, and technology alone cannot fix it.

How often should security awareness training be given?

Awareness should be continuous — think weekly tips or monthly newsletters. Formal training for specific skills should be done at least annually, and after any major security incident or policy change. Phishing simulations should be run quarterly to keep skills sharp.

Who is responsible for creating the security awareness programme?

The CISM or security manager typically designs the strategy and selects content. But they work with HR, legal, IT, and senior leadership to ensure the programme is compliant, practical, and funded. The programme is a cross-team effort.

How do I measure if my security awareness programme is working?

Run simulated phishing campaigns before and after training and compare click rates. Track the number of real security incidents reported by employees (rather than by automated systems). Also measure quiz scores and completion rates, but remember that completion is not the same as behaviour change.

Is it mandatory to have a security awareness programme?

For many industries, yes. Regulations like GDPR (Europe), PCI DSS (payment card industry), and HIPAA (US healthcare) explicitly require organisations to provide security awareness training. Even if not legally required, it is considered a fundamental security control by standards like ISO 27001.

What should I do if an employee repeatedly fails a phishing simulation?

First, provide additional one-on-one coaching to understand why they are falling for it. If it continues, escalate to a formal progressive discipline process, as defined in the organisation's Acceptable Use Policy. The goal is not punishment, but to prevent a real attack from succeeding.

Terms Worth Knowing

Keep going

You've finished Security Awareness, Training, and Education. Continue through the CISM study guide to build a complete picture of the exam.

Done with this chapter?