Skip to content
All lessons
Objective 5.6Governance & Risk· 3 min read

Security Awareness Practices

Given a scenario, implement security awareness practices

What you will learn

  • Design an awareness programme measured by its effect, not its attendance.
  • Explain how simulated phishing works and the common mistake in running it.
  • Know how to set up incident reporting that encourages reports rather than punishing them.
  • Name the anomalous behaviours users are trained to notice.

The most used vector is the human, and the cheapest control for it is awareness. But awareness fails when it is measured by attendance: "96% completed the course" is not a result. The results are a falling click rate on simulated links, a rising number of reports, and a shortening time for a report to arrive.

An awareness programme that works

  1. Measure a baseline first

    A simulated phishing campaign before any training. Without a number before, the number after means nothing.

  2. Train on what applies to them

    Finance on transfer fraud, the service desk on impersonation over the phone. Generic training is forgotten.

  3. Simulate continuously, not once

    Awareness decays. One annual campaign measures memory, not behaviour.

  4. Make reporting easy and safe

    One button in the mail client, and a culture that does not punish someone for reporting their own mistake.

  5. Monitor the effect and adjust

    Click rate, report rate, and time to first report. Those are the programme's numbers, not attendance.

Anomalous behaviour users are trained to spot

Urgency and pressure"Within the hour or else…" Urgency disables verification, which is its purpose.
Unexpected authorityA request from an executive who has never asked you for anything, over an unusual channel.
Unusual requestBypassing a normal process: an urgent transfer without approvals, or sending a file outside the usual channels.
Risky behaviourUnapproved devices, shared credentials, software installed outside approval — shadow IT in objective 2.1's language.

Punishing clickers ends your programme

The best-known mistake in phishing training: naming or punishing those who clicked. The result is that people stop reporting for fear of blame, and you lose the programme's most valuable output — the early report. The purpose is measurement and improvement, not catching people out. If a question says reporting dropped after a campaign, look for the punishment.

Real-world example: one number improves, another worsens

A company starts running simulated phishing. The click rate falls from 31% to 9% over six months — an apparent success. But the report rate falls too, from 22% to 6%. The cause: management began sending a notice to everyone who clicked, copying their manager. People learned not to click, and equally learned not to report so as not to draw attention. The second number is the dangerous one: a click is an individual mistake, while the absence of reports means a real breach will pass in silence.

Three numbers, not one

The click rate measures how many fall for it, the report rate measures vigilance, and time to first report measures response speed. A programme that improves the first while destroying the second has failed, however good its headline number looks.

What matters on the exam

  • Attendance is not a success metric. The metrics are click rate, report rate and time to report.
  • Role-based training beats generic. The question may name a department and ask what its training should cover.
  • Easy reporting and no punishment are preconditions. Any option proposing to punish clickers is wrong.
  • Awareness is operational by category and directive by function — a direct link back to objective 1.1.

Quick check

Answer in your head first, then reveal.

  1. The click rate fell and reporting fell with it. Is the programme succeeding?Reveal the answer

    No. Falling reports mean people have become afraid of drawing attention, so a real attack will pass unreported. The usual cause is punishing clickers or publishing their names.

  2. Why measure a baseline before training?Reveal the answer

    Because a number after training means nothing without one before it. No improvement can be claimed without knowing the starting point.

  3. What training specifically suits an accounts payable team?Reveal the answer

    Training on transfer fraud and business email compromise: an executive impersonated to request an urgent payment or change a supplier's bank details. That is what they actually face, unlike a generic password course.

  4. Security awareness: which control category, and which function?Reveal the answer

    Operational by category, because people carry it out day to day, and directive by function, because it guides the required behaviour. One of the most commonly misclassified controls in objective 1.1.

Sign in to track your progress on this topic.

Your next step

Read the lesson, then mark it complete

Sources

Used to verify the facts. The writing is original to Passuit.