4.1 Support and Implement Security Awareness and Training
Key Takeaways
- Security awareness is continuous communication; training is a designed learning event with an objective and a metric — annual learning-management-system completion is audit evidence, not a complete program.
- Report rate and time-to-report measure whether people help the security operations center; a falling click rate with a falling report rate means people learned to freeze, not to assist.
- Role-based training: help desk practices vishing and identity proofing; administrators practice spear phishing against change and multi-factor authentication; executives practice whaling and business email compromise.
- A tabletop is facilitated discussion with no systems touched; a walkthrough inspects the actual procedure; simulated phishing is a live lure that measures click and report behavior.
- Phishing, smishing, vishing, and whaling are training vehicles in Knowledge Area 1.7; Domain 7 catalogs them as attack methods.
Support and Implement Security Awareness and Training
Domain 1 of the ISC2 Systems Security Certified Practitioner (SSCP) exam — Security Concepts and Practices, weighted at 16% — includes Knowledge Area 1.7: support and/or implement security awareness and training. The October 1, 2025 outline's examples are social engineering, phishing, tabletop exercises, and awareness communications. That is an operations brief. Domain 7 later catalogs phishing, smishing, vishing, impersonation, scarcity, and whaling as attack methods. Knowledge Area 1.7 asks a different question: how does a practitioner train people so those methods fail more often, and how do you prove the program works?
A policy PDF that nobody reads is not awareness. A forty-five-minute annual video everyone clicks through at 1.5x speed is not training. SSCP items are framed the way a sysadmin, security operations center (SOC) analyst, or help-desk lead actually works: design a campaign, pick the right exercise, measure the right metric, and give privileged roles harder, more relevant content than the rest of the workforce.
You may not own the learning management system (LMS). Support and/or implement still means you inject operational realism: you help the SOC time a simulation, you write the help-desk vishing script, you stop leadership from treating click rate as a shame score, and you keep communications ready for the morning a real campaign lands.
Awareness Versus Training
| Program | Purpose | Typical delivery | How you know it worked |
|---|---|---|---|
| Security awareness | Build a culture that notices and reports risk | Newsletters, intranet posts, manager talking points, digital signage, just-in-time alerts after a real campaign | Reporting volume, time-to-report, surveys of I know how to report |
| Security training | Teach a specific skill or obligation | Onboarding modules, role-based labs, simulated phishing, tabletop exercises, after-incident coaching | Completion plus skill checks, click rate, report rate, help-desk handling of a vishing test |
Awareness is continuous communication. Training is a designed learning event with an objective and a measurement. You need both. Awareness without training leaves privileged users unprepared for whaling and vishing. Training without awareness leaves a workforce that can pass a January quiz and still ignore the report-phish button in November.
Scenario. Your organization ships an annual module every January. Completion is 98 percent. In March a real business email compromise (BEC) campaign hits finance. Nobody reports it for six hours because the last communication about reporting was the January module. Completion is audit evidence. It is not a living program.
Campaign Design
Design a campaign the way you would design a control: audience, objective, content, channel, frequency, owner, and metric. Do not start from a vendor catalog of clever posters.
- Audience. Split at least general staff, privileged administrators, help-desk and identity staff, executives and assistants who approve payments, and developers. One module for everyone is the classic failure.
- Objective. Write a behavior, not a slogan. Increase report rate on simulated phishing from 22 percent to 50 percent in two quarters is an objective. Make people more security-aware is not.
- Content. Map content to how that audience is actually attacked. Help-desk training is password-reset vishing and the CIO is locked out. Administrator training is spear phishing that impersonates a change ticket or a vendor multi-factor authentication (MFA) reset. Executive training is whaling and wire-transfer BEC.
- Channel. Email, collaboration chat, manager huddles, new-hire orientation, just-in-time banners on the mail gateway after a real campaign, and a persistent report-phish button in the mail client. If the only channel is the LMS, you will train people to complete LMS courses, not to interrupt an attack.
- Frequency. Continuous beats annual. Event-driven beats calendar-driven: a public ransomware story, an actual click in your tenant, a new vishing pattern against your help desk.
- Tone. Blame-free reporting. If the first click earns public shaming, people hide the next one. Repeat clickers and people who forward a phish to coworkers instead of reporting get coaching. Concealment after a known campaign is a conduct issue, not a training miss.
Scenario. A sysadmin receives a simulated message that looks like a request for change (RFC) from the change manager: approve this firewall exception before the 02:00 window. That is role-based content. Sending that same RFC lure to a marketing intern teaches nothing useful and trains the intern to ignore change-management mail.
The awareness program is a cycle, not a once-a-year event. Assess who is being attacked, set a behavioral objective, deliver role-based content, exercise the workforce, measure click versus report, coach, and retune. If you skip measurement, you have theater. If you skip coaching, you have a scoreboard.
Metrics: Click Rate Versus Report Rate
Simulated phishing is popular because it produces numbers. The SSCP cares which numbers you treat as success.
| Metric | What it measures | Operational reading |
|---|---|---|
| Click rate | Percentage of recipients who opened a payload link or entered credentials on the lure | Lower is better, but a falling click rate alone can mean people learned to ignore unfamiliar mail, not that they will help the SOC |
| Report rate | Percentage who used the official report path (button, SOC mailbox, help-desk ticket) | Higher is better; this is the behavior that starts incident response |
| Time-to-report | Minutes from delivery to first good report | Faster containment for a real campaign |
| Repeat-clicker rate | People who click more than one campaign | Coaching and access-risk review, not a public leaderboard |
| Training completion | LMS checkbox | Necessary for audit evidence; insufficient as the only metric |
| Help-desk handling rate | Percentage of vishing tests where the agent followed the identity-proofing script | The metric that matters for identity staff |
A program that drives click rate toward zero while report rate also collapses has trained people to freeze, not to assist. A click that is reported in two minutes is operationally better than a no-click culture in which the first real click sits in a mailbox until the attacker has a session.
Do not use click rate as a punishment score. Pair it with report rate, time-to-report, and whether the person used the sanctioned path. Feed aggregated metrics to leadership. Feed individual coaching to managers, and to identity and access management (IAM) when a privileged account is the one that clicked.
The report-phish button is both a control and a training reinforcement. If it dumps into a mailbox nobody triages, people stop reporting. The SSCP's operational job includes making sure simulated and real reports land where the SOC can act, and that users get a short thank-you so the behavior is rewarded.
Scenario. After three campaigns, click rate dropped from 18 percent to 6 percent, and report rate dropped from 31 percent to 9 percent. Leadership celebrates the click-rate slide. The SSCP should not. People learned the lures look fake and did nothing. The next well-written spear phish will not be reported. Fix the communications and the report path before you claim success.
Role-Based Training
Least privilege applies to training content. Give people the attacks they will actually face.
General staff. Phishing recognition, the report button, clean desk, a USB drive found in the parking lot (turn it in; do not plug it in), and how to verify a payment-change request out of band.
Help desk. This is the highest-value human control after MFA. Attackers vish agents to reset passwords, enroll a new MFA device, or read a one-time code. Training must include identity proofing that cannot be satisfied by knowing the chief executive officer's middle name, a callback to a number the caller provides, or pressure (I am in a board meeting). Run vishing simulations against the service desk the same way you run email lures against everyone else.
Administrators. Spear phishing that impersonates vendors, change managers, or cloud consoles. Cover never approve an MFA prompt you did not initiate, out-of-band verification of emergency change requests, and that a privileged access management (PAM) checkout is not authorization to skip change management.
Executives and executive assistants. Whaling and BEC: a message that appears to come from the chief executive officer asking the chief financial officer to wire funds or share tax files. Executives skip the LMS; give them short briefings and a dedicated reporting path. Train the assistants who actually move money.
Developers and sysadmins who ship code. Malicious packages, fake security-scanner browser extensions, and credential-harvesting sites that clone Git or cloud login pages. This is still awareness work; the full malware catalog is Domain 7.
Using Social Engineering as Training Content
Teach the training and operations angle here. Domain 7 will ask you to name the method. Domain 1 asks you to use the method as a teaching tool without turning the workforce into a research lab.
- Phishing — fraudulent email. Primary vehicle for simulated campaigns. Keep lures realistic but not cruel (do not spoof a death in the family). Align difficulty with the audience.
- Smishing — Short Message Service (SMS) lures. Password-reset and package-delivery texts are in scope. Give people a report path that is not forward the SMS to the help desk and hope.
- Vishing — voice calls. Essential for help-desk and finance. A tabletop is not a substitute for a live call to the service desk asking for a password reset.
- Whaling — targeted lures against senior officers. Run these as tightly scoped simulations with executive-office buy-in so you do not surprise the board with a public gotcha.
Coordinate with the SOC so a simulation is not ticketed as a real incident for six hours — unless the objective of the exercise is to time the SOC, in which case you say so in the exercise plan. Warn physical security if a lure could send panicked staff to the lobby. Uncoordinated simulations burn trust and create real availability incidents.
Tabletop, Walkthrough, and Simulated Phishing
These are different instruments. Mixing them up is a common exam trap.
| Exercise | What happens | Systems touched? | Best use |
|---|---|---|---|
| Tabletop | Facilitated discussion around a written scenario; players say what they would do | No | Decision-making, roles, communications, gaps in a playbook — ransomware, BEC, the CEO's mailbox is forwarding |
| Walkthrough | Team steps through the actual procedure, checks contact trees, verifies the report button and SOC mailbox, confirms who can disable a mail rule | Light / inspection only | Prove the procedure is usable, not just written |
| Simulated phishing (and vishing/smishing analogs) | Live lure sent to people; measure click and report behavior | Production mail and sometimes voice | Measure human detection and reporting under realistic conditions |
| Full simulation / drill | Inject a scenario into production-like processes (SOC, help desk, physical security) | Yes, under a plan | Test the system of people plus tools |
A tabletop does not measure whether people click. Simulated phishing does not test whether the incident commander can brief legal. If an item describes executives sitting in a conference room talking through a BEC scenario with no mail sent, that is a tabletop, not simulated phishing.
Scenario. The SOC lead wants to do a tabletop by emailing a fake invoice to accounts payable and watching who clicks. That is simulated phishing, and it needs campaign controls: scope, no-shame coaching, and the SOC informed. If the same lead sits finance, legal, and the mail admin in a room and walks a BEC timeline — who calls the bank, who disables forwarding rules, who notifies customers — that is a tabletop. Both belong in the program. They are not interchangeable.
Awareness Communications
Communications are a control in Knowledge Area 1.7, not an afterthought. Own a calendar: new-hire message, monthly micro-tip, manager talking points, and a just-in-time template the SOC can send when a real campaign is active (We are seeing lures that impersonate payroll. Use the report button. Do not call the number in the message.).
Good communications are specific, short, and actionable. Be careful out there is not a control. Payroll will never ask you to buy gift cards. Report messages that do. is.
Close the loop with physical security and the help desk: a poster in the lobby about tailgating is awareness; a guard who has never been told what a visitor badge looks like is a collaboration failure you will meet in Knowledge Area 1.8.
When you sit the exam, ask: is this item about building the program (campaign, metric, role, exercise type, communication), or about naming the attack (Domain 7)? Knowledge Area 1.7 is the program.
After three simulated phishing campaigns, click rate fell from 18 percent to 6 percent, but report rate also fell from 31 percent to 9 percent. Leadership wants to declare the awareness program a success. What should the SSCP treat as the operational reading?
Help-desk agents are taking after-hours calls from someone who claims to be the chief information officer, is in a board meeting, and needs a multi-factor authentication device re-enrolled immediately. As the SSCP supporting role-based awareness training, what is the appropriate program action?
Executives, legal counsel, and the mail administrator sit in a conference room and talk through a business email compromise timeline: who calls the bank, who disables mailbox forwarding, and who notifies customers. No messages are sent and no production systems are changed. Which exercise is this?