Security Awareness Training and Phishing Simulation
Security awareness training is a recurring, delivered program: short, role-relevant sessions on the situations each group actually faces, simulated phishing that measures how people respond, and reporting that tells leadership whether behavior is changing, rather than an annual video watched to satisfy a checkbox.
- Part of
- The decisions, records and oversight that turn security activity into something leadership can direct.
- Engaged as
- A defined piece of work, or as part of an ongoing vCISO engagement.
- Sits under
- Executive ownership of the cybersecurity program.
The problem
Why this comes up
The majority of incidents begin with a person: a credential typed into a convincing page, an invoice paid to a changed bank account, a file opened because it looked routine. The annual compliance video does not change what a person does on a Tuesday afternoon under pressure.
The organizations that have run training for years often cannot say whether it works, because the only measure they hold is completion. Completion is attendance. It is not behavior.
The service
What this engagement is
Who it is for
- Organizations whose last awareness effort was a single annual module.
- Finance teams and executives who are the targets of payment fraud and impersonation.
- Companies whose insurer or framework expects recurring training with evidence.
- Leadership teams that want to know whether the money spent on awareness is changing anything.
A program run across the year: brief sessions built around the scenarios each role meets, finance and executives on payment fraud and impersonation, everyone on credential theft and reporting, administrators on the attacks aimed at them. Simulated phishing campaigns test what the sessions taught, and reporting follows the results by group and over time.
The program is governed by the organization's policy and standards, and it feeds the security program's reporting, so leadership sees the human layer beside the technical one.
Scope
What Heights does
-
Role-based training program
Sessions scoped to what each group is likely to face, on a cadence across the year rather than one event.
-
Simulated phishing campaigns
Realistic campaigns run on a schedule, escalating in difficulty, with immediate coaching for anyone who acts on one.
-
Executive and finance targeting
Payment fraud, impersonation and pretext scenarios aimed at the people who move money and sign approvals.
-
Reporting and incident culture
A simple way to report a suspicious message, and recognition when people use it, so reporting rises as clicking falls.
-
Measurement and reporting
Results by group and over time, presented to leadership with the rest of the program's reporting.
Timing
When organizations engage this
- A phishing email reached someone who acted on it.
- A payment was redirected, or nearly was, by a message that looked like the boss.
- The insurer or a framework asks for training completion and phishing results.
- Completion rates are high and nobody can say what changed.
- New hires arrive between annual sessions and receive nothing.
What you receive
- An annual program calendar with sessions and campaigns by role
- Simulated phishing results by campaign, group and trend
- Completion and behavior evidence formatted for insurers and assessors
- A quarterly awareness report for leadership
- NIST CSF
- A widely used structure for organizing a security program around outcomes rather than products. Its current version adds an explicit governance function, which is why it maps well onto executive-level work.
- HIPAA
- The HIPAA Security Rule requires administrative, physical and technical safeguards for electronic protected health information, including a documented risk analysis and risk management process. The Breach Notification Rule sets defined duties and timelines once a breach is discovered. HITECH extended enforcement and applies obligations directly to business associates.
- PCI DSS
- Prescriptive control requirements imposed through payment brand agreements wherever cardholder data is stored, processed or transmitted. Scope reduction is usually the highest-leverage decision available.
- SOC 2
- An examination performed by a licensed CPA firm against the AICPA trust services criteria. Security is always in scope; availability, confidentiality, processing integrity and privacy are added when relevant.
- CMMC
- NIST SP 800-171 sets the security requirements for protecting controlled unclassified information in non-federal systems. CMMC is the program under which contractors demonstrate that implementation, by self-assessment or third-party assessment depending on level.
The flagship
How this fits under vCISO leadership
Awareness is a control, and like any control it needs an owner. The vCISO decides what behavior the program must change and reads the results beside the technical measures; this service delivers the program and produces the evidence.
Sectors
Where this comes up most
- Legal and Professional Services Confidentiality duties owed to every client, ethics rules that now speak directly to technology, and corporate clients who audit their law and accounting firms the way they audit any other vendor.
- Financial Services Several supervisory regimes at once, and several of them expecting a named individual to be accountable for the information security program.
- Healthcare Statutory obligations for protected health information, clinical availability requirements that constrain how controls can be applied, and growing security scrutiny from payers and partners.
- Education Student records protected by federal law, financial-aid data that brings banking-grade obligations onto campus, open networks by mission, and a sector ransomware operators treat as a soft target.
- Insurance Organizations Licensed entities holding concentrated nonpublic personal data, state insurance data security laws with annual certification duties, and carriers auditing the agencies and administrators they appoint.
First steps
How an engagement begins
The same three steps whichever service you start with.
-
A confidential conversation
What prompted the enquiry, what you are obliged to do, and what leadership is being asked to answer for. No cost, no obligation.
-
Scope agreed in writing
What Heights will do, what stays with you, the working rhythm, and how progress will be reported.
-
Work begins
Delivered by your team, your providers or Heights, with expectations and acceptance criteria stated up front.
FAQ
Questions we are asked about this
Broader questions about executive security leadership are answered on the vCISO page.
Is simulated phishing fair to staff?
It is, when it is run to teach rather than to catch. Campaigns are announced as a program, results are reported by group rather than by name to leadership, and anyone who acts on a simulation gets a short explanation in the moment, not a reprimand.
The measure that matters is the reporting rate. A workforce that reports suspicious messages quickly is protecting the organization whether or not any individual clicked.
How much time does this take from staff?
Sessions are short by design, minutes rather than hours, and spread across the year so no one loses an afternoon. Role-based scoping means people are only trained on what applies to them.
Simulations take no scheduled time at all; they arrive as ordinary messages do.
Does this replace the policy and awareness work?
No. The policy and standards work establishes what the organization expects of people and governs the program. This service delivers the program on a recurring basis and measures it.
Many organizations begin with the governance work and add the delivered program when they want the human layer measured continuously.
Portfolio
Related services
- Cyber Risk Management One register of the risks that could genuinely disrupt the business, rated consistently, owned by name, and reviewed on a schedule leadership can rely on.
- Security Policy, Standards and Awareness Policies written to match how your organization actually operates, with the standards that make them workable and the training that makes them understood.
- Vendor, MSP and Third-Party Oversight Clear accountability for the security work your providers perform: defined expectations, stated evidence requirements, and a review process that holds over the life of the contract.