FREE TEMPLATE
Security Awareness Training Policy
The payment verification rule, phishing simulations measured the right way, and why nobody is ever punished for reporting.
[COMPANY NAME]
Effective date: [DATE] · Owner: [NAME, TITLE] · Review: annually, or after any material change
Purpose
Every other policy here protects a system. This one protects the control that fails most often: a person in a hurry, being asked to do something that looks normal.
The purpose is not to make everyone a security expert. It is to make a handful of specific moments feel wrong.
Scope
Everyone who can log into a company system — employees, contractors, temporary staff, and the owners. Especially the owners. Attackers research who signs off payments and target them by name.
What training covers
| Topic | The point |
|---|---|
| Phishing and malicious links | What to look at before clicking, and what to do after clicking |
| Payment fraud and invoice redirection | Any request to change bank details is verified, no exceptions |
| Passwords and MFA | Why reuse is the real risk, and why an unexpected MFA prompt is a warning |
| MFA fatigue and prompt bombing | Repeated prompts you did not trigger mean someone has your password |
| Data handling | What counts as sensitive here, and where it is allowed to live |
| Physical and social | Tailgating, unknown visitors, phone calls claiming to be IT |
| Reporting | How to report, and that reporting early is always the right call |
Frequency
At hire, before access is granted — not in the third week.
Annually, a full refresh for everyone.
Short reinforcement through the year. Fifteen minutes quarterly beats two hours once.
After an incident, targeted at whatever actually happened.
The payment verification rule
Singled out because it is the one that costs small businesses the most money, and it is entirely preventable.
Any request to create a new payee, or to change bank details on an existing one, is verified by calling the requester back on a number already on file — never a number in the request.
This applies regardless of who the request appears to come from, including the owner, and regardless of urgency. Urgency is the tactic.
Amounts over [AMOUNT] require a second named approver.
This rule is written down, everyone is told it applies to them, and nobody is ever criticized for using it on a genuine request.
Phishing simulation
[COMPANY NAME] runs simulated phishing [QUARTERLY / MONTHLY].
The measure that matters is the reporting rate, not the click rate. A company where twenty percent click and sixty percent report is in better shape than one where five percent click and nobody says anything.
Simulations are never used as grounds for discipline. The moment people believe clicking gets them in trouble, they stop reporting real ones, and you have made the business less safe while producing a better-looking number.
Reporting
Suspected phishing, a click already made, a lost device, an odd MFA prompt, a strange payment request — all go to [REPORTING METHOD] immediately.
Nobody is punished for reporting, including for reporting their own mistake. Time is the only thing that reduces damage in an incident, and fear of blame is what costs you the time.
What happens next is in the Incident Response Plan.
Records
[POLICY OWNER] records who completed what and when, and keeps it for [NUMBER] years.
Insurance applications ask whether you deliver security awareness training. The honest answer needs a record behind it, and the record is what turns a yes into a defensible yes.
| Name | Role | At hire | Last annual | Last simulation result |
|---|---|---|---|---|
Responsibilities
[POLICY OWNER] runs the program, the simulations and the records.
Business owner completes it like everyone else, visibly. A program the owner skips is a program nobody takes seriously.
Managers make time for their teams to do it properly.
Everyone completes training on schedule and reports anything that feels wrong, early.
Review
Reviewed at least annually by [POLICY OWNER], after any incident involving a person rather than a system, and whenever the tools or threats change materially.
Acknowledgment
I have completed the [COMPANY NAME] security awareness training, and I understand the payment verification rule above applies to me.
Name: ______________________________
Signature: __________________________
Date: ______________________________
Template provided free by Cybertitans LLC, Woodbury, Minnesota. It is a starting point, not legal advice, and it has not been reviewed against your contracts, your industry’s regulations or your retention obligations. Have counsel review it before you adopt it. Downloading or using this template does not create a client relationship with Cybertitans, and Cybertitans makes no representation that adopting it satisfies any insurer, regulator, auditor or customer requirement.
EDITABLE VERSION
Want the Word version you can edit?
The policy above is free to read, copy and adapt — that is the point of publishing it. The Word file is the same text with every fill-in field marked, our formatting, and the signature block ready for your team to sign. Tell us where to send it.
Free. About 20 seconds.
Where should we send it?
THE REST OF THE SET
Nine more, and someone to run them.
This is one of ten free templates written for businesses with no IT department. The others are on the resource library, and the editable Word versions are a name and an email away.
A policy nobody operates is a document. If you would rather someone owned this — and the offboarding, the backups and the MFA behind it — that is what TiTAN is.
