
Can your security awareness training stand up to an audit?
Related Items
Your team has completed its security awareness training. The dashboard looks reassuring. Then an auditor, a customer or your board asks what that training has actually achieved.
Can you show who took part, what they practised, where the gaps remain and what happened next? A completion figure answers only part of that question. For a financial services business or another regulated organisation, the more useful conversation is about the evidence behind the programme and the decisions it supports.
Cybersecurity Awareness Month is a good opportunity to look beyond the annual training reminder. The aim is not simply to get another course finished. It is to give people regular practice, understand where they need help and keep a record you can use when someone asks how you manage the human side of security.
Completion is a starting point, not the whole picture
A record of completed training matters. It shows that the learning reached the people it was intended for. But it does not, on its own, tell you how someone would respond to an unexpected payment request or a convincing sign-in message.
Training records and phishing simulation results answer different questions. One shows participation. The other helps you understand how people respond to a particular scenario. Neither should be presented as proof that your organisation cannot be compromised. Together, with documented follow-up, they give you a more useful view than either measure alone.
Think about the next assurance conversation you expect to have. Could you explain why you chose those training topics, whether relevant staff and leaders took part, and what you changed after reviewing the results? If the answers sit across several spreadsheets and inboxes, the task is not just to collect more data. It is to make the programme easier to explain.
A practical first step is to review the last training cycle. Look for the link between the risks you wanted to address, the learning you delivered and the action you took afterwards.
Keep completion records, but connect them to testing, follow-up and the risks the training addresses.
Start with your own phishing baseline
Before changing your programme, establish a starting point. An organisation-wide phishing simulation can help you see how staff respond to a realistic request and where further learning may be useful.
Use that baseline to guide the next steps, not to label people as the problem. A result is useful when it leads to a clear decision: which topics need attention, which roles need a different scenario, and when to test again. The purpose is to build safer habits and make it easier for staff to recognise and report suspicious requests.
Be careful with comparisons. Your own results depend on the scenario, the people involved and how the exercise is run. A later test may use a different message or cover a different group. Record that context so a change in the headline percentage does not become a claim the evidence cannot support.
For example, an invoice request and a sign-in prompt test different situations. These are useful training scenarios, not interchangeable measures of every security risk. A baseline gives you a place to begin the conversation. Regular testing and follow-up make it a programme rather than a one-off exercise.
Measure your own starting point and document the context before drawing conclusions from later results.
Give people practice that reflects their work
A polished message is not evidence that a request is genuine. AI-generated text and voice impersonation can make familiar social engineering tactics appear more convincing, but the everyday decision remains recognisable: should I trust this request, check it through another channel or report it?
That is why the training needs to reflect the situations people encounter. Finance teams may need practice with payment and supplier requests. Other employees may need to recognise unexpected account prompts or requests for sensitive information. Senior leaders need to take part too, rather than treating awareness as something delegated to everyone else.
Regular, bite-sized learning and realistic simulations give staff opportunities to practise those decisions as threats change. The useful question is not whether the course library is large. It is whether the learning is relevant to your workforce and whether someone reviews the results and follows up.
When reviewing a programme, ask how topics are chosen, how training is matched to different roles and what happens when someone needs additional support. Look for a manageable rhythm of learning, testing and review rather than a burst of activity that ends when the annual deadline passes.
Choose training around the decisions your people make, not simply the number of courses available.
Make the evidence useful outside the training dashboard
When an auditor or customer asks about awareness training, a screenshot may not provide enough context. A useful evidence pack brings together the training period, the people in scope, completion records, simulation results and the follow-up those results prompted.
You should be able to explain what the records show and what they do not. A training completion report is not a guarantee of competence in every situation. A simulation result is not a promise about future incidents. Clear reporting makes those boundaries visible while helping you show that the programme is being run and reviewed.
Calligo’s managed security awareness service includes a quarterly evidence pack mapping training completion and phishing results to ISO 27001 A.6.3, PCI DSS 12.6 and SOC 2 CC2.2. It also provides data formatted for cyber insurance renewal questionnaires. That can help you organise the material you need for assurance conversations, rather than reconstructing it at the last minute.
The mapping supports your evidence gathering; it does not guarantee certification, an auditor’s acceptance or an insurer’s decision. Before choosing any service, ask to see how the reporting is structured and check that it fits the requirements your organisation actually needs to address.
Ask for reporting you can explain and use, with clear boundaries around what it demonstrates.
Bring leadership into the conversation
Leadership involvement should mean more than approving the training budget. Your board and senior management need a clear view of the risks the programme addresses, the participation it requires and the action its findings support.
A leadership phishing baseline can give that conversation a practical starting point. Calligo offers a simulated phish for the leadership team, with results presented by its CISO in a 30-minute briefing. The value is the opportunity to discuss the findings and next actions directly, alongside the wider organisation’s training needs.
For financial entities within DORA’s scope, awareness and resilience training includes employees and senior management. Role-based training, leadership engagement and documented results can support those obligations, but a training service does not fulfil every DORA requirement or make a firm compliant by itself.
If you operate in the UK or internationally, establish which requirements apply to your own activities rather than assuming every framework has the same scope. Use the leadership discussion to clarify responsibilities, agree what needs attention and decide how progress will be reviewed.
Use leadership briefings to agree responsibilities and follow-up, not simply to present a score.
Decide who will run the programme
Access to a training platform is only one part of the decision. Someone still has to organise campaigns, follow up completion, review simulations and prepare the reporting. If those responsibilities fall between teams, even a capable platform can become an occasional activity rather than a sustained programme.
Before choosing an approach, ask:
- Who will organise the learning and phishing simulations?
- Who will follow up incomplete training and identify where extra support is needed?
- How will results be reviewed and translated into the next training cycle?
- What reporting will be available for leadership, audits and insurance questionnaires?
Calligo Security Awareness Training is powered by KnowBe4 and delivered as a managed service. Calligo runs the campaigns, follows up training completion and reports the results, so your team does not have to operate the programme.
The question is whether that division of work suits your organisation. If you already have the capacity to run a consistent programme, assess what additional help would be useful. If the work repeatedly slips behind other priorities, a managed approach may make it easier to sustain the learning and maintain the evidence.
Compare the operating responsibilities and reporting, not just the platform.
An October opportunity to put the foundations in place
If you are considering a managed programme for the year ahead, Calligo’s October offer provides time to begin before January. Sign a 12-month agreement by 31 October 2026 and November and December are free, with service starting during November. The 12-month paid term begins on 1 January 2027.
Those first two months cover onboarding, an organisation-wide baseline phishing test and an executive risk briefing. The commitment is agreed before the service begins, so this is not a free trial you can leave before the paid term starts.
Use the discussion to check whether the programme fits your workforce, your reporting needs and the responsibilities you want to retain internally. Confirm eligibility, seat requirements and agreement terms with Calligo before signing. If you are already a Calligo managed-service client, your Account Manager can help you explore the fit.
The useful starting point is the same whether you take up the offer or not: understand your baseline, make training relevant to your people and keep evidence that explains the action you are taking.
Consider the offer in the context of your programme needs, with the commitment and terms clear before signing.
A stronger security awareness programme is not defined by a reassuring dashboard alone. It gives your people regular practice, helps you identify where support is needed and leaves a clear record of what you did next.
For your next review, start with three questions: what does the baseline tell us, who is responsible for the follow-up, and can we explain the evidence to someone outside the training team? Those answers will help you decide what to keep, what to change and whether a managed service is the right fit.
Explore Calligo’s managed security awareness programme and the October offer, then discuss whether it fits your organisation’s training and evidence needs.








