Security Awareness Training for Compliance

Security Awareness Training: The Compliance Requirement That Actually Works

Security awareness training is required or expected under HIPAA, GLBA, PCI DSS, SOC 2 and CMMC, and it's one of the few compliance controls where you can actually watch the results improve.

Most compliance controls reduce risk in ways that are hard to measure. Training is different. You run a phishing simulation, record the results, train, simulate again and see whether fewer people take the bait. The feedback loop is short, progress is visible, and the program produces the records auditors want to see along the way. Required and measurable is a rare combination, which makes training one of the best-value controls a small business can put in place.

Which frameworks require it

HIPAA. The Security Rule's security awareness and training standard is required: covered entities and business associates must train all workforce members, including management. Its implementation specifications (security reminders, protection from malicious software, log-in monitoring and password management) are "addressable," which means you must implement them or document why an equivalent alternative is reasonable. It doesn't mean optional.

GLBA (FTC Safeguards Rule). Non-bank financial institutions must provide security awareness training to staff and keep it current as part of their information security program. The amended rule took effect in June 2023. SEC-registered advisers fall under Regulation S-P instead, and examiners there also expect staff to know the firm's policies. Our IT for financial advisers and wealth managers page covers that side.

PCI DSS v4.0.1. Requires security awareness training at hire and at least once a year, including awareness of phishing and social engineering.

SOC 2. Auditors look for documented training with completion evidence, mainly under the control environment and communication criteria.

CMMC and NIST SP 800-171. Awareness and training is its own control family for organizations handling controlled unclassified information.

If your current program is an annual slideshow that people click through and forget, you likely have a documentation problem and a security problem.

Why phishing still deserves the attention

Phishing and other social engineering remain among the most common ways attackers get in, whether the goal is ransomware, stolen credentials or business email compromise. Organizations that have never trained or tested their staff often see high click rates on their first simulation, and regular training with repeat simulations usually brings that down meaningfully over time. Results vary by organization, which is exactly why measuring your own baseline matters. For a quick reference your team can use, see how to spot a phishing email.

What an effective program includes

Baseline phishing simulation. Before any training, a simulated campaign shows where your organization actually stands. That result is both a compliance record and the benchmark you measure progress against.

Role-appropriate content. A practice manager handling PHI faces different risks than a front desk coordinator, and an adviser with client account access faces different risks than an office administrator. Training should reflect real jobs.

Regular simulation cadence. Monthly or quarterly simulations, with varied templates and pretexts, keep skills fresh. Annual training alone rarely changes behavior for long.

Immediate, non-punitive feedback. When someone clicks a simulated link, a short lesson in the moment works far better than a report to their manager two weeks later.

Completion records. HIPAA, GLBA, PCI DSS and SOC 2 all expect evidence: names, dates, completion and simulation results, stored where you can retrieve them for an audit.

Current content. Attackers change tactics. Training should cover AI-written phishing, QR code lures, voice phishing (vishing) and text-message phishing (smishing), not just the attacks of a few years ago.

The documentation it produces

A well-run program generates the evidence examiners and auditors look for: dated baseline results, training completion by person, follow-up simulation results, logs showing a regular cadence, policy acknowledgments, and records of follow-up for anyone who clicked. That package answers the two questions every reviewer asks: "Do you train your employees?" and "How do you know it's working?"

How it fits with the technical controls

Training lowers the odds of a successful phishing attack, but it can't remove them. Someone will eventually click. That's where the technical layers come in: endpoint detection and response (EDR) on the device, email filtering that catches malicious links, multi-factor authentication (MFA) that keeps a stolen password from becoming a stolen account, and monitoring that spots unusual activity. Training is the human layer, and it works best alongside the others.

How NerdSquad helps

Security awareness training, including phishing simulations and completion tracking, is a standard part of NerdSquad cybersecurity plans. We set the baseline, run the program and keep the records organized for your auditor, examiner or insurer. For a step-by-step example, see an example scenario: from phishing test to audit-ready. For the wider compliance picture, see Can you help us meet compliance requirements like HIPAA, PCI, and SOC 2?


Talk to NerdSquad

Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.

Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.

Related: Cybersecurity services for businesses