Security awareness training
Training that arrives while it still means something
A failed simulation is the best teaching moment a security programme ever gets, and it lasts about an hour. SafeLoop enrols the matching lesson in seconds — three to five minutes, on the device the person failed on, mapped to the control your auditor will ask about.
- 3–5 min
- per module
- 6
- frameworks mapped
- 94%
- median completion
Enrolment
Assigned in seconds, finished in minutes
The lesson matches the failure. Someone who submitted credentials to a fake single-sign-on page gets the credential-harvesting module, not a general awareness course. Certificates and completion write straight to the append-only audit log.
- Auto-enrol on click, submit or missed report
- Certificates on completion, exportable as evidence
- Repeat-failure journeys for the cohort that matters
- Spotting a spear-phish4 min · Complete
- MFA fatigue & push bombing3 min · Complete
- Invoice fraud and BEC5 min · 62% done
- QR codes in the wild3 min · Assigned
Coverage
Mapped to the control, not to a topic
Every module carries the framework references an assessor cites, so the evidence pack you export answers the question directly instead of asking the auditor to infer it. That mapping is what turns training records into an audit artefact.
- NIST CSF and SP 800-53 awareness controls
- HIPAA Security Rule §164.308(a)(5)
- PCI DSS 12.6, GDPR Art. 39, ISO 27001 A.6.3, SOC 2 CC2
The library
What people actually get taught
Written against current attacker tradecraft, not last decade's Nigerian-prince example.
Spear-phishing and BEC
Thread hijacks, vendor-change requests and invoice fraud — the lures that survive a spam filter.
MFA fatigue and OAuth consent
Push bombing, consent-screen abuse and the help-desk call that resets somebody else's factor.
Smishing, vishing and quishing
Why a text message and a phone call bypass every control your email gateway provides.
Deepfakes and voice cloning
What a cloned executive voice sounds like, and the verification step that defeats it regardless.
Handling and classification
Practical rules for the tools people actually use, including the ones they were not issued.
24 languages, WCAG 2.2 AA
Captioned, keyboard-navigable and screen-reader tested, because a third of a workforce is not at a desk.
Compliance mapping
What each framework wants, and what we give the auditor
| Framework | The requirement | Evidence SafeLoop exports |
|---|---|---|
| NIST CSF 2.0 | PR.AT — awareness and training for all users | Per-person assignment, completion date, module content version |
| HIPAA Security Rule | §164.308(a)(5) awareness programme with periodic reminders | Enrolment history, certificates, simulation cadence per person |
| PCI DSS v4.0 | 12.6.3 — awareness at hire and annually, including phishing | Hire-date baseline, annual completion, phishing result trend |
| GDPR | Article 39(1)(b) — staff awareness and training | Training register with lawful-basis and retention notes |
| ISO 27001:2022 | Annex A 6.3 — awareness, education and training | Programme scope, per-control mapping, effectiveness metric |
| SOC 2 | CC2.2 — internal communication of security responsibilities | Assignment, acknowledgement and audit-log extract |
The evidence pack is one export per framework. Assessors receive the register, the certificates and the immutable log together.
Questions
Asked on every first call
The ones that decide whether a first call turns into a second one.
3 questions
How long are the modules?
Three to five minutes. Anything longer is abandoned on a shop floor or between clinical rounds, and completion rates show it. Longer-form content exists for specialist roles, but the default assignment is short by design.
Can we use our own content and branding?
Yes. The academy can be white-labelled on Enterprise, and you can upload your own modules, policies and acknowledgements alongside the SafeLoop library. Custom content is authored with you on the content-studio add-on.
Does training completion feed the risk score?
It is one of ten factors, and deliberately not the heaviest. Completion measures attendance; the score weights what people do when tested — susceptibility, report rate and real-threat response — so a department cannot grade well by clicking through courses.
Keep reading
Related
See the enrolment fire in real time
We run a live simulation, someone clicks, and you watch the lesson land before the call ends.