Skip to content

Security awareness training

Training that arrives while it still means something

A failed simulation is the best teaching moment a security programme ever gets, and it lasts about an hour. SafeLoop enrols the matching lesson in seconds — three to five minutes, on the device the person failed on, mapped to the control your auditor will ask about.

3–5 min
per module
6
frameworks mapped
94%
median completion
~1 hourthe failure staysteachable0s+8s+4mSubmitted at 0s · assigned by +8s · finished inside 4 minutes.Next quarter’s cycle arrives long after this window shuts.

Enrolment

Assigned in seconds, finished in minutes

The lesson matches the failure. Someone who submitted credentials to a fake single-sign-on page gets the credential-harvesting module, not a general awareness course. Certificates and completion write straight to the append-only audit log.

  • Auto-enrol on click, submit or missed report
  • Certificates on completion, exportable as evidence
  • Repeat-failure journeys for the cohort that matters
  • Spotting a spear-phish4 min · Complete
  • MFA fatigue & push bombing3 min · Complete
  • Invoice fraud and BEC5 min · 62% done
  • QR codes in the wild3 min · Assigned
An enrolment generated by one failed simulation — assigned, tracked and certificated automatically.

Coverage

Mapped to the control, not to a topic

Every module carries the framework references an assessor cites, so the evidence pack you export answers the question directly instead of asking the auditor to infer it. That mapping is what turns training records into an audit artefact.

  • NIST CSF and SP 800-53 awareness controls
  • HIPAA Security Rule §164.308(a)(5)
  • PCI DSS 12.6, GDPR Art. 39, ISO 27001 A.6.3, SOC 2 CC2
0%10%20%30%40%Baseline: 33.2% phish-prone33.2%Baseline90 days: 20.1% phish-prone20.1%90 days12 months: 4.2% phish-prone4.2%12 months−87%
Phish-prone rate over 12 months of continuous simulation and training. Source: KnowBe4 2026 Phishing by Industry benchmark (33.2% → 20.1% → 4.2%).

The library

What people actually get taught

Written against current attacker tradecraft, not last decade's Nigerian-prince example.

Email

Spear-phishing and BEC

Thread hijacks, vendor-change requests and invoice fraud — the lures that survive a spam filter.

Identity

MFA fatigue and OAuth consent

Push bombing, consent-screen abuse and the help-desk call that resets somebody else's factor.

Multi-channel

Smishing, vishing and quishing

Why a text message and a phone call bypass every control your email gateway provides.

AI-era

Deepfakes and voice cloning

What a cloned executive voice sounds like, and the verification step that defeats it regardless.

Data

Handling and classification

Practical rules for the tools people actually use, including the ones they were not issued.

Accessibility

24 languages, WCAG 2.2 AA

Captioned, keyboard-navigable and screen-reader tested, because a third of a workforce is not at a desk.

Compliance mapping

What each framework wants, and what we give the auditor

FrameworkThe requirementEvidence SafeLoop exports
NIST CSF 2.0PR.AT — awareness and training for all usersPer-person assignment, completion date, module content version
HIPAA Security Rule§164.308(a)(5) awareness programme with periodic remindersEnrolment history, certificates, simulation cadence per person
PCI DSS v4.012.6.3 — awareness at hire and annually, including phishingHire-date baseline, annual completion, phishing result trend
GDPRArticle 39(1)(b) — staff awareness and trainingTraining register with lawful-basis and retention notes
ISO 27001:2022Annex A 6.3 — awareness, education and trainingProgramme scope, per-control mapping, effectiveness metric
SOC 2CC2.2 — internal communication of security responsibilitiesAssignment, acknowledgement and audit-log extract

The evidence pack is one export per framework. Assessors receive the register, the certificates and the immutable log together.

Questions

Asked on every first call

The ones that decide whether a first call turns into a second one.

3 questions

How long are the modules?

Three to five minutes. Anything longer is abandoned on a shop floor or between clinical rounds, and completion rates show it. Longer-form content exists for specialist roles, but the default assignment is short by design.

Can we use our own content and branding?

Yes. The academy can be white-labelled on Enterprise, and you can upload your own modules, policies and acknowledgements alongside the SafeLoop library. Custom content is authored with you on the content-studio add-on.

Does training completion feed the risk score?

It is one of ten factors, and deliberately not the heaviest. Completion measures attendance; the score weights what people do when tested — susceptibility, report rate and real-threat response — so a department cannot grade well by clicking through courses.

See the enrolment fire in real time

We run a live simulation, someone clicks, and you watch the lesson land before the call ends.

See your human risk in 20 minutes

Book a demo and we’ll run a sample campaign against a test group.