Security awareness that changes behaviour rather than completion rates
This course teaches SY0-801, the Security+ exam that launches on or around 17 November 2026. If you are booked on SY0-701, which can be taken until 11 June 2027, use our SY0-701 course instead.
Objective 5.6 is a scenario objective: given a situation, choose the awareness measure that would improve it. That means knowing the kinds of training and when each fits, the ways of delivering it, the subjects worth the time, and how to tell whether any of it changed what people do. It is the last lesson of the course.
Why this matters
Domain 2 established that most intrusions begin with a person being persuaded to do something. This objective is the control for that, and it is the one most often run as a compliance exercise: an annual module, a completion percentage, and no measurable change in behaviour.
SY0-801 has reshaped the objective around exactly that problem. It asks what type of training a situation calls for, how it is delivered, and how its effectiveness is reported, alongside the familiar topics. The scenario questions reward the answer that changes behaviour for the people at risk, not the one that produces the neatest completion figure.
This lesson has no short hands-on lab, for a reason worth stating plainly: the real exercise is a phishing simulation against colleagues who have agreed to be measured, and a campaign you run against yourself proves nothing. The applied lab has you design the programme instead: the training mix, the simulation, its control group and the metrics.
The lesson
Onboarding, ongoing, targeted and corrective training, and when each is the right tool
- Onboarding (initial) training happens when someone joins, before or as they receive access. It covers the acceptable use policy and its acknowledgement, how to report something, password and MFA setup, and the handful of rules specific to the role. Its job is to set expectations before habits form.
- Ongoing training keeps knowledge current: short, regular pieces through the year rather than one long annual module. Threats change, and memory of a single session fades within months.
- Targeted training goes to the roles that face specific attacks. Finance staff learn payment-change verification against business email compromise; the help desk learns identity checks before password resets; developers learn secrets handling; executives and their assistants learn about whaling and impersonation. A scenario describing one group under one kind of attack wants targeted training.
- Corrective training follows a specific failure: a clicked simulation, a policy breach, an incident. It should be immediate, brief and about what to do next time, not a punishment. The moment just after a mistake is when the lesson lands.
The rule that ties them together: punishing mistakes suppresses reporting, and reporting is the part of awareness with operational value. An organisation where people hide mistakes is worse off than one where they raise them at once.
Delivery: a learning platform, a self-service portal, one-to-one or one-to-many
- A learning management system (LMS) assigns modules, tracks who completed what, and keeps the records that compliance needs. It scales well and is the natural home for onboarding and ongoing training. Its weakness is that it measures attendance, not behaviour.
- A self-service portal gives people what they need at the moment they need it: the policies, how-to guides, a "report a concern" route, guidance on a suspicious message. Just-in-time help is often worth more than a module completed months earlier.
- One-to-one delivery is coaching: for an executive whose risk profile is unusual, for a person after a corrective event, or for a high-risk role where generic material does not fit. Expensive and highly effective.
- One-to-many delivery is briefings, webinars and team sessions. Good for an urgent warning about a live campaign, or for a team-specific threat that benefits from discussion and questions.
Choose by the situation: a new threat hitting the finance team this week is a one-to-many briefing for finance, not an LMS module for everyone next quarter.
Topics that earn the time: social engineering, BEC, credentials, removable media and hybrid work
- Social engineering: phishing and its variants by text, voice and QR code, pretexting and impersonation, taught as realistic scenarios rather than definitions. Recognising an attempt: urgency, an unexpected request, a sender mismatch, a link whose target differs from its text, a request to bypass a normal process. Responding: do not click, reply or delete; report it, and leave it in place so the security team can find who else received it.
- Business email compromise (BEC): a message from a real or convincingly faked account asking for a payment, a change of bank details, or sensitive data. Technical controls see little wrong because nothing malicious is attached. The defence is procedural: verify any payment change by calling a number already on file, never one in the message.
- Password and credential management: long passphrases, no reuse, a password manager, MFA everywhere, and never approving an MFA prompt you did not start.
- Removable media and cables: why a found USB stick is a threat, and that a device or even a cable can present itself to a computer as a keyboard.
- Remote and hybrid work: home network hygiene, screen privacy in public, device security outside the office, and taking care with family members' access to work devices.
- BYOD: what the BYOD policy requires, and why device enrolment exists.
- Emerging topics: the threats that have changed since the material was written, currently including AI-generated voice and video impersonation and data pasted into unapproved AI tools. Ongoing training is how new topics get in.
Situational awareness and operational security beyond the phishing module
Situational awareness is noticing that the present situation is unusual: an unfamiliar person in a secure area without a badge, someone following closely through a door, a call that creates urgency, a request that does not follow the normal process. It is what defeats vishing, tailgating and impersonation, which technical controls largely cannot see. People notice things no detection rule was written for, and a workforce that knows what "off" looks like, and has an easy way to say so, covers the gaps between the tools.
Operational security (OPSEC) is controlling what you reveal without meaning to: system names and versions in job adverts and conference talks, internal screenshots on social media, travel plans, out-of-office replies that name a deputy and their direct line, documents left on a train. Each item is harmless alone; together they are the reconnaissance an attacker needs to make a pretext convincing. Training that shows staff how an attacker assembles those pieces is more persuasive than a list of rules.
Measuring effectiveness: metrics, managerial reports and behaviour risk scoring
Metrics measure behaviour, not attendance. In order of value:
- Report rate: the share of people who reported a simulated or real phish. A reported phish is a detection, often within minutes.
- Time to first report: minutes is an early-warning system; hours is not.
- Click rate and credential submission rate: useful as trends, and easy to game by sending simple simulations.
- Completion rate: necessary for compliance records, and the least informative about risk.
The measure that connects to everything else is real attacks reported by staff before any tool caught them.
Managerial reports give each manager their own team's picture: trends, outstanding training, and where their people are being targeted. Managers can act on that in a way a company-wide figure never prompts, and they should get trends and patterns rather than a list of names to shame.
Personnel behaviour risk scoring combines signals per person or per role (simulation results, reporting, training status, policy alerts) into a score used to direct targeted training where it is needed. Treat it with care: it is personal data, it should be transparent to the people scored, and it must drive support rather than discipline, or it will suppress the reporting it is meant to improve.
What to take into the exam
- Onboarding sets expectations, ongoing keeps them current, targeted fits the role's threat, and corrective follows a specific failure, quickly and without blame.
- An LMS tracks completion; a self-service portal gives just-in-time help; one-to-one coaches; one-to-many briefs groups fast.
- BEC is defeated by verifying payment changes through a known channel.
- Situational awareness notices the unusual; OPSEC limits what you reveal.
- Report rate is the metric that matters; completion measures attendance.
- Behaviour risk scoring directs training and must not become punishment.
Practise what you just read
1. Which metric should lead the reporting of a phishing simulation programme?
Select one
Show answer
D. A reported phish is a detection, often within minutes, and lets the security team pull the message from every mailbox. Click and credential submission rates are useful trends but can be gamed with easier simulations, and completion measures attendance rather than behaviour.
2. Finance staff have been targeted this month by fake requests to change supplier bank details. What kind of training fits best?
Select one
Show answer
B. Targeted training goes to the roles that face specific attacks, such as finance staff learning payment-change verification against business email compromise. A scenario that describes one group under one kind of attack calls for targeted training, not a module for everyone.
3. An employee has just clicked a simulated phishing link. What should the corrective training look like?
Select one
Show answer
C. Corrective training should be immediate, brief and focused on what to do next time, because the moment after a mistake is when the lesson lands. Punishment suppresses reporting, and reporting is the part of awareness with operational value.
Hands-on labs
Part of the free CompTIA Security+ SY0-801 course — 47 lessons and 78 hands-on labs.
This is an independent study companion for CompTIA Security+ SY0-801 and is not produced by or endorsed by CompTIA.