Cybersecurity
Security Awareness Training
Training nobody dreads.
Security awareness training teaches your team the handful of things that genuinely matter: how to check an unexpected request, how to handle client information, and what to do the moment something feels off. happier IT runs it for Canadian organizations of roughly 15 to 200 people, in short sessions, with role-specific content for finance, and measures it by how often people report, not how often they click.
Who it's for
Four reasons this ends up on a to-do list.
Two are obligations and two are ordinary good management. All four are satisfied by the same programme.
A contract or a policy requires it. Annual training named in a client’s security schedule, an insurance renewal, or a privacy policy your own organization wrote. You need completion records with dates, not just a good intention.
You did the hour-long video once. Watched at double speed in a background tab and forgotten by the following week. The instinct that it wasted everyone’s time was correct.
New starters get nothing. Training happens annually, so someone who joins in February waits ten months for their first session while having full access from day one.
Your finance team is doing a different job. The people who move money face specific, well-crafted requests that involve no dodgy link at all, and general training does not prepare anyone for them.
What we measure
Reporting rate: what proportion of people flag something suspicious. Time to first report: how quickly, which decides how much of a response is preventive rather than clean-up. Participation, because a programme half the organization skips is not a programme.
Click rate is a thermometer. It is never used as a performance measure for an individual.
What's included
The curriculum, and how it is delivered.
Everything here is designed around one constraint: people have jobs, and the training has to fit into a working day without resentment.
-
Short modules on a regular cadence
A few minutes at a time, monthly, rather than one annual hour. People retain the short version, resent it far less, and the spacing is what makes it stick rather than the total minutes.
-
Plain language throughout
No acronym without a plain-English gloss, no stock photographs of hooded figures at keyboards, and no statistics we cannot source. Training that opens by frightening people teaches them that security is somebody else’s alarming hobby.
-
A finance-specific track
Supplier bank-detail changes, payroll redirection requests, approval thresholds, invoices that arrive slightly early, and requests that arrive by text from a number claiming to be a director. Concrete scenarios, with your actual approval process as the answer.
-
A track for executives and their assistants
The names most likely to be forged, and the people most often asked to act quickly and quietly. Short, direct, and delivered without any suggestion that being busy is a character flaw.
-
Built into onboarding
Day one, before the accounts are handed over, covering the four or five things that matter in the first week. New starters are keen and attentive exactly once, and it is worth using.
-
The topics beyond suspicious emails
Using a password manager, handling personal information under Canadian privacy law, PIPEDA federally, with Alberta and British Columbia running their own private-sector statutes, lost devices, wifi on a jobsite or in a hotel, paper records, and what should not be pasted into a public <a href="/ai/">AI tool</a>.
-
Records for whoever asks
Who completed what and when, what the content covered, and the organizational trend over time. Exportable, and written to satisfy a client questionnaire or an insurer without further work from you.
-
A quarterly conversation about the content
What people reported, what confused them, and what to cover next. The best training topics come from your own reported messages rather than from a vendor’s content calendar.
How it works
Baseline, teach in small pieces, then adjust.
The first measurement is a starting point, never a verdict on anybody.
-
Find the starting point
A short baseline: one simulated message, a two-minute survey about what people find confusing, and a look at how suspicious messages currently get reported. The results go to you as an organizational figure, and no individual list is circulated.
-
Teach in small, regular pieces
Monthly modules of a few minutes, with the finance and executive tracks running alongside the general one. New starters get their session in week one automatically rather than waiting for the annual cycle.
-
Measure the right thing and change the content
Each quarter we look at the reporting rate and the time to first report, and we change what is taught rather than who is blamed. If a topic is not landing, the module is wrong before the people are.
What it costs
Included in managed IT. Standalone, priced per person per year.
It is the cheapest control on this site and the easiest to do badly, which is a bad combination for buyers.
Security awareness training is inside happier IT’s managed IT
Standalone, it is priced per person, per year, and is usually bought with phishing prevention
The real cost is not the licence. It is the twenty or thirty minutes per person per year, plus the hour a quarter someone spends deciding what to teach next. A programme nobody curates becomes a compliance box within a year, and everyone can tell.
A fair warning about platforms
Most awareness platforms sell largely the same library of videos. The differences that matter are whether the content sounds like it was written for adults, whether it can be tailored by role, and whether somebody reviews the results with you.
If a quote is only for platform access, you are buying a video library. That may be all you need, just price it as one.
Why us for this
The non-punitive rule is a working constraint, not a nicety.
Training exists to change what people do in the ten seconds after something looks odd, and the behaviour you want is telling someone immediately. Anything that makes reporting feel risky, a leaderboard, a name in a management report, a joke at a staff meeting, trades a click statistic for the thing that actually protects you.
So: no names published, no results sent to managers as performance items, and a thank-you to everyone who reports, including the many who report perfectly innocent messages. Reporting a real newsletter is a good outcome, and it should feel like one.
happier IT delivers this alongside the monitoring that acts on what people report, from our own security operations centre in Canada. A reported message is searched for across every mailbox and removed. Staffed hours: 24/7, with the Surrey office on Monday to Friday, 8:00 am to 5:00 pm Pacific.
Go deeper
- Phishing prevention and training The technical controls and the simulations.
- Cybersecurity services Where training sits among the other controls.
- Compliance and risk management Where the completion records get used.
Questions
What people ask before they sign anything.
What is security awareness training?
It is regular, short teaching that helps staff recognise and respond to the situations where their decision matters: an unexpected request for money or credentials, a device left somewhere, client information going to the wrong place. Good training is specific to the roles people actually hold, and it treats them as competent adults who have not been told something rather than as the weakest link.
How often should we run it?
Monthly, in pieces of a few minutes, rather than annually in one sitting. Spacing is what produces retention; a single long session mostly produces a completion record. Add a short session at onboarding on day one, and one extra whenever something genuinely changes: a new finance system, a new approval process, a new way of working.
Does security awareness training actually work?
It reliably improves how quickly and how often people report, which is the outcome worth buying. It does not eliminate mistakes, and any provider implying otherwise is overselling. Think of it as reducing the time between something happening and someone competent finding out, a mistake reported in two minutes is a small task, while the same mistake found six weeks later is an investigation.
Should we punish people who keep clicking?
No. Someone who clicks repeatedly needs a conversation about what makes these messages convincing, and often a look at whether their role puts an unusual number of unexpected attachments in front of them, accounts payable and recruitment being the obvious examples. Discipline for a simulation teaches everyone that mistakes are dangerous to admit, which removes the reporting you were trying to build.
Will this satisfy our client’s security requirements?
Usually, provided you can produce the records. Most client security schedules and insurance questionnaires ask whether training happens, how often, and whether completion is tracked. Our reporting is built to answer those three directly. Where a client names a specific framework or curriculum, send it to us and we will tell you plainly whether what we run meets it or not.
What does security awareness training cost?
Whichever you buy, budget the staff time as well, a programme with a licence and no curation stops working within about a year.
Related
Where to go next.
Want to know what this would look like for you?
A 30-minute call. No slides, no audit fee, no obligation. We ask what is breaking and tell you honestly whether we are the right fit.