Compliance
What security awareness training do employees receive?
How to answer this security questionnaire question, with an expert response your security or GRC team can adapt.Expert answer
Require security-awareness training at onboarding and at least annually, including phishing simulations and role-specific training for engineers. Track completion and cover data handling, social engineering, and reporting.What the security reviewer is checking
Every vendor claims annual training, so reviewers differentiate on specifics: when training happens (at hire and on a recurring cycle), whether completion is tracked and enforced rather than optional, whether phishing simulations run with measured results and remedial follow-up, and whether people in higher-risk roles — engineers, administrators, finance, support staff with data access — get content beyond the generic module. Auditors sample completion records, so the numbers must exist. Increasingly, reviewers also ask whether training has kept pace with current threats: AI-enabled phishing, deepfake voice fraud targeting finance teams, and safe handling of data in AI tools.Example response you can adapt
This is an illustrative template, not a real vendor's security posture. Replace every claim with what is actually true for your organization before submitting it.All employees and contractors complete security awareness training during onboarding, before receiving access to production or customer data, and annually thereafter. The curriculum covers phishing and social engineering, credential and MFA hygiene, data classification and handling, incident reporting, physical security, and acceptable use of AI tools, and is refreshed each year for current threats including AI-generated phishing and voice-clone fraud. Completion is tracked in our compliance platform with automated reminders, manager escalation, and access suspension for non-completion past the grace period; completion has exceeded 98 percent in each of the last two cycles. Monthly simulated phishing campaigns run against the whole company, with click and report rates tracked over time — employees who click receive immediate micro-training. Role-based tracks add depth: engineers complete annual secure coding training aligned to the OWASP Top 10, and finance staff receive targeted payment-fraud and pretexting training.
Evidence reviewers expect you to attach
- Security awareness training curriculum or module list
- Completion rate report from the last annual cycle
- Phishing simulation metrics trend (click rate, report rate)
- Secure coding training records for engineering
- SOC 2 report section covering security training (CC1.4/CC2.2)
Follow-up questions reviewers ask next
- What are your current phishing simulation click and report rates?
- What happens when an employee repeatedly fails phishing simulations?
- Do engineers receive secure coding training beyond general awareness content?
- Are contractors and temporary staff required to complete the same training?
- Does training cover safe use of AI tools with company and customer data?
Answer every security questionnaire in minutes
Wolfia drafts accurate, cited answers to security questionnaires and RFPs from your existing documentation. See it work on your own questions.Book a demoRelated compliance questions
Do you have a formal Information Security Policy?Do you have a documented incident response plan?Do you have a business continuity plan?Do you have cyber insurance coverage?How do you manage third-party vendor risk?Do you have a responsible disclosure policy?
Browse the full security questionnaire question library