HomeBlog › Security training

Security training for new hires and contractors

Annual compliance videos train people to click through as fast as the player allows. Thirty focused minutes during onboarding, covering four things, does more than an hour of content nobody watches.

Security training illustration: new joiners walking a path marked with the topics onboarding should cover, including phishing awareness, access basics such as accounts and least privilege, device handling, and how to report a problem, beside a welcome checklist.

Security awareness training has a credibility problem. Most people's experience of it is a mandatory annual video with a quiz that can be passed by guessing, which trains exactly one behaviour: clicking through as fast as the player permits.

The version worth doing is different in kind. It is short, it is specific to how your company actually works, it happens when someone joins rather than on an anniversary, and it covers four things.

Why onboarding is the moment

A new joiner is paying attention, forming habits, and has not yet learnt any workarounds. They are also, in the first fortnight, unusually vulnerable: they do not know who normally emails them, they do not know what requests are normal, and they very much want to be helpful.

That combination is precisely what a targeted phishing attempt exploits. A message claiming to be from a founder, asking a new employee to do something slightly unusual and slightly urgent, works far better in week one than in year two. Training that arrives at the next annual cycle has missed the window entirely.

The four things worth covering

Phishing: spot it, stop, report it

Not a taxonomy of attack types. Three practical habits.

Urgency plus unusual request is the pattern. Almost every successful social attack combines time pressure with something outside normal process. Teaching people to slow down specifically when both are present is more effective than teaching them to inspect headers.

Verify through a different channel. If a message asks for something consequential, confirm it by another route: call the person, message them somewhere else. Never reply to the message to check whether the message is genuine.

Reporting is always welcome. Say explicitly that nobody will be made to feel foolish for reporting something that turns out to be fine. The cost of a false alarm is thirty seconds; the cost of someone staying quiet because they feel embarrassed is the entire incident.

How accounts and access work here

Specific to you, not generic advice. Which password manager, and that everything goes in it. That MFA is required and why. That they will get access to what they need and not more, and that this is not about trust. Who to ask when they need something they do not have.

The useful subtext is that asking for access is normal and sharing credentials is not. Most credential sharing in small companies happens because somebody needed something at 5pm and the request path was unclear.

Devices and data

Where customer data may and may not go. Whether personal devices are permitted and under what conditions. That downloading a customer export to a laptop to work on it is a decision with consequences rather than a neutral act. Disk encryption, screen lock, what to do if a device is lost.

Keep it to what you actually expect. A policy prohibiting something the team does daily is a policy that teaches people to ignore policies.

How to report something wrong

One channel, one name, no judgement. Whether it is a suspicious email, a mistake they made, or something that just looks odd.

Mistakes are the important case. Someone who clicked a link and typed a password needs to tell you in the next five minutes, and whether they do is determined almost entirely by whether they expect to be blamed. Say out loud that reporting quickly is the thing you value, and that you would rather hear about it at once than discover it later.

Contractors, and why they are the gap

This is where most small companies fail, and where auditors look.

Contractors are hired for a specific piece of work, given access quickly, and skip the onboarding process because they are not going through the HR flow. They frequently have production access. They frequently have less context about what is sensitive.

The fix is not a separate programme. It is deciding that access to your systems triggers the same thirty minutes, whatever the contractual relationship. If somebody can reach customer data, they get the same session and the same record.

Their engagement should also have an end date attached at the start, which is the same point made in the offboarding checklist: a contractor with a ninety-day access expiry is one whose access closes itself when everybody forgets.

Phishing simulations, and whether to bother

Simulated phishing is the obvious next step and it is worth being careful about, because done badly it makes things worse.

The failure mode is using it to catch people. Teams that publish click rates, or single out individuals, teach one lesson very effectively: do not admit to anything. That is the opposite of what you need, because your entire detection capability for social attacks is people volunteering that something looked odd.

If you run simulations, set the purpose explicitly as measuring reporting rather than clicking, tell the team in advance that simulations happen, and publish only aggregate results. The number worth watching is what proportion of recipients reported it, not what proportion clicked.

For a team of under about ten people, simulations are usually not worth the effort compared with simply sharing the real attempts as they arrive. You will get several genuine ones a year, and they are better teaching material than anything simulated, because they are aimed at you specifically.

Evidence

This is what turns training from an activity into a control, and it is cheap.

Keep a simple record: name, date, what was covered, and a version number for the material. A spreadsheet is entirely adequate. When a customer asks whether staff receive security training, you can answer with a list rather than a reassurance.

Also version the material itself. Being able to say what the training covered in March of last year, rather than only what it covers now, is the difference between a record and a claim.

Keeping it alive without an annual video

The annual refresh is worth doing and is not where the value is. Two cheaper habits do more.

Share real examples. When a phishing attempt reaches the team, post it with a short note on what gave it away. This is more memorable than any training module because it is real, current, and aimed at them specifically.

Explain changes when you make them. When you enforce MFA or change how access is requested, say why in a sentence or two. Teams that understand the reasoning route around controls far less than teams who experience them as arbitrary.

Both of these cost nothing and accumulate. A team that talks about this occasionally is meaningfully safer than a team that watches a video once a year, regardless of what the compliance record says.

What a Trufend scan can and cannot tell you here. Training is entirely internal: who received it, what it covered, and whether it changed anyone's behaviour. None of that is observable from outside. Trufend reports what your domain exposes publicly and is explicit that it is not a SOC 2 assessment.

The minimum that counts

Write one page covering the four topics above, specific to your company. Spend thirty minutes on it with every new joiner and every contractor with access. Record who and when.

That is a real control, it is defensible in a security review, and it takes less time to set up than evaluating training platforms.

Questions people ask about this

What must security training cover?

For most small teams: recognising and reporting phishing, how accounts and access work here including MFA and least privilege, how to handle devices and data, and how to report something that looks wrong. Everything else is optional.

How often should it be repeated?

At onboarding, and then a short refresh annually. The refresh matters less than the onboarding session and less than the ongoing habit of discussing real examples when they happen.

Do contractors need the same training?

Yes, and they are the group most often missed. Anyone with access to your systems or your customers' data needs to know how you expect them to behave, whatever their employment arrangement.

Do we need to buy a training platform?

No. A written page, a thirty-minute conversation and a record of who completed it is a legitimate control for a small team. A platform helps mostly with tracking, which a spreadsheet also does.

Can Trufend verify our training?

No. Training is entirely internal. Trufend reports what your domain exposes to an anonymous visitor and is not a SOC 2 assessment.

Check your externally visible posture

Trufend reports TLS, DNS, security headers, email authentication and exposed assets for any domain. Free and passive.

Run a free check