Cybersecurity Awareness Training
Mandatory annual training program to equip all employees with foundational cyber hygiene practices — phishing recognition, password standards, endpoint protection, and incident reporting procedures.
This policy establishes the mandatory Cybersecurity Awareness Training program for all employees, contractors, and authorized system users. The program is designed to reduce organizational risk by ensuring every individual who accesses corporate systems can identify, avoid, and report common cyber threats — including phishing, social engineering, password compromise, and malware. Training content is updated annually to reflect current threat intelligence and regulatory requirements under PIPEDA and applicable provincial privacy laws.
Completion of the training and a signed attestation is a condition of continued network access. Failure to complete within the designated window results in automatic escalation and may lead to suspension of system privileges. The IT Security department owns the training curriculum; Human Resources manages enrollment and compliance records.
This policy applies to all personnel — permanent, temporary, part‑time, and contract staff — who access any corporate network, email system, SaaS platform, or internal application owned or operated by the organization. Third‑party vendors who require network access to deliver services must also complete an abbreviated vendor security awareness module prior to account provisioning.
Exemptions are granted only by the Chief Information Security Officer (CISO) in writing for roles with zero system access (e.g., purely on‑site physical labour with no digital touchpoints). All exemptions are reviewed quarterly. New hires must complete the training within 30 calendar days of their start date; existing employees must recertify annually by the last Friday of Q1.
- Phishing & Social Engineering: Never click unsolicited links or download attachments from unknown senders. Report any suspicious message to
security@company.cawithin 15 minutes. Quarterly simulated phishing exercises are mandatory; repeated failure requires manager coaching and re‑training. - Password Hygiene: All accounts must use passphrases of at least 14 characters with a mix of character types. Password reuse across corporate and personal accounts is prohibited. MFA is required for all email, VPN, and administrative systems. Passwords must be changed immediately following any suspected compromise.
- Endpoint Protection: All devices connecting to the corporate network must run approved antivirus software, receive OS patches within 7 days of release, and have full‑disk encryption enabled. USB mass storage devices are forbidden unless issued and encrypted by IT. Personal devices must pass a compliance check before accessing corporate email or data.
- Incident Reporting: Any confirmed or suspected security incident — lost device, ransomware, data breach, unauthorized access — must be reported to IT Security within 30 minutes. Do not attempt to contain or investigate independently. The incident response team will triage, contain, and escalate per the Incident Response Playbook.
- Chief Information Security Officer (CISO): Owns the training program, approves curriculum changes, reviews exemption requests, and reports program effectiveness to the executive team quarterly. Maintains the incident response escalation chain.
- IT Security Team: Develops and updates training modules, conducts phishing simulations, tracks completion rates, investigates reported incidents, and provides remediation coaching for repeat offenders.
- Human Resources: Enrolls new hires within 5 days of onboarding, manages the annual recertification window, records signed attestations in personnel files, and coordinates disciplinary actions for non‑compliance with the employee's manager.
- Managers & Supervisors: Ensure direct reports complete training on time, discuss security expectations during one‑on‑one meetings, and approve leave or shift swaps that may affect training deadlines. Managers are accountable for their team's 100% completion rate.
- All Employees & Contractors: Complete all assigned modules, pass the knowledge assessment with a score of 80% or higher, sign the annual attestation, and report any security incident or near‑miss immediately. Failure to comply results in network access suspension.