What is security awareness training (SAT)?
A security awareness programme (Security Awareness Training, SAT) isn't a once-a-year course you forget. It's ongoing training + simulations to change your team's behaviour against real threats.
The goal isn't passing a test, it's cutting human risk and being able to prove it with data.
How phishing simulation works
Phishing simulations are the heart of the programme: realistic sends to measure and train.
- Simulated phishing based on real attacks.
- Measurement of who clicks and how they react.
- Just-in-time training, right when someone fails.
- Repetition to build the habit.
- Per-employee and overall reporting for management.
Who and why?
Training your team is no longer optional.
- Required to train by NIS2, ISO 27001 or the ENS.
- Because phishing is the number-one way in.
- To actually reduce incidents, not just tick a box.
How we set it up
- Baseline. A first simulation to see where you stand.
- Campaign plan. Across the year, not all at once.
- Simulations + training, tailored to each person's risk.
- Tracking and continuous improvement.
- Management report with the trend.
It's Tria's Human Factor, built on a white-label platform with a per-employee cost. It comes as a Plan Tria add-on: basic awareness is included; the ongoing programme with simulations is the advanced level.
Frequently asked questions
Is it a course or something ongoing?
Ongoing. A one-day course is forgotten; behaviour change comes from simulations and reinforcement across the year.
Does simulated phishing really fool my people?
Yes, it's realistic on purpose: that's how people learn. When someone clicks, they get in-the-moment training, with no blaming or punishment.
How much does it cost?
Billed per employee, with a monthly or annual fee depending on team size.
Does it help me comply with NIS2, ISO 27001 or the ENS?
Yes: it's the training-and-awareness evidence those standards require.