A living standard for security awareness practice
Written by practitioners, endorsed by vendors, owned by neither. A shared standard for what good security awareness practice actually looks like.
Foundations
While there is value in the items on the right, we value the items on the left more.
Out-of-the-box settings are a starting point, not a policy. The person running the programme should be trusted to adapt it.
A programme's success is measured by what people do differently, not how many finished a module.
Frequency should be set by risk, role, and evidence of what's working, not a fixed schedule because it sounds thorough. Over-frequent simulation breeds fatigue and complacency, the opposite of the culture it's meant to build.
One well-targeted intervention beats ten generic ones sent to everyone.
Programmes that punish or shame users for failing simulations erode the reporting culture they're meant to build.
The function should offer real senior roles, not force practitioners to leave the field to keep advancing. Remove the ceiling and there's no need to leave it in the first place, so the best talent stays, the next generation has something to aspire to, and the skills built over a career aren't lost.
Practice standards
Every practice area sits somewhere on the same path, from rigid compliance to a genuine culture shift. Select one to see the full standard.
Endorsed by
Get involved
Add your name as a practitioner who stands behind these principles and standards.
Publicly commit to building toward this standard and have your logo added to the wall.