Training & Awareness
Implementation and audit guidance for cybersecurity-related awareness and training activities.
Guidance to Implement
Implement a recurring, updated security awareness communications schedule; incorporate current threat scenarios into content.
Guidance to Audit
Awareness materials
Key Performance Indicator
X% of employees recognize AI-generated threats.
Guidance to Implement
1- Pause & Frame: employees articulate the problem by themself before querying an AI. 2- Strip & Test: remove sensitive data and run a low-risk test prompt. 3 - Cross-Check: compare AI output with at least one human-curated source before action.
Guidance to Audit
Use structured micro-quizzes or decision-case assessments where employees must demonstrate the three-step protocol. Optionally, gather anonymized prompt summaries tagged by users in internal AI tools to assess adherence patterns.
Key Performance Indicator
Achieve X% reduction in data leakage incidents and hallucinations in AI outputs.
Guidance to Implement
Integrate interactive modules + tabletop drills that include crisis-counselling protocols.
Guidance to Audit
Review completion logs and sample staff feedback; verify deepfake scenarios are included in drills.
Key Performance Indicator
Reduce stress-related errors from AI threats by X%.
Guidance to Implement
Create and maintain an up-to-date, searchable internal knowledge base with regular content reviews and updates.
Guidance to Audit
Knowledge base usage logs and periodic update records.
Key Performance Indicator
Update knowledge base quarterly with X% of new AI-related incidents.
Guidance to Implement
Conduct quarterly evaluations (via surveys and testing) to refine training content based on feedback and incident trends.
Guidance to Audit
Evaluation reports and documented improvement plans.
Key Performance Indicator
X% of employees pass the AI risk readiness test.
Guidance to Implement
Integrate insider threat scenarios into training modules and use simulations to reinforce learning.
Guidance to Audit
Simulation reports and incident reporting logs.
Key Performance Indicator
X% of employees successfully identify AI-driven insider threats.
Guidance to Implement
Offer annual training sessions focused on physical security measures and emergency response procedures.
Guidance to Audit
Training attendance records and post-training assessments.
Key Performance Indicator
X% of employees recognize AI-enhanced physical threats.
Guidance to Implement
Extend training requirements to third parties and verify training completion before system access is granted.
Guidance to Audit
Third-party training certificates and compliance audit logs.
Key Performance Indicator
X% of third-party contractors complete AI misuse training.
Guidance to Implement
Schedule tailored security briefings for the executive board focusing on strategic risks and incident impacts.
Guidance to Audit
Executive meeting minutes, presentation slides, and attendance records.
Key Performance Indicator
X% of executives receive training on deepfake risks annually.
Guidance to Implement
Provide training materials in multiple accessible formats (video, text, interactive) and ensure compliance with accessibility standards.
Guidance to Audit
Accessibility compliance reports and user feedback surveys.
Key Performance Indicator
X% compliance with accessibility standards in AI tools.
Guidance to Implement
Mandate annual certification for security professionals; offer study support and monitor status.
Guidance to Audit
Certification receipts and HR training records.
Key Performance Indicator
X% of security professionals certified in AI threat defense strategies.
Guidance to Implement
Subscribe to reputable threat intelligence sources and review the information regularly during team meetings.
Guidance to Audit
Subscription records and meeting minutes discussing threat intelligence.
Key Performance Indicator
Update threat intelligence with AI-specific data every X weeks.
Guidance to Implement
Plan and budget for attendance at a major security conference and require post-event knowledge sharing sessions.
Guidance to Audit
Conference attendance records and post-event reports.
Key Performance Indicator
X% attendance rate at AI-focused security sessions.
Guidance to Implement
Encourage security team members to join professional cybersecurity associations and track their involvement.
Guidance to Audit
Membership certificates and activity logs.
Key Performance Indicator
X% participation in AI security professional groups.
Guidance to Implement
Develop specialized training modules tailored to data privacy laws and relevant regulatory requirements.
Guidance to Audit
Training completion certificates and assessment results.
Key Performance Indicator
X% of data privacy training modules include AI-specific privacy issues.
Guidance to Implement
Map employee roles to applicable regulations using a maintained regulatory matrix. Integrate AI-specific requirements (e.g.; transparency; explainability; fairness) into training modules and update as laws evolve. Collaborate with legal counsel to ensure coverage of high-risk areas like automated profiling; synthetic data; and algorithmic accountability.
Guidance to Audit
Verify presence of regulatory role-mapping; and check AI-related content version history in LMS or training platform.
Key Performance Indicator
X% completion rate for AI regulatory compliance training.
Guidance to Implement
Establish a recognition program for employees who report potential security issues; share success stories internally.
Guidance to Audit
Recognition program records and internal communication examples.
Key Performance Indicator
X% of employees report AI-related security incidents.
Guidance to Implement
Highlight positive security behaviors in internal newsletters, using anonymized case studies for learning.
Guidance to Audit
Internal newsletter editions and employee feedback surveys.
Key Performance Indicator
Highlight X% cases per quarter where AI threats were identified.
Guidance to Implement
Deploy quarterly anonymous surveys to gauge security sentiment and adjust training accordingly.
Guidance to Audit
Survey reports and trend analysis documents.
Key Performance Indicator
Conduct surveys every X months with Y% participation and actionable insights.