SEC536: Adversarial AI - Penetration Testing AI Systems

Phishing awareness training helps employees recognize and respond to phishing attempts: deceptive emails, links, QR Codes, or messages designed to steal information or deliver malware. It matters because phishing remains one of the most common and effective ways attackers gain access to organizations.
SANS Workforce Security & Risk Training teaches employees how phishing works, what red flags to look for, and how to report suspicious activity. When employees understand attacker tactics and know what to do, they become a critical part of your organization’s defense.
Attackers know that people, not technology, are often the easiest way into an organization. While security tools block many threats, one mistaken click can still give attackers access to systems, credentials, or sensitive data.
Phishing awareness training helps close this gap by building stronger human defenses. Workforce Security & Risk Training focuses on how social engineering works, from fake invoices to impersonated executives, and gives employees the confidence to question and verify before acting.
Employees encounter a range of phishing tactics, including:
SANS Workforce Security & Risk Training helps employees recognize these tactics through real-world examples, interactive learning, and continuous reinforcement.
Phishing awareness training works by changing behavior. When employees understand how attackers think and what phishing looks like, they stop engaging with suspicious messages and start reporting them instead.
Through ongoing, scenario-based modules and optional simulated phishing campaigns, SANS Workforce Security & Risk Training helps organizations measure and track progress, reinforce key lessons, and reduce their overall exposure to phishing threats.
SANS recommends that organizations deliver phishing awareness training on a continuous basis rather than as a one-time event. This can include:
a. Onboarding training for all new hires.
b. Quarterly refreshers with updated threat examples.
c. Regular phishing simulations to test and reinforce behavior.
d. Role-based training: Providing tailored guidance for employees in higher-risk roles such as finance, HR, or IT, who may face more targeted attacks
Frequent, relevant reinforcement ensures that employees stay alert to evolving phishing tactics and maintain good habits over time. Aligning these activities with frameworks such as NIS2 or ISO 27001 also supports organizational compliance and a more mature security culture.
Measuring effectiveness involves tracking both behavioural and cultural indicators. SANS recommends monitoring:
When employees consistently report suspicious emails and fewer people fall for simulations, it’s a strong sign that training is reducing human risk and strengthening the organisation’s overall security culture.
Regular phishing awareness training delivers measurable business value. It:
SANS Workforce Security & Risk Training ensures every employee, regardless of role, understands how their actions contribute to the organization’s overall security posture.