52 / 63Security Awareness Training

Security awareness training somebody actually runs, month after month

Canadian security awareness training run as a programme, with phishing simulation, coaching, and an auditor-ready record.

  • CCIE Security-led team
  • Running Canadian programmes since 2021
  • Platform-neutral, we'll run yours
THE WORK

Security awareness training, three pillars, one operator.

One Canadian team sends the phish, coaches whoever clicked, and keeps the record your auditor asks for. Employee security training only changes behaviour when somebody owns the calendar every month.

  1. 1

    Phishing simulation

    Lures built from your own suppliers and systems, getting harder as your people get better. The phishing simulation runs monthly, not every October, and it goes out whether or not anyone chases us for it.

  2. 2

    Coaching at the click

    A ninety-second lesson the moment somebody clicks, plus a report button people trust using, sitting inside the mail client they already have open.

  3. 3

    The record

    Completion, click rate, reporting rate and exemptions, per person, per framework, signed off. That record is the artefact an auditor can count, and most training platforms can't produce it.

THE PROOF

Built to last. Evidence over promises.

98% of Canadian organisations already train their people. Only 39% make that training mandatory for everyone (CIRA Cybersecurity Survey, 2025). We run security training Canada-wide as a programme, because the gap between those two numbers is where the clicks happen.

IN PRODUCTION

Phishing reports a Canadian auditor could count.

We'd owned a training platform for three years. Everybody watched the videos every October, and our click rate never moved. SMEnode ran it properly, monthly, with lures built from our own invoices. Now people forward the suspicious ones instead of quietly deleting them.

SMEnode · Engineering principle
  • CCIE Data Center
  • CCIE Security
  • CCDE Design
  • Canadian data residency
THE DEEP DIVE

Security awareness training in Canada, made real.

Nearly every organisation runs training of some kind. Far fewer can tell you whether it changed what anybody does.

Reporting rate is the number worth chasing.

Good work moves the reporting rate, not the click rate. Click rate is the number every platform puts on its dashboard, and it mostly tells you who got caught this month. Reporting rate tells you how many people saw something wrong and said so, which is the behaviour that turns a bad morning into a short one. So we chase the second number. It climbs slowly, it climbs unevenly by team, and it keeps climbing once somebody owns the programme.

The platform isn't the problem, the running of it is.

You probably own a platform already, and we'll run the one you have. Content in this market is close to interchangeable, so swapping libraries rarely changes an outcome. What changes it is somebody owning the calendar, writing lures that look like your own suppliers, chasing the twelve people who never finished, and dealing with the executive who asks to be exempted. Human risk management is the newer name for that work, and the name matters far less than who does it on the first Monday of the month.

What Canadian compliance actually asks for.

The compliance answer is more specific than most pages admit. PCI DSS names phishing and social engineering in requirement 12.6.3.1 and expects training at least once every twelve months (Source: PCI Security Standards Council, PCI DSS v4.0.1, 2026). ISO 27001's Annex A 6.3 expects an ongoing awareness programme for everyone with access, evidenced by completion records (Source: ISO/IEC 27001:2022). Federally regulated financial institutions answer to OSFI's B-13, whose companion guideline E-21 reached full adherence on 2026-09-01. Under PHIPA and Quebec's Law 25, accountability for the people handling personal data stays with you.

Zero-Trust vault
THE METHOD

How our phishing simulation and human risk management work runs.

Four steps, and step 01 is the one nobody enjoys. We send a realistic phish before any training goes out, because a click rate measured after a warning tells you nothing. It usually lands somewhere between one in five and one in three, senior people click about as often as junior ones, and finance is rarely the worst team. That baseline is the only honest number you'll get, and you only get it once.

  1. Step 01

    Baseline quietly

    One unannounced simulation across everyone, scored by department and seniority rather than by named individuals, so the first conversation is about the pattern instead of about who fell for it. Nobody gets a list of names in week one.

  2. Step 02

    Build the programme

    Monthly cadence, lure themes mapped to how your organisation actually gets attacked, role-based content for the teams that move money, and a written exemption policy before anybody asks for one.

  3. Step 03

    Run it, every month

    We send, we coach, we chase the stragglers, and we keep the report button working inside your mail client. Nothing here waits for October.

  4. Step 04

    Report and prove

    A board-ready trend on reporting rate and click rate, per-person completion evidence mapped to whichever framework you answer to, and a short list of the teams that need a different approach next quarter.

QUESTIONS

Security awareness training questions, answered straight.

Answers first, including the free option and the case for waiting a quarter. An architect takes the call, not a salesperson.

More organisations than realise it. Take card payments and PCI DSS requires training every twelve months, with phishing named specifically. Chase ISO 27001 or SOC 2 and an auditor will ask for completion records against a named control. Federally regulated financial institutions answer to OSFI. Anyone holding health records or Quebec personal data carries accountability for the staff touching it, whether or not a rule names training.

Yes, and some of it's good. The Canada School of Public Service publishes a free course, and several vendors give away a starter tier. Free content isn't the expensive part. The expensive part is somebody sending simulations on schedule, following up the people who ignore three reminders, and producing evidence in the shape an auditor wants. Take the free videos. Pay for the programme that makes them count.

The running of it. Most organisations we meet bought a licence, ran the onboarding module, and left it there. We take over the calendar, write lures from your own supplier and invoice patterns, coach at the moment of the click, handle exemption requests, and hand you a signed record each quarter. If you're already on a mainstream awareness platform, we'll operate it rather than sell you a replacement.

Reporting rate, mostly. Click rate drops quickly once people know simulations are coming, which flatters everyone and proves little. The number that matters is how many people report a suspicious message, how fast they do it, and whether that holds when the lure is one they haven't seen before. We track both, per team, and we'll say plainly when a flat quarter means the content went stale.

When nobody will own the follow-up, because unenforced training is worse than none: it produces a record saying you tried. When the logins aren't locked down yet, since fixing that stops the same attack more cheaply. And when your reporting inbox goes nowhere, because asking people to report and then ignoring them teaches them to stop reporting.

Not in week one. The baseline is scored by department and seniority, so the first conversation is about the pattern rather than a list of names. Once the programme is running, managers see their own team's numbers, repeat clickers get coaching, and the per-person record stays for the auditor rather than the all-staff email.

LET'S CONNECT

A senior engineer replies within an hour, 24/7.