Security awareness with a defensible record

Security training that survives inspection.

Continuous security awareness for any organization that has to prove its people were trained. Twelve core modules, monthly reinforcement, and a training record built to be inspected — so when an auditor, an assessor or a customer says show me your evidence, it takes ninety seconds, not two weeks.

Regulated? Add the pack your framework names: 21 CFR Part 11 · HIPAA · GLBA · PCI DSS · NIST 800-171 · ISO 27001

Training record · export preview ◼ Verified
Person
M. Okafor · Accounts Payable Specialist
Module
A.1 — Phishing, Spear Phishing & Social Engineering
Version
2.4.0 (effective 2026-06-01)
Completed
2026-08-14 09:41:07 CDT
Assessment
94% · threshold 80% · 1 attempt
Signature
Electronic · meaning: completed and understood
Record ID
TS-8841-A1-0714
Audit trail · 4 entries · no modifications Retention: per records policy

Illustrative export. Every completion produces one of these.

The problem

The annual video is not a program.

Most security awareness training exists to be completed, not to change behavior. Once a year, everybody clicks through forty minutes of stock footage, and the organization goes eleven months without another word about it — while the phishing gets better every quarter.

Then someone asks for proof. A customer security questionnaire, a SOC 2 auditor, a HIPAA risk analysis, a cyber-insurance renewal, an FDA inspector. Every one of them wants the same thing: who was trained, on what, when, and can you show it. A completion checkbox in a generic LMS is not an answer.

Annual compliance video

  • One 40-minute sitting, once a year
  • Same content for the engineer, the receptionist and the CFO
  • Generic curriculum with a compliance module bolted on
  • Nothing about the provision your assessor actually cites
  • Evidence is a spreadsheet export someone reformats under pressure
  • Content ages for twelve months while threats don't

Trained State

  • Annual course establishes the baseline, assessed and signed
  • Monthly units of three to five minutes keep it current
  • Role variants so people learn what applies to their job
  • Add-on packs cover the regulation your framework names, by section
  • Inspection packet exports attributable, timestamped records on demand
  • Event-driven units ship within 48 hours of a real incident

Core curriculum

Twelve core modules. Four tracks. Then the pack your regulator expects.

Tracks A through D are the security awareness canon, written for busy professionals rather than for a generic office. Every organization gets them. Add-on packs go deeper where a specific framework says you must.

Track A

Human attack surface

  • A.1Phishing, spear phishing, smishing and social engineering
  • A.2Password security and multi-factor authentication
  • A.3Secure email, internet and communication practices

Track B

Information & privacy

  • B.1Protection of confidential, proprietary and sensitive information
  • B.2Privacy and personal data protection
  • B.3AI and emerging technology security risks

Track C

Device & environment

  • C.1Malware and ransomware awareness
  • C.2Endpoint, laptop and mobile device security
  • C.3Remote working and physical security

Track D

Governance & third parties

  • D.1Access control and least privilege
  • D.2Acceptable use of company systems and technology
  • D.3Third-party, vendor and cloud security

Add-on packs

The modules your regulator names. Cited by section.

A pack adds three or four modules written by people who work in that sector, cites the provision it supports on screen and in the record, and exports in the form that framework's reviewer expects. Core first, pack on top, one record.

Design-partner pilot · available now

Clinical & GxP

Clinical sites, CROs, sponsors, and the recruitment and data vendors around them.

  • E.1Clinical trial and regulated data protection
  • E.2Electronic records, audit trails and data integrity
  • E.3Security incident identification, escalation and reporting

21 CFR § 11.10(i) · ICH E6(R3) · ALCOA+

The clinical research page →

Roadmap · built with a design partner

Healthcare & HIPAA

Covered entities and business associates: providers, health plans, and the vendors that touch their data.

  • Protected health information and the minimum-necessary standard
  • Recognizing a breach and who to tell, in what order
  • Security reminders, malware, log-in monitoring and passwords as the rule lists them

45 CFR § 164.308(a)(5) · § 164.530(b)(1)

Roadmap · built with a design partner

Financial services

Lenders, brokers, advisers, insurers and fintech under the FTC Safeguards Rule.

  • Customer financial information and who may see it
  • Payment fraud, invoice redirection and executive impersonation
  • Training that tracks the risk assessment, as the rule requires

16 CFR § 314.4(e)(1) · NY DFS 23 NYCRR Part 500

Roadmap · built with a design partner

Payment card

Merchants and service providers with a cardholder data environment.

  • What cardholder data is and where it is allowed to exist
  • Skimming, tampering and social engineering at the point of sale
  • Handling card data on the phone and in support tools

PCI DSS v4.0 · Requirement 12.6

Roadmap · built with a design partner

Defense & government contractors

Suppliers handling controlled unclassified information under CMMC and DFARS.

  • CUI and FCI: recognizing, marking and handling it
  • Insider threat awareness
  • Reporting a cyber incident up the contract chain

NIST SP 800-171 · Awareness and training family (3.2) · CMMC 2.0

Roadmap · built with a design partner

SaaS & technology vendors

Companies proving SOC 2 or ISO 27001 to their customers.

  • Customer data handling and tenant isolation, for non-engineers too
  • Secrets, tokens and access hygiene
  • What the auditor will ask about your training, and the evidence they accept

ISO/IEC 27001:2022 · Annex A 6.3 · SOC 2 Trust Services Criteria

Roadmap · built with a design partner

Privacy & data protection

Organizations processing EU, UK or state-privacy-law personal data.

  • Lawful handling, purpose limitation and data minimization in daily work
  • Data subject requests and what not to say in the reply
  • Breach notification duties and the internal escalation that makes them meetable

GDPR Art. 32 · Art. 39(1)(b)

Roadmap · built with a design partner

Energy & critical infrastructure

Utilities and operators with personnel who touch bulk electric system cyber systems.

  • Operational technology is not IT: the differences that matter to the person at the console
  • Physical and electronic access to protected systems
  • Awareness and role-based training as the standard separates them

NERC CIP-004 · Personnel & Training

Roadmap packs are built with a design partner in that sector. If yours is on the list, that partner could be you.

Why packs

Everyone can sell you phishing simulation.

Nobody else will teach your people the module your assessor actually cites.

Incumbents sell one generic curriculum with a compliance module bolted on. Packs are written by people who have sat on the wrong side of an audit in that sector, and every module names the provision it supports — on screen, in the record and in the export.

  • Core first. Everyone completes Tracks A through D. A pack adds to the core; it never replaces it, because the phishing email does not care which regulation you are under.
  • Role variants. Each pack module has a full version for the people who do the work and a short version for everyone else who needs to recognize it.
  • Cited, not implied. A pack module says which section it supports and what a reviewer would look for. No acronym soup, no claims we cannot back.
  • One record. Core and pack completions land in the same training record and the same inspection packet, with the same timestamps, versions and signatures.

How it runs

Establish it once. Maintain it all year. Prove it on demand.

Four modes, one program. The annual course is the floor, not the whole building.

Annual

Establish

The core curriculum plus your packs, assessed against a pass threshold and closed with an electronic signature. Roughly an hour, adjusted by role. This is the artifact an auditor asks for.

Monthly

Maintain

One unit of three to five minutes, plus a phishing simulation. Rotates through the tracks so no topic goes more than a quarter without contact.

On event

React

Triggered by a real incident, a new customer requirement or an emerging threat. Under three minutes, published within 48 hours. This is what makes a program feel alive rather than annual.

Always on

Prove

Every completion writes a durable record: what, when, which version, what score, whose signature. Export the whole population as an inspection packet, or one person as a training file.

The record

Built so the evidence holds up.

Most training platforms treat reporting as an afterthought — a CSV of names and dates, assembled the week before an audit. When someone is checking your work, the record is the deliverable. It has to be attributable to a real person, contemporaneous with the act, tied to the exact content version, and impossible to quietly change.

Trained State applies the data integrity principles that regulated industries have used for decades to its own records. The audit trail is computer-generated, independently timestamped, and retained for the life of the record. Content versions are frozen at completion, so a record from 2026 still shows what the person was actually taught in 2026.

Trained State supports your Part 11, HIPAA, GLBA and similar obligations. It does not make an organization compliant on its own — compliance depends on your procedures, your validation and how you use the system.

  • AttributableTied to a uniquely identified individual, never a shared login.
  • LegibleHuman-readable export, no proprietary viewer required.
  • ContemporaneousWritten at completion with an independent server timestamp.
  • OriginalThe system of record, not a re-keyed summary.
  • AccurateScore, attempts, version and threshold captured as taken.
  • CompleteIncludes failed attempts and remediation, not just the pass.
  • ConsistentOne timestamp standard and one identity across all records.
  • EnduringRetained per policy, independent of employment status.

What it maps to

Every module cites the provision it supports.

On screen, in the record, and in the export — because that is what the reviewer is checking for.

FrameworkProvisionObligationWhere
HIPAA Security Rule45 CFR § 164.308(a)(5)A security awareness and training program for all workforce members, including periodic reminders, malware protection, login monitoring and password management.Core · Healthcare
HIPAA Privacy Rule45 CFR § 164.530(b)(1)Training of all workforce members on the policies and procedures for protected health information, as necessary for their functions.Healthcare
FDA 21 CFR Part 11§ 11.10(i)Determination that persons who develop, maintain or use electronic record and electronic signature systems have the education, training and experience to perform their assigned tasks.Clinical & GxP
ICH E6(R3) GCPComputerised systemsExpanded expectations for computerised systems, data governance and risk-proportionate quality management across sponsors, CROs and sites.Clinical & GxP
FTC Safeguards Rule16 CFR § 314.4(e)(1)Security awareness training for personnel, updated as necessary to reflect risks identified by the risk assessment.Financial services
PCI DSS v4.0Requirement 12.6Security awareness education as an ongoing activity for all personnel, with acknowledgment of the security policy.Payment card
NIST SP 800-171Family 3.2Awareness and training requirements for organizations handling controlled unclassified information, the basis of CMMC assessment.Defense & government
ISO/IEC 27001:2022Annex A 6.3Information security awareness, education and training for personnel and relevant interested parties.SaaS & technology
GDPRArt. 32 · Art. 39(1)(b)Security appropriate to risk, and an explicit data protection officer duty covering awareness-raising and training of staff involved in processing.Core · Privacy
NERC CIP-004Personnel & TrainingSecurity awareness and role-based training for personnel with access to bulk electric system cyber systems.Energy
NIST SP 800-53AT control familyAwareness and training controls, for customer security questionnaires and federal or government-contract-adjacent work.Core

Who it's for

Anyone who gets asked for proof.

Companies proving it to customers

Security and compliance leads answering questionnaires and SOC 2 or ISO 27001 auditors, who need training evidence that does not have to be assembled by hand.

Healthcare & covered entities

Providers, plans and business associates whose risk analysis and workforce training are the first two things a HIPAA reviewer asks about.

Clinical research

Sites, CROs, sponsors and trial vendors who get audited by sponsors and inspected by regulators. There is a page for you.

Finance, payments & government contractors

Organizations whose regulator or contract names a training requirement by section, and whose assessor will check for it.

Pilot program

Start with the core. Add the pack.

We're onboarding a small number of design partners. Clinical research organizations get the Clinical & GxP pack now; if your sector's pack is on the roadmap, a design partner is how it gets built. You get the program first, we get your audit findings and your people's honest opinion of the content. Fair trade.

Developed with a clinical research design partner · STACSTRAT LLC