Tutorials/Security Awareness Training Evidence Structure

Security Awareness Training Evidence Structure

Purpose

This document sets out the security training every person at Hybrowlabs receives, when they receive it, and the evidence we retain.

Most security failures in an ERP implementation are not technical. They come from a screenshot pasted into a public ticket, a database export left in a downloads folder, a customer credential shared over chat, or an administrator acting on a request that was not what it appeared to be. Training is aimed at those situations rather than at generic security theory.

Audience

Everyone who performs work for Hybrowlabs completes training, including contractors, interns and subcontracted personnel. Training is a condition of holding access, not an optional development activity.

Curriculum

Training is delivered in three modules. The module assigned depends on the access the role holds.

Module Who receives it Cadence
Core security awareness Everyone Onboarding, then annually
Customer data handling Consultants, developers, support and account teams Onboarding, then annually
Privileged access Anyone holding administrative access to a customer environment Before access is granted, then annually

Core security awareness

  • Phishing and business email compromise, including invoice and payment change requests
  • Social engineering attempted by phone or messaging rather than email
  • Credential handling and the approved password manager
  • Multi-factor authentication
  • Device controls: disk encryption, automatic screen lock, current patching
  • Physical security and clear desk
  • Recognising an incident and reporting it immediately rather than resolving it privately
  • The prohibitions set out in the Acceptable Use Policy

Customer data handling

  • Data classification and what counts as customer data
  • Exports, backups, screenshots, log files and support attachments, which routinely contain live records
  • Production data in development and demonstration environments, and when masking is required
  • Approved channels for file transfer and customer communication
  • Restrictions on public AI tools, code assistants and file converters
  • What may not be posted in community forums, public issue trackers and public repositories
  • Personal data obligations and customer-specific restrictions

Privileged access

  • Administrator and System Manager roles, and why they are not the default working role
  • Permission and role changes, and their effect on existing users
  • Server and bench access, SSH keys and API tokens
  • Credential rotation
  • Backup and restore handling
  • Verifying the origin of a request before acting on it in production, including requests that appear to come from a customer contact
  • Change discipline in a live environment

Timing

Core security awareness and customer data handling are completed within the first five working days of joining. Access to a customer environment is not provisioned until they are complete.

Privileged access training is completed before administrative access is granted, not after.

All modules are repeated annually.

Additional targeted training is delivered after a security incident, after a role change that raises the access tier, on a material policy or tooling change, on a finding from an audit or customer assessment, and where a customer contract requires training specific to their account.

Completion and consequence

Completion is recorded against the individual with the module, date and outcome. Where a module includes an assessment, the pass mark is recorded, and a failed assessment is retaken before access is granted or retained.

Training that falls overdue is escalated to the project lead and the director. Where annual training is more than thirty days overdue, administrative access to customer environments is suspended until it is completed. This is the control that makes the record meaningful, and it is applied rather than waived.

Records

Training records are maintained centrally and cover the participant, role and team, module, delivery date, completion status, assessment outcome where applicable, and the closure of any overdue item.

Records are retained for the duration of the engagement and for the period required by applicable law and customer contract.

Evidence provided to customers

On request we provide a training summary for the personnel assigned to a customer account, covering the modules completed, completion dates and current status. Individual assessment scores and personal data are not disclosed.

The following are maintained and available for audit, subject to redaction:

  • Training material and module content
  • Completion report per individual
  • Signed policy acknowledgements
  • Assessment outcomes where applicable
  • Overdue escalation and access suspension records
  • Targeted training delivered after incidents, audits or policy changes
  • HR Security Policy
  • Acceptable Use Policy
  • Background Verification Process
  • NDA / Confidentiality Agreement Structure
  • Vendor / Subprocessor Management Policy

Need training evidence for your vendor file?

If your security or procurement team requires a training summary for the personnel assigned to your account or evidence against a specific control, our team can respond directly.

Need help with your workflow setup?

If you're stuck or want help applying these guides to your setup, our team can assist with configuration, customization, and workflow implementation.