Security Awareness Training Evidence Structure
Purpose
This document sets out the security training every person at Hybrowlabs receives, when they receive it, and the evidence we retain.
Most security failures in an ERP implementation are not technical. They come from a screenshot pasted into a public ticket, a database export left in a downloads folder, a customer credential shared over chat, or an administrator acting on a request that was not what it appeared to be. Training is aimed at those situations rather than at generic security theory.
Audience
Everyone who performs work for Hybrowlabs completes training, including contractors, interns and subcontracted personnel. Training is a condition of holding access, not an optional development activity.
Curriculum
Training is delivered in three modules. The module assigned depends on the access the role holds.
| Module | Who receives it | Cadence |
|---|---|---|
| Core security awareness | Everyone | Onboarding, then annually |
| Customer data handling | Consultants, developers, support and account teams | Onboarding, then annually |
| Privileged access | Anyone holding administrative access to a customer environment | Before access is granted, then annually |
Core security awareness
- Phishing and business email compromise, including invoice and payment change requests
- Social engineering attempted by phone or messaging rather than email
- Credential handling and the approved password manager
- Multi-factor authentication
- Device controls: disk encryption, automatic screen lock, current patching
- Physical security and clear desk
- Recognising an incident and reporting it immediately rather than resolving it privately
- The prohibitions set out in the Acceptable Use Policy
Customer data handling
- Data classification and what counts as customer data
- Exports, backups, screenshots, log files and support attachments, which routinely contain live records
- Production data in development and demonstration environments, and when masking is required
- Approved channels for file transfer and customer communication
- Restrictions on public AI tools, code assistants and file converters
- What may not be posted in community forums, public issue trackers and public repositories
- Personal data obligations and customer-specific restrictions
Privileged access
- Administrator and System Manager roles, and why they are not the default working role
- Permission and role changes, and their effect on existing users
- Server and bench access, SSH keys and API tokens
- Credential rotation
- Backup and restore handling
- Verifying the origin of a request before acting on it in production, including requests that appear to come from a customer contact
- Change discipline in a live environment
Timing
Core security awareness and customer data handling are completed within the first five working days of joining. Access to a customer environment is not provisioned until they are complete.
Privileged access training is completed before administrative access is granted, not after.
All modules are repeated annually.
Additional targeted training is delivered after a security incident, after a role change that raises the access tier, on a material policy or tooling change, on a finding from an audit or customer assessment, and where a customer contract requires training specific to their account.
Completion and consequence
Completion is recorded against the individual with the module, date and outcome. Where a module includes an assessment, the pass mark is recorded, and a failed assessment is retaken before access is granted or retained.
Training that falls overdue is escalated to the project lead and the director. Where annual training is more than thirty days overdue, administrative access to customer environments is suspended until it is completed. This is the control that makes the record meaningful, and it is applied rather than waived.
Records
Training records are maintained centrally and cover the participant, role and team, module, delivery date, completion status, assessment outcome where applicable, and the closure of any overdue item.
Records are retained for the duration of the engagement and for the period required by applicable law and customer contract.
Evidence provided to customers
On request we provide a training summary for the personnel assigned to a customer account, covering the modules completed, completion dates and current status. Individual assessment scores and personal data are not disclosed.
The following are maintained and available for audit, subject to redaction:
- Training material and module content
- Completion report per individual
- Signed policy acknowledgements
- Assessment outcomes where applicable
- Overdue escalation and access suspension records
- Targeted training delivered after incidents, audits or policy changes
Related documents
- HR Security Policy
- Acceptable Use Policy
- Background Verification Process
- NDA / Confidentiality Agreement Structure
- Vendor / Subprocessor Management Policy
Need training evidence for your vendor file?
If your security or procurement team requires a training summary for the personnel assigned to your account or evidence against a specific control, our team can respond directly.