Security awareness training is the control most often required and least often evidenced. Insurers ask for it, customer security questionnaires ask for it, and PCI DSS requires it outright for anyone who touches cardholder data, but organizations frequently cannot produce a dated record showing who completed what.
These courses cover the awareness obligation and produce exactly that record. Each certificate carries a unique ID that a customer, auditor or insurer can verify without contacting us.
Courses in Cybersecurity & Data Compliance
Common questions
Is security awareness training required by PCI DSS?
PCI DSS requires personnel to be aware of the cardholder data security policy and procedures, with training on joining and at least annually thereafter. Organizations in scope have to be able to show who was trained and when, which is where an undocumented program fails an assessment.
Who needs PCI training rather than general security awareness?
Anyone whose role involves handling cardholder data or who can affect the security of the cardholder data environment. That usually reaches beyond the payments team into support, sales and technical staff who can see or touch card data in the course of their work.
Will this satisfy our cyber insurance requirement?
Insurers generally ask for evidence that staff receive regular security awareness training, and a dated verifiable certificate per employee is the evidence they are asking for. Confirm the specific wording of your own policy, since some insurers also require phishing simulation or a named frequency.