Guides

Free phishing awareness training resources for small teams

Free phishing guidance from CISA, the FTC, NIST and the UK NCSC, and how to turn a month of awareness work into training evidence an auditor will accept.

Most phishing advice is free, and most of it is good. The trouble is that a small company reads it, forwards a link to the team in October, and has nothing to show for it when an auditor asks in March how staff are trained to recognize social engineering.

This post covers both halves: the free material worth using, and how to keep a record of it.

The free material

CISA, NSA, FBI and MS-ISAC, "Phishing Guidance: Stopping the Attack Cycle at Phase One." A joint guide that splits phishing into the two things attackers usually want, credentials and malware, and lists the defenses for each. It is written for the people who run the network, so hand it to whoever manages your email and identity provider.

CISA's phishing-resistant MFA fact sheet. Text-message codes and push approvals can be phished or fatigued. This sheet explains which methods resist that (FIDO2 security keys and passkeys) and how to roll them out. If one change this month would cut your phishing risk the most, it is probably this one.

The FTC's "How to Recognize and Avoid Phishing Scams." Plain-language consumer advice that also works as a staff handout. It covers the tells, what to do if you clicked, and where to report.

The UK NCSC's phishing guidance. It argues for layered defenses over relying on users alone, which is the right frame for anyone who has watched a careful colleague click on a good lure.

Google's phishing quiz. A short, free quiz that shows real-looking emails and asks which are fake. It works well as a five-minute team exercise.

NIST's Phish Scale (Technical Note 2276). If you do run your own phishing exercises, this gives you a way to rate how hard each lure was, so a low click rate on an easy email is not mistaken for a trained team.

NIST SP 800-50 Rev. 1, "Building a Cybersecurity and Privacy Learning Program." The long-form reference for anyone designing an awareness program rather than a one-off session.

Where to report a phish you received: forward it to your IT contact first, then use the FTC at reportfraud.ftc.gov, or the FBI's IC3 at ic3.gov if money or data was lost.

What the frameworks ask for

Each of these expects awareness training, and CIS and PCI DSS name phishing outright:

  • ISO 27001 Annex A.6.3, information security awareness, education and training
  • CIS Controls Safeguard 14.2, training the workforce to recognize social engineering
  • PCI DSS Requirement 12.6, security awareness, including phishing
  • HIPAA §164.308(a)(5), the security awareness and training standard
  • SOC 2 auditors ask for training records as part of how you communicate security responsibilities internally

None of them is satisfied by a link in a Slack channel. They want to see who was trained, on what, and when.

Turning October into evidence

The cheapest way to make this month count is to keep the record as you go:

  1. Pick the material. The free sources above, a course, or both.
  2. Assign it to named people with a due date, so "the team" becomes a list you can check.
  3. Keep completion records and certificates somewhere an auditor can see them, dated.
  4. Write down that you did it in your acceptable use or information security policy, so the training ties back to a control you already claim.

Keel does this part. Security awareness training is on every plan, including Free, and the Free courses include Phishing & Social Engineering, Security Awareness Fundamentals, and Acceptable Use & Insider Risk. You assign a course, Keel tracks completion, and each certificate is saved to your evidence library, labelled with the controls the course maps to.

See how training works in Keel, or start free.

Next week: free baselines for hardening laptops, phones and servers.

This article is general information, not legal or audit advice. Framework names (SOC 2, ISO 27001, PCI DSS, etc.) are referenced factually; Keel is not affiliated with or endorsed by their owners.

Put this into practice with Keel

Keel gives growing teams a self-serve path to SOC 2, ISO 27001, and more, controls, evidence, policies, access reviews, and a trust center on one graph.