The program document
Audiences, topics, delivery methods, timeline and periodicity, each tied to its requirement. Your information security function signs and owns it (IRDAI item 13).
Employee security awareness training in India
Auditors ask who owns the program, which content version ran, who acknowledged the policy and what happens when someone doesn't finish. We write that program and deliver targeted staff training.
Course versus program
IRDAI, India's insurance regulator, publishes the auditor's report form with its guidelines. Its Awareness and Training block is ten yes-or-no questions, and not one asks how many people finished.
NIST, the US standards body, agrees in SP 800-50r1, Building a Cybersecurity and Privacy Learning Program (September 2024). Staff may think the program is "the annual or regularly scheduled training course" (Section 2.7). NIST splits it into awareness activities, experiential learning and practical exercises, and training, with awareness "on an ongoing basis throughout the year" (Section 2.7.1).
Annual training isn't wrong: PCI DSS, the card-payment security standard, sets an annual floor, and NIST calls annual common practice. But the yearly module is one bullet of one PCI requirement, 12.6.3; the rest of the program still needs building.
What you get
We write the program and deliver targeted staff training. You sign, run and keep it, because the standards put the duty there.
Audiences, topics, delivery methods, timeline and periodicity, each tied to its requirement. Your information security function signs and owns it (IRDAI item 13).
Content mapped to your requirement, plus a register of each version and the incident, audit finding or new threat it absorbed. You sign each version into use.
What is captured per person, where it lives and how it maps to each requirement. You run the system and set the retention period.
Which measure, formula, population, target and evidence, modeled on the securities regulator SEBI's Annexure-K, and which Kirkpatrick level it reaches (the four levels NIST uses: reaction, learning, behavior, results). You run the evaluation and sign the benchmark.
A map from every document to the requirement it answers and the check the assessor is expected to run.
Awareness training for the groups your requirement names, on phishing, social engineering and acceptable use of end-user technologies.
Reinheimer and colleagues (SOUPS 2020) found people spotted phishing better directly after a program and four months later, but not after six, and recommend a reminder after half a year. ENISA's Technical Annex: Evidence Reviews (December 2018) found threat or punishment framing can "boomerang and reduce security behaviour", so our content explains rather than frightens.
One row per rulebook
Find your regulator or contract and read the middle column first: several reach contractors and vendors, some the Board.
| Publisher and document | Who it binds | What it asks of a program |
|---|---|---|
| PCI DSS v4.0.1 SAQ D for Merchants, October 2024 | All personnel | 12.6.1 a formal program. 12.6.2 a yearly review, updated for new threats. 12.6.3 training upon hire and yearly, more than one channel, and a yearly acknowledgement. 12.6.3.1 phishing and social engineering; 12.6.3.2 acceptable use of end-user technologies (12.2.1). |
| SEBI Cybersecurity and Cyber Resilience Framework (CSCRF), Version 1.0, circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113, 20 August 2024, as modified by SEBI's Technical Clarifications circular of 28 August 2025 | All regulated entities (REs), mandatory | PR.AT covers awareness and training. PR.AT.S1: mandatory periodic programs, updated for new threats. The PR.AT guidelines add a focus on non-technical staff and extension, where possible, to outsourced staff. PR.AT.S4: a Board program. |
| IRDAI Information and Cyber Security Guidelines, 2026 (VER 2.0), circular IRDAI/GA&HR/CIR/MISC/51/4/2026, 06th Apr, 2026 | Insurers, including foreign reinsurers' branches (FRBs), and the intermediaries in circular para 5: brokers, corporate agents, web aggregators, TPAs, IMFs, insurance repositories, ISNP, corporate surveyors, MISPs, CSCs and the Insurance Information Bureau of India | Policy 2.4, Section 3.2, items 11, 13 and 14: content, timeline, periodicity, per-person attendance with a catch-up period, and content version history. Audited at Annexure - III controls 167 to 176, plus control 38 (update at least annually). |
| Reserve Bank of India, RBI/DPSS/2024-25/123, 30 July 2024, Master Directions on Cyber Resilience and Digital Payment Security Controls for non-bank Payment System Operators, Section 25 | Non-bank Payment System Operators, from 1 April 2025 (large), 2026 (medium) and 2028 (small) | Periodic training for employees and vendors managing information assets; periodic evaluation of awareness against a benchmark score; Board and key senior management as an audience. |
| Reserve Bank of India, 2026 Directions for commercial banks, RBI/DoS/2026-27/410, 31 July 2026 | Commercial banks | Paragraph 203: awareness programs mandatory for all new recruits, and annual training for lower and middle management. Paragraph 204: annual training for all Board members and Senior Management. |
| UIDAI (the Aadhaar authority), AUA/KUA Undertaking, bound with the Comprehensive compliance checklist for Requesting Entities, control 18(b) | Personnel of AUAs and KUAs (organizations that use Aadhaar authentication or e-KYC), business correspondents, Sub-AUAs, Sub-KUAs and similar entities | Training at induction, half-yearly and when the authentication ecosystem changes; role-specific training; a record of trainings. |
| NIST SP 800-53 Rev. 5, AT-2, AT-4, AT-6 | Users of the catalog, and contracts that name it | AT-2: initial training, then a frequency you define, and again when system changes or defined events require it, with content updates and incident lessons (AT-2c, AT-2d). AT-4: records kept for a period you define. AT-6: results reported to named people at a defined frequency. |
| National Security Council Secretariat (NSCS), Cyber Security Audit Baseline Requirements, NSCS-46-16 Rev 1.0, October 2020 | Mandatory for owners and regulators of Critical Information Infrastructure; all other organizations "strongly encouraged" | Markers pro.14 (periodic role-based training, including associated external entities), pro.15 (appropriate content) and imp.5 (improvement across exercises and trainings). |
Entities in IRDAI's circular para 5 comply from the current financial year. Section 1.4 leaves insurance agents, micro-insurance agents, Point of Sale Persons and individual surveyors outside; insurers bring them under a Board-approved minimum framework.
ENISA's mapping table, published with its Technical Implementation Guidance on cybersecurity risk management measures, links awareness and training to ISO/IEC 27001:2022 clauses 7.2 and 7.3 and Annex A. ENISA calls it advisory, not a measure of equivalency. Which Annex A controls apply is an ISO 27001 scoping question.
UIDAI's checklists count a control as compliant only where compliance is secured "on an ongoing basis", which one training run does not show.
NSCS makes every marker mandatory except a Recommended set. pro.14 and pro.15 are never in it; imp.5 is in it only at Low Risk, so it stays mandatory at High and Medium Risk. That is our reading of its tables, not an NSCS statement.
How we build the program
The clause decides cadence, audience and evidence. Compliance "should only be the starting point" (NIST SP 800-50r1 Section 5.2.2).
All users, privileged account holders and staff with significant security or privacy duties (NIST Section 2.5), plus the third parties, senior executives and Board that SEBI names.
PCI requires it. NIST suggests logon-screen messages, email signatures, newsletters and posters.
Content follows a named threat and policy list, plus incident lessons. Its review runs on its own clock (PCI 12.6.2, IRDAI control 38, NIST AT-2c).
Completion rates and quiz scores are only Kirkpatrick levels 1 and 2. Name the level in writing, so a completion rate is never reported as proof that behavior changed.
IRDAI allows a catch-up time, then treats a miss as non-compliance with the policy. RBI lets non-bank payment operators restrict staff who score below a benchmark from information assets. Both are your decisions.
SEBI PR.AT.S4 and RBI name the Board as an audience. NIST wants results reported to named people (AT-6); SP 800-50r1 Section 5.2 says the report covers metrics, compliance information and whether the training worked.
Scope and limits
We don't host a standing program, sell a subscription or track who completed the training. Your team does.
We define how awareness is measured, but nobody can honestly promise a behavior change.
Nothing we write states that a requirement has been met; the assessor named in your scope decides that. We are not an auditor or certification body.
A bounded engagement. Rehearsing your incident plan is a separate Blue Team exercise; preparing for a real incident is incident response readiness.
See also GRC and compliance, PCI DSS compliance, vCISO services for Board reporting, or all defensive cybersecurity services.
FAQ
Only part of it. Requirement 12.6.3 asks for training upon hire and at least once every 12 months, more than one method of communication, and a yearly acknowledgement that personnel have read and understood the information security policy and procedures. 12.6.2 adds a yearly program review, so one module leaves the second channel, the acknowledgement record and the review open.
No, and PCI says so both ways. The Applicability Note to Requirement 5.4.1, on automated anti-phishing controls, says meeting it does not meet Requirement 12.6.3.1 on awareness training, and the note under 12.6.3.1 calls them separate and distinct requirements.
Your own requirement decides. PCI: upon hire and at least once every 12 months. UIDAI's control 18(b) is the strictest published Indian cadence: at induction, half-yearly, and whenever the authentication ecosystem changes. RBI asks non-bank payment system operators for "periodic repeated training / awareness programs", and NIST calls all-user training "regularly scheduled (often annual but preferably more frequent)".
Mostly documents a course doesn't produce. IRDAI's ten questions (Annexure - III, controls 167 to 176) cover content version history, training for key personnel and leaders, periodic review, policy communication, whether users understand their responsibilities, evaluation of awareness level, a non-completion process, a named owner and participation in cyber security exercises. PCI's Expected Testing for 12.6.3 names program records, personnel interviews, program materials and acknowledgements.
Mostly yes, so decide it at scoping. PCI says all personnel. IRDAI item 11 names "all the employees, contractors and relevant third-party users of Organization systems". SEBI asks for extension "wherever possible ... to outsourced staff, third-party service providers, etc."
No. Rule 6(1) of the Digital Personal Data Protection Rules, 2025 lists seven minimum security safeguards, from encryption, access control and logging to backups, one-year retention of logs and data, a Data Processor clause and appropriate technical and organizational measures. Training isn't one, and the word awareness appears nowhere in the Rules. In India the training duty is sectoral: RBI, SEBI, IRDAI, UIDAI or the NSCS audit baseline.
You do. We write the program documents and deliver targeted staff awareness training. The delivery cycle, per-person tracking, evaluation of awareness and the consequence for non-completion stay with you, because NIST AT-4 and IRDAI item 14 address records, attendance and version history to the organization.
Decide your measurement level before the first session. NIST SP 800-50r1 (Section 5.2.3.3, page 61) gives the four Kirkpatrick levels: Reaction, Learning, Behavior, Results. Completion rates and quiz scores are Levels 1 and 2, and NIST (Section 2.4.1) says measurements "must go beyond simply achieving compliance". SEBI's Cyber Capability Index (Market Infrastructure Institutions and Qualified REs only) states its Security Training Measure with a formula, a 100% target and a 5% weighting, and counts security personnel, not the whole workforce.
Let's talk
Name the requirement, the people it reaches and the assessor who reads the evidence, and we scope against those three. We reply within one working day.