Security awareness with a defensible record
Security training that survives inspection.
Continuous security awareness for any organization that has to prove its people were trained. Twelve core modules, monthly reinforcement, and a training record built to be inspected — so when an auditor, an assessor or a customer says show me your evidence, it takes ninety seconds, not two weeks.
Regulated? Add the pack your framework names: 21 CFR Part 11 · HIPAA · GLBA · PCI DSS · NIST 800-171 · ISO 27001
- Person
- M. Okafor · Accounts Payable Specialist
- Module
- A.1 — Phishing, Spear Phishing & Social Engineering
- Version
- 2.4.0 (effective 2026-06-01)
- Completed
- 2026-08-14 09:41:07 CDT
- Assessment
- 94% · threshold 80% · 1 attempt
- Signature
- Electronic · meaning: completed and understood
- Record ID
- TS-8841-A1-0714
Illustrative export. Every completion produces one of these.
The problem
The annual video is not a program.
Most security awareness training exists to be completed, not to change behavior. Once a year, everybody clicks through forty minutes of stock footage, and the organization goes eleven months without another word about it — while the phishing gets better every quarter.
Then someone asks for proof. A customer security questionnaire, a SOC 2 auditor, a HIPAA risk analysis, a cyber-insurance renewal, an FDA inspector. Every one of them wants the same thing: who was trained, on what, when, and can you show it. A completion checkbox in a generic LMS is not an answer.
Annual compliance video
- One 40-minute sitting, once a year
- Same content for the engineer, the receptionist and the CFO
- Generic curriculum with a compliance module bolted on
- Nothing about the provision your assessor actually cites
- Evidence is a spreadsheet export someone reformats under pressure
- Content ages for twelve months while threats don't
Trained State
- Annual course establishes the baseline, assessed and signed
- Monthly units of three to five minutes keep it current
- Role variants so people learn what applies to their job
- Add-on packs cover the regulation your framework names, by section
- Inspection packet exports attributable, timestamped records on demand
- Event-driven units ship within 48 hours of a real incident
What you get
Three things, one program.
A core curriculum everyone completes, packs for the regulation your sector is held to, and a record that proves both. Each has its own page.
01
Core curriculum
Twelve modules in four tracks: the security awareness canon, written for busy professionals, with monthly reinforcement so it stays current.
The curriculum →02
Add-on packs
Modules for the regulation your assessor actually cites, by section. Clinical & GxP now; seven more built with design partners.
The packs →03
The record
Every completion writes an attributable, timestamped, version-pinned record. Export the inspection packet in ninety seconds, unassisted.
The record →Who it's for
Anyone who gets asked for proof.
Companies proving it to customers
Security and compliance leads answering questionnaires and SOC 2 or ISO 27001 auditors, who need training evidence that does not have to be assembled by hand.
Healthcare & covered entities
Providers, plans and business associates whose risk analysis and workforce training are the first two things a HIPAA reviewer asks about.
Clinical research
Sites, CROs, sponsors and trial vendors who get audited by sponsors and inspected by regulators. There is a page for you.
Finance, payments & government contractors
Organizations whose regulator or contract names a training requirement by section, and whose assessor will check for it.
Pilot program
Start with the core. Add the pack.
We're onboarding a small number of design partners. Clinical research organizations get the Clinical & GxP pack now; if your sector's pack is on the roadmap, a design partner is how it gets built. You get the program first, we get your audit findings and your people's honest opinion of the content. Fair trade.
Developed with a clinical research design partner · STACSTRAT LLC