By company type

How do you market security awareness training?

Awareness training is one of the few security purchases where most buyers are not security people. This page covers who decides, the standards that make training a requirement, how to prove it changes behaviour rather than just counting clicks, and which channels reach the people who buy it.

By the ShoutEx Team · Updated October 2026 · Facts checked October 7, 2026
Training buyers want two things: evidence for the auditor and fewer incidents caused by people. Market both.Marketing for Cybersecurity Companies · Updated October 2026
12 months
PCI DSS v4.x requires the awareness program to be reviewed at least every 12 months
4 phases
In NIST SP 800-50 Rev. 1's model for a cybersecurity and privacy learning program
3.6
Cyber Centre baseline control number for providing employee awareness training

How do you market security awareness training?

How do you market security awareness training?

Market to a mixed committee. HR or learning teams care about employee experience and time away from work; compliance cares about evidence for auditors; IT and security care about reported phishing and fewer incidents. Show how the product meets named requirements, how it fits into existing learning systems, and what changes in behaviour you can measure.

This differs from most security marketing. The buyer may have no technical background, the users are every employee in the company, and the product competes with other training for time on the calendar. Clear, friendly material often outperforms technical depth here.

Who buys security awareness training?

In smaller organizations, the IT manager often buys and runs training. In larger ones, the decision spreads across several teams, each with a different worry.

Example · buying committee map
Who decides on awareness training
1HR or learning and development
Worries aboutEmployee time, tone, accessibility and language options
Needs from youCourse lengths, sample lessons, LMS integration, French content
2Compliance or risk
Worries aboutEvidence for PCI DSS, ISO or insurer reviews
Needs from youCompletion reports, policy acknowledgement records, mapping to controls
3IT manager
Worries aboutSetup effort, user sync, email delivery of simulations
Needs from youDirectory sync guide, allowlisting steps, admin time per month
4Security lead
Worries aboutWhether people report suspicious messages
Needs from youReport-rate trends, simulation realism, integration with the reporting button
5Finance
Worries aboutCost per employee and contract length
Needs from youClear per-user pricing and what is included
Committee map: five roles common in mid-sized organizations. Titles and influence vary; in a 40-person company one person may hold every seat.

Which standards make awareness training a requirement?

Several, and naming them precisely is one of the most useful things your content can do. The PCI Security Standards Council's summary of changes for PCI DSS v4.0 lists requirement 12.6.2, reviewing the awareness program at least every 12 months; 12.6.3.1, training that includes phishing and related attacks and social engineering; and 12.6.3.2, training on acceptable use of end-user technologies. These were best practices until March 31, 2025 and are now required.

For small and medium organizations in Canada, the Cyber Centre's baseline cyber security controls include control 3.6, "Provide Employee Awareness Training", among 13 baseline controls. ISO/IEC 27001:2022 includes Annex A control 6.3, "Information security awareness, education and training". NIST's SP 800-50 Rev. 1 (September 2024) describes a learning program in four phases: plan and strategy; analysis and design; development and implementation; and assessment and improvement.

Build one page per requirement, showing which lessons, simulations and reports support it. Compliance firms often recommend training vendors to their clients, so material written for them is also partner content; see compliance and vCISO firms.

How do you prove training works beyond click rates?

A falling click rate on simulated phishing is easy to show and easy to game: make the simulations easier and the number drops. NIST SP 800-50 Rev. 1 says the program "should encourage behavior change as part of risk management". Buyers who have been through a few renewals know the difference and ask for more.

  • Report rate: the share of staff who report a simulated or real suspicious message, and how fast.
  • Repeat clickers: whether the same people keep clicking after targeted follow-up.
  • Real reports: suspicious messages reported by staff that turned out to be real attacks.
  • Completion by department: where training is not reaching people.
  • Simulation difficulty: shown next to results, so improvements are honest.
ShoutEx rule

Sell to the person who answers to the auditor.

The security team may like your content, but compliance and HR often own the budget and the renewal. Give them the reports they need.

What should an awareness training product page show?

Lead with the outcome and the requirement, show a lesson, and make a trial easy.

Example · awareness training landing page
lanternfish.example/security-awareness
Lanternfish SecuritySee a sample lesson
Security awareness training your staff will finish

Short lessons in English and French, realistic phishing simulations and reports mapped to PCI DSS 12.6 and the Cyber Centre baseline controls.

  • Lessons of 5 minutes or less, with captions and screen-reader support
  • Simulations matched to the staff member's role
  • Report-rate and repeat-clicker trends by department
  • Syncs users from Microsoft Entra ID or Google Workspace
Content reviewed by a learning designerHosted in Canada
Start a 14-day trial
Work email
Organization
Number of employees
Main requirement (PCI DSS, ISO, insurer, other)
Start the trial
Trial includes 3 lessons and 1 simulation for up to 25 users. No card needed.
Proof
Requirement mappingWhich lessons and reports support each control
Sample admin reportWhat compliance and leadership receive each month
Questions
Can we use our own LMS?
Do simulations need allowlisting?
Is pricing per employee?
Training product page: the hero names the requirement buyers must meet, the points speak to HR, IT and compliance, and the trial is small enough to start in a day. Lanternfish Security is fictional. Illustrative example written by ShoutEx for this guide, not a benchmark.

Which channels reach awareness training buyers?

ShoutEx view: three channels do most of the work. MSPs and MSSPs resell training to many small clients and want multi-tenant administration and partner pricing. Search catches buyers looking for a named requirement, such as "PCI DSS 12.6 training". A short, self-serve trial lets IT managers try the admin experience before involving HR; free trials and PLG covers how to design one.

LinkedIn and email work best when aimed at HR and compliance with practical material, such as an annual training plan template. Messaging that speaks only to security teams misses most of the committee. Training sits beside other software categories, and the general guidance for security product vendors still applies to integrations and procurement.

What should an awareness training company measure?

Measure what predicts purchase and renewal, and connect product data to the CRM.

Awareness training metricsFictional Lanternfish Security, one quarter
MetricExample valueWhat it shows
Trials started140Reach and offer appeal
Trials that sync users88IT engagement
Trials that send a simulation61Activation
Paid conversions19Fit and pricing
Share of revenue through MSP partners40%Channel dependence
Customers whose report rate rose year over yearTracked at renewalProof of behaviour change
Illustrative example written by ShoutEx for this guide, not a benchmark.

Frequently asked questions

Who usually buys security awareness training?

In small organizations, the IT manager. In larger ones, HR or learning, compliance, IT and security share the decision, with finance approving the cost.

Does PCI DSS require security awareness training?

Yes. PCI DSS v4.x requirement 12.6 covers an awareness program reviewed at least every 12 months, with training on phishing, social engineering and acceptable use. Several items became required after March 31, 2025.

Is awareness training part of the Cyber Centre baseline controls?

Yes. Control 3.6, Provide Employee Awareness Training, is one of the 13 baseline controls for small and medium organizations.

Which ISO 27001 control covers training?

Annex A control 6.3 in ISO/IEC 27001:2022, Information security awareness, education and training.

Are phishing click rates a good success measure?

Only alongside report rates, repeat clickers and simulation difficulty. Click rates alone can be lowered by making simulations easier.

Should awareness training offer a free trial?

Usually yes, small and quick to start, so an IT manager can test user sync and a simulation before involving the wider committee.

Do we need French content to sell in Canada?

For many Quebec organizations and federal bodies, yes. Even elsewhere, bilingual lessons broaden your market and are worth stating clearly.

Sources & further reading

Regulations, platform policies and market data change. These sources let you check the facts on this page, last checked October 7, 2026.