security-awareness-training

Designs phishing simulations, role-based security training, and behavior-change programs for organizations.

1|Updated Jul 17, 2026
One-click install
npx skills add https://github.com/anonymous99-Rise/multi-CyberSecurity --skill security-awareness-training-anonymous99-rise
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-awareness-training
Source: https://github.com/anonymous99-Rise/multi-CyberSecurity/tree/main/Skills20260809/security-awareness-training
Command: npx skills add https://github.com/anonymous99-Rise/multi-CyberSecurity --skill security-awareness-training-anonymous99-rise

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve? Human error drives the majority of breaches, yet annual e-learning rarely changes employee behavior. This Skill helps security teams build a complete behavior security engineering program: AI-era threat training, authorized phishing simulations, role-based curricula, and quantified effectiveness measurement. ## Core Features & Use Cases - Phishing Simulation Design: Plan GoPhish/King Phisher campaigns and authorized AiTM (Evilginx2) full-chain MFA simulations with compliance, ethics, and data-protection guardrails. - AI-Era Threat Training: Cover deepfake voice/video vishing, AI-generated spear phishing, quishing, ClickFix, prompt injection, and multi-channel combined attacks with updated red-flag criteria. - Role-Based Training & Measurement: Deliver tailored curricula for executives, finance, HR, developers, and general staff, then measure results with the Kirkpatrick four-level model, phish-prone rate baselines, and HAIS-Q/SeBIS behavior surveys. - Use Case: A CISO needs to cut the company's 33% phishing click rate. Use this Skill to design a quarterly simulation calendar, role-specific training, instant point-of-error education, and a board-ready report showing click-rate and report-rate trends. ## Quick Start Ask the AI to design a quarterly phishing simulation and role-based security awareness training plan for your organization, including baseline metrics and Kirkpatrick evaluation.

Frequently Asked Questions about security-awareness-training

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I design a phishing simulation campaign for my company?

Plan in four phases: define goals and metrics, build realistic scenarios in GoPhish or King Phisher, send in batches during business hours, then deliver instant education to clickers within 30 minutes. Obtain written approval from management, HR, and legal before launching.

What is a good phish-prone rate benchmark for security awareness?

The global baseline is about 33.1% per KnowBe4 2025 data, with healthcare highest at 41.9%. Organizations running 12 months of continuous training and simulation typically reduce it to around 4.1%, with mature programs targeting under 5%.

Can Evilginx2 be used for phishing awareness training?

Yes, but only in authorized sandboxed drills. Evilginx2 acts as an adversary-in-the-middle proxy that relays real login flows and captures session cookies, demonstrating how MFA can be bypassed. It requires written authorization, isolated domains, and immediate teardown after the exercise.

How do I measure whether security awareness training actually works?

Use the Kirkpatrick four-level model: reaction surveys, knowledge tests, behavior metrics like click rate and report rate, and organizational outcomes like reduced incident costs. Knowledge gains alone do not equal behavior change, so behavior-level measurement is essential.

How should employees detect deepfake voice phishing calls?

Train procedural defenses rather than audio forensics: call back on an official verified number, use pre-agreed code words, require dual approval for transfers, and enforce cooling-off periods for sensitive requests. Urgency and unusual channels are the strongest red flags.

What are the legal risks of running phishing simulations on employees?

Simulations require written authorization defining scope, time windows, and exemptions. Never collect real credential plaintext, never shame or punish clickers, handle drill data under personal information protection laws, and take phishing domains offline immediately after the exercise.