HLD Group
Security awareness & training policy
Mandatory security training and phishing simulations.
Last updated: 24 July 2026
Version 1.0 · Review cycle: 365 days · View all frameworks
1. Purpose
This policy defines HLD Group’s security awareness and training programme. People are both the first line of defence and a common point of failure; sustained awareness and role-specific training materially reduce security risk.
2. Scope
This policy applies to all personnel and, where relevant, contractors with access to HLD Group systems or data.
3. Core awareness programme
- Security awareness training at induction and at least annually thereafter
- Coverage of phishing and social engineering, password and authentication hygiene, data handling and classification, safe use of devices and email, and incident reporting
- Regular awareness communications and updates on emerging threats
- Simulated phishing exercises with supportive follow-up rather than punitive handling
4. Role-specific training
- Developers — secure coding and the secure development lifecycle
- Administrators and privileged users — safe handling of privileged access
- People handling personal data — privacy obligations and data subject rights
- People handling regulated data — HIPAA, CUI, or sector-specific requirements as relevant
- Managers — recognising and responding to security and speak-up concerns
5. Tracking and effectiveness
Completion of required training is tracked, and outstanding training is followed up. The effectiveness of the programme is assessed through phishing simulation results, incident trends, and feedback, and the programme is adjusted accordingly.
6. Framework alignment
- ISO/IEC 27001:2022 Annex A control 6.3 (information security awareness, education and training)
- NIST SP 800-53 Rev. 5 control family AT (Awareness and Training)
- NIST SP 800-50 (building an awareness and training program)
- SOC 2 Trust Services Criteria CC1.4 and CC2.2
7. Roles, exceptions, and review
The security function, with People and Culture, owns the programme under the CISO. Exceptions require documented approval. This policy is reviewed at least annually.
Related frameworks
For contractual attestations or audit packs, contact [email protected].