Security awareness training

Service Definition • Armstrong Bell • 8 August 2026

Document summary

This document sets out what's included in our security awareness training solution. Phish testing is covered in a separate service definition, and the two services are designed to operate together.

Core service provision

Our security awareness training service is designed to educate users on the threats that cyber attacks pose to an organisation. Training is delivered monthly rather than as a single annual exercise, so that awareness is maintained as threats evolve. The service provides the following feature set:

  • Enrolment into monthly cyber security training for staff

  • Training content covering current and evolving threats, delivered as short modules

  • Automated enrolment of users identified as susceptible during phishing testing into targeted awareness training

  • Tracking of module completion and outstanding assignments

  • Reporting to identify trends, high-risk groups, and areas for improvement

The solution is fully managed by our team, from enrolment through to completion reporting.

Service desk support

Customers can raise queries directly with our dedicated support team for assistance. Typical requests include:

  • Adjusting training schedules or user groups

  • Clarifying reporting insights and recommendations

  • Resolving issues with enrolment, module delivery or completion tracking

Service coverage is provided in line with the customer's existing Managed IT Service support contract.

Alert management

Our team receive alerts for a variety of events relating to the platform, including:

  • Planned maintenance

  • Degraded service due to issues arising

  • Critical incidents or major outages

When one of these is received, it is initially reviewed for impact, and if appropriate, communications will be sent to customers.

Available reporting

The following reports are available through the platform, providing actionable insights into security awareness levels across the organisation:

  • Training completion and outstanding assignment reports

  • High-risk users

Vendor escalation

Our team collaborates with our preferred partner for the platform, escalating complex incidents or platform-specific issues as needed. All initial analysis and troubleshooting are conducted internally, with vendor escalation fully managed by our team. This process incurs no additional cost to the customer.

Addition of new features

Where a new feature is introduced to the platform that would benefit a customer, the required changes are reviewed by our team to ensure they are suitable for implementation. If the change requires disruption to service, or an adjustment to core components that may alter existing functionality, this will be communicated to the customer and a route forward agreed.

For any additional functionality requiring considerable work and/or integration, these items will be scoped and discussed independently with the customer.

On-boarding

  • Initial consultation and requirements assessment

    • Review organisational goals and compliance requirements relating to training

  • Training setup

    • Configure integration with Microsoft 365 tenant

    • Enrol organisation in to training platform

    • Set auto-follow up for training that is outstanding for users

    • Configure automatic enrolment of users identified as susceptible during phishing testing

  • Execution and monitoring

    • Release scheduled training to enrolled users

    • Receive data on completion rates

  • Reporting and improvement

    • Embed key metrics within our Customer Service Reporting (CSR)

    • Provide ad-hoc reporting if further detail is required