# Policy-to-Training Security Refresher Mini-Course

A free, reviewable cybersecurity awareness course package for teams that need to turn security policy language into practical training people can use.

Use this starter in Content Studio, adapt it to your approved policy, review it with the right stakeholders, then export or publish through your normal training workflow.

## Course overview

**Working title:** From Policy to Practice: Everyday Security Decisions

**Audience:** Employees, managers, new hires, MSP clients, or role-specific teams that need a practical refresher based on approved security policy.

**Estimated seat time:** 7-10 minutes

**Format:** Lesson, three workplace scenarios, five-question knowledge check, remediation note, LMS packaging notes, and Content Studio adaptation prompt.

**Learning objective:** Given a common work situation involving company systems, data, messages, or AI tools, the learner can identify when to pause, check the approved policy or system, and use the correct reporting or help path.

**Review boundary:** This is a starter asset, not legal advice or a compliance guarantee. Adapt it to approved policies, systems, reporting channels, customer commitments, contracts, and regulated-data requirements before publishing.

## Lesson copy

Security policies can look like rules written for auditors, lawyers, or systems administrators. But the point of a good security policy is practical: it helps people make safer decisions during normal work.

Most risky moments do not announce themselves as cybersecurity events. They show up as ordinary tasks:

- A file needs to be shared quickly.
- A vendor asks for updated payment details.
- A customer document includes sensitive information.
- A teammate wants to paste a transcript into an AI tool.
- A login prompt appears after clicking a link.
- A manager asks whether a shortcut is acceptable because the deadline is today.

The training decision is simple, but important: before acting on a request that involves systems, credentials, money, customer information, employee information, confidential business information, or approved tools, pause and check the expected workflow.

That does not mean stopping work every five minutes. It means knowing which decisions deserve a second look.

Use this three-step habit:

1. **Name what is at stake.** Is this about access, money, data, identity, customer information, employee information, confidential business information, or an approved tool?
2. **Check the trusted source.** Use the approved policy, help center, manager guidance, ticketing process, or security channel. Do not rely on an email thread, chat message, or AI answer as the authority for company rules.
3. **Use the approved path.** Share files through the approved system, verify payment changes through the approved process, report suspicious messages through the approved channel, and ask before using unapproved tools for sensitive work.

A policy is only useful if people can apply it when work gets messy. The goal is not to memorize every sentence. The goal is to recognize the moment when the policy matters.

## Scenario 1: The fast file share

You are preparing for a customer call. A teammate asks you to upload a document to a personal file-sharing account because the approved workspace is being slow. The document includes customer names and project details.

**Safer action:** Use the approved sharing system or ask the owner/security/help desk for the approved workaround. Do not move customer or confidential information into an unapproved tool just because it is faster.

**Teaching point:** Convenience is not approval. If a file includes customer, employee, financial, contract, CUI, confidential, or regulated information, the storage and sharing path matters.

## Scenario 2: The AI shortcut

You are asked to summarize a long document. An AI tool could help, but the document includes internal planning details and customer information.

**Safer action:** Check whether the AI tool and the data type are approved for that use. If the policy is unclear, ask through the approved help channel before pasting content into the tool.

**Teaching point:** AI can be useful, but the prompt box is not automatically a safe place for work data. The approved tool, data category, and use case all matter.

## Scenario 3: The urgent process change

A vendor emails a new payment instruction and says the change must be completed today. The message appears to come from someone you know.

**Safer action:** Follow the approved vendor-change verification process, such as using a trusted phone number or internal workflow. Do not rely only on the email thread.

**Teaching point:** Urgency is a common pressure tactic. The policy exists to protect both the organization and the employee from being pushed into a risky shortcut.

## Knowledge check

### Question 1

A policy says customer files must be stored in approved systems. A teammate asks you to upload a customer file to a personal sharing account because it is faster. What should you do?

A. Upload it because the request came from a teammate.

B. Use the approved sharing system or ask for an approved workaround.

C. Remove the file name and upload it anywhere.

D. Email the file to your personal account first.

**Correct answer:** B

**Feedback:** The approved system matters when customer or confidential information is involved. If the normal workflow is blocked, ask for the approved workaround instead of inventing one.

### Question 2

Which source should be treated as the authority for whether a tool can be used with sensitive work data?

A. A public AI answer.

B. A coworker’s guess.

C. The approved policy, approved tool list, or designated help channel.

D. The fastest option available.

**Correct answer:** C

**Feedback:** AI and coworkers can help explain, but they are not the authority for company policy. Use the approved source and ask when unclear.

### Question 3

Why should payment-change requests be verified through an approved process?

A. Because every vendor email is fake.

B. Because urgent or familiar-looking messages can still be fraudulent or mistaken.

C. Because finance teams should never use email.

D. Because policies prevent every bad outcome.

**Correct answer:** B

**Feedback:** Verification reduces avoidable risk, but it does not guarantee outcomes. The point is to use the workflow designed for higher-risk decisions.

### Question 4

What is the best way to think about security policy in daily work?

A. A document to memorize once a year.

B. A practical guide for decisions involving access, data, money, identity, tools, and reporting.

C. Something only security teams need to understand.

D. A replacement for judgment.

**Correct answer:** B

**Feedback:** The goal is not memorization. The goal is recognizing when the policy applies and knowing where to check.

### Question 5

If the policy does not clearly answer your question, what should you do?

A. Make your best guess and move on.

B. Ask an AI tool to decide.

C. Use the approved help, manager, compliance, or security channel.

D. Copy the last person who handled a similar request.

**Correct answer:** C

**Feedback:** Uncertainty is exactly when the approved help path matters. Asking early is usually faster than cleaning up an avoidable mistake later.

## Remediation note

If this course is used after a simulation, audit finding, policy rollout, or real support pattern, keep the follow-up respectful and specific:

> This refresher focuses on the decision point we want everyone to practice: when a request involves data, money, access, identity, approved tools, or reporting, pause and use the approved workflow. The goal is not to blame people for needing help. The goal is to make the safer next step easier to recognize.

## LMS packaging notes

Recommended structure:

1. Lesson page: “Why policy matters during real work”
2. Scenario page: “Fast file share”
3. Scenario page: “AI shortcut”
4. Scenario page: “Urgent process change”
5. Knowledge check: five questions with teaching feedback
6. Final takeaway: “Pause, check the trusted source, use the approved path”

Recommended metadata:

- **Course type:** Security awareness refresher
- **Estimated duration:** 7-10 minutes
- **Suggested audience:** All employees, new hires, managers, MSP clients, or selected role groups
- **Reviewers:** Security, GRC/compliance when policy-sensitive, L&D, business owner, legal/privacy as needed
- **Exports:** SCORM, xAPI, HTML, or PDF depending on the delivery environment

## Content Studio adaptation prompt

Copy this into Content Studio and replace the bracketed fields before generating your version.

```text
Create a reviewable cybersecurity awareness micro-course called “From Policy to Practice: Everyday Security Decisions.”

Audience: [employee group, role, client type, or department]
Policy source: [approved policy name, section, or summary]
Approved systems/tools: [approved file sharing, AI tools, reporting channels, ticketing/help process]
Sensitive data categories to mention: [customer data, employee data, confidential business information, CUI/FCI/CDI if applicable, regulated data if applicable]
Primary learner decision: Before acting on a request involving systems, credentials, money, customer information, employee information, confidential information, AI tools, or reporting, the learner should pause, check the trusted source, and use the approved path.
Tone: Friendly professor, practical, non-shaming, clear.
Length: 7-10 minutes.
Include:
- A plain-language lesson
- Three workplace scenarios customized to the audience
- Five quiz questions with teaching feedback
- A respectful remediation note
- Captions/transcript guidance if video or voiceover is created
- LMS packaging notes for SCORM/xAPI/HTML/PDF export
- Review notes for security, GRC/compliance, L&D, and legal/privacy when needed

Do not claim the course makes the organization compliant, prevents breaches, guarantees behavior change, or replaces human review.
```

## Human review checklist

Before publishing, confirm:

- The course names only approved tools, systems, reporting paths, and policy sources.
- Sensitive data examples match the organization’s definitions.
- Regulated, contractual, CUI, CDI, FCI, export-control, privacy, or employee-data references have the right reviewer.
- Quiz feedback teaches the safer decision without shaming the learner.
- The LMS export, captions, transcripts, and accessibility checks match the delivery requirement.
- The final copy avoids compliance guarantees, breach-prevention guarantees, and surveillance framing.
