August 15, 2026
Slide Deck Template for Security Awareness Presentations
Annual security awareness training is a compliance requirement for every organization operating under SOC 2 Type II, HIPAA, ISO 27001, PCI DSS, or CMMC. The requirement is not just that training happened — it is that completion was documented, the content covered specific domains, and attestations were captured in a format that survives an audit. Every year, organizations fail audit readiness reviews because their security training was delivered but not properly evidenced, or because the content was too generic to demonstrate that specific risks were addressed.
This guide covers the structure for two distinct security presentations: the all-employee annual security awareness training (the compliance requirement) and the board-level security posture update (the governance requirement). Both are necessary. Neither is optional. And both are regularly done poorly enough that a template based on what actually needs to be covered is worth having.
All-Employee Security Awareness Training
The goal of annual security awareness training is behavioral change, not compliance theater. A training session that employees forget within two weeks has satisfied the documentation requirement and failed the actual objective. The framing, content, and format choices in the deck determine whether your team walks out of the session more vigilant or more resentful.
Module 1: Phishing Recognition
Phishing is the entry point for approximately 90% of corporate security incidents. It is also the area where employee behavior has the most direct impact on risk. This makes it the correct place to start.
The SLAM method — Teach employees a consistent framework for evaluating suspicious messages. SLAM stands for:
- Sender: Does the sender's email address match the claimed identity? An email claiming to be from Microsoft Support but sent from a Gmail address is a phishing attempt. An email from
accounts@microsoft-support-team.cois not from Microsoft, regardless of the display name in the From field. - Links: Before clicking any link, hover over it to see the actual URL destination. The display text "Click here to reset your password" can point to any URL. Train employees to check the destination URL before clicking, and to be suspicious of URLs that use lookalike domains (microsoft vs. rnicrosoft), URL shorteners, or domains that do not match the company claiming to send the email.
- Attachments: Treat unexpected attachments as suspicious regardless of who appears to have sent them. Malicious attachments frequently arrive via compromised accounts that belong to real contacts. An invoice from a known vendor is not automatically safe if the account was compromised.
- Message: Does the message create urgency or fear? "Your account will be suspended in 24 hours unless you verify your information immediately" is the psychological template for phishing. Legitimate organizations do not create urgency around account actions via email. Urgency is a manipulation signal.
Include real examples — Show actual phishing emails (redacted if necessary) with the red flags highlighted. Abstract descriptions of phishing tactics are less effective than visual examples. Employees who have seen what a realistic phishing email looks like in your company's context — using your company's name, your executives' names, or your known vendors — are better at recognizing them.
Vishing and smishing — Voice phishing (vishing) and SMS phishing (smishing) use the same psychological mechanisms as email phishing but are perceived as lower-risk by most employees because they associate phishing with email. The "Hi, this is Mark from IT Security calling about suspicious activity on your account — I need to verify your credentials to protect your access" call is a vishing attack. Train employees to verify caller identity by hanging up and calling back through a verified number.
Simulated phishing programs — If your organization runs a simulated phishing program (KnowBe4, Proofpoint Security Awareness Training, Cofense, and similar platforms all offer this), share the organization's phishing simulation results in the training. Industry average click rate on simulated phishing is approximately 10–15%. Organizations with mature, ongoing security awareness programs achieve below 5%. Showing employees where the organization stands and how it has improved over time creates accountability and demonstrates that the training program is measurable.
Module 2: Password Hygiene
Most corporate password policies are based on outdated guidelines. NIST Special Publication 800-63B (updated 2020) changed the recommended approach to password security significantly, and most organizations are still enforcing policies that contradict the current standard. Training employees on current best practices — and explaining why the outdated rules made things worse — is both more accurate and more memorable.
What NIST 800-63B actually says:
- Minimum length: 15 characters (NIST's current guidance for memorized secrets; 12 is the practical floor for most enterprise policies)
- No mandatory complexity requirements: requirements like "must include uppercase, lowercase, number, and special character" do not improve security and consistently produce predictable patterns (Password1!, P@ssw0rd, etc.)
- No mandatory periodic rotation: unless a credential is suspected to be compromised, forced rotation every 90 days leads employees to make minimal incremental changes (Password1 → Password2 → Password3) rather than choosing genuinely new credentials
- Breach credential checking: passwords should be checked against known-compromised credential databases at creation and rotation. Platforms like HaveIBeenPwned maintain databases of hundreds of millions of compromised credentials.
Password managers — Train employees on the organization's approved password manager (Bitwarden for Business, 1Password Business, or Dashlane Business are common enterprise choices). A password manager allows each account to have a unique, randomly generated password of maximum length without requiring memorization. Employees who resist password managers usually do so because they have never been taught to use one — the training session is the right place to demonstrate the workflow.
Address 1Password vs. LastPass credibly — If your organization previously used LastPass before its significant 2022 data breach (encrypted vaults were exfiltrated), acknowledge it and explain why the current approved tool is the replacement. Employees who know about the breach and see the organization continuing to use the affected product will lose trust in the security program.
Module 3: Multi-Factor Authentication
MFA is the single most effective control against credential-based attacks. An account with MFA enabled is dramatically harder to compromise than an account with only a password, even if the password is known to an attacker.
MFA method hierarchy (from most to least secure):
- Hardware security keys (FIDO2/WebAuthn) — YubiKey and similar devices. Phishing-resistant by design because the key only responds to requests from the legitimate domain. The gold standard.
- Authenticator app TOTP (Time-based One-Time Password) — Google Authenticator, Authy, Microsoft Authenticator. Codes rotate every 30 seconds. Not phishing-resistant (an attacker who tricks you into a fake login page can capture the code in real time) but a significant improvement over SMS.
- SMS one-time codes — Susceptible to SIM-swapping attacks and SS7 vulnerabilities. Better than nothing; weaker than authenticator apps.
- Email OTP — Susceptible to account compromise by definition; if the attacker has compromised your email, email OTP provides no additional protection.
MFA fatigue attacks — Also called MFA bombing or push fatigue attacks. The attacker has obtained your username and password and initiates repeated MFA push notifications to your authenticator app, hoping you will approve one to make the interruptions stop. Train employees explicitly: never approve an MFA push notification you did not initiate. If you receive unexpected MFA push notifications, do not approve them and report them to IT Security immediately — it means your password has been compromised and needs to be changed.
Module 4: Data Classification and Handling
Define your organization's data classification tiers and the handling requirements for each. The classification names and tier count vary by organization, but a typical four-tier structure:
- Public: Information approved for external distribution — marketing materials, published blog posts, public documentation.
- Internal: Information intended for employees and contractors but not the general public — internal wiki articles, project plans, company-wide emails.
- Confidential: Sensitive business information that could cause harm if disclosed — customer lists, financial projections, personnel records, contract terms.
- Restricted: Highly sensitive information with strict need-to-know access — board materials, M&A information, security incident details, PII regulated by GDPR or HIPAA, authentication credentials.
For each classification level, specify: what it can be stored in (corporate systems, approved cloud applications, personal devices), how it can be shared (unencrypted email, encrypted email, secure file transfer, in-person only), and who can authorize exceptions.
The handling requirement that generates the most incidents is the use of personal cloud storage (Dropbox, Google Drive personal, iCloud) for work files. Train employees explicitly on this: confidential and restricted information may not be stored in unapproved personal services, regardless of convenience. The reason is not abstract: when an employee leaves the company, files stored in personal cloud services leave with them.
Module 5: Incident Reporting
The fastest containment of a security incident depends on early reporting. Train employees on exactly what to do if they suspect they have been phished, clicked a malicious link, or observed a potential security event.
The immediate steps after clicking a suspicious link:
- Do not try to "fix it yourself" — do not run antivirus, do not delete emails, do not try to determine whether the link was actually malicious.
- Disconnect from the network immediately — unplug the ethernet cable or turn off Wi-Fi. This limits the potential spread of any malware.
- Call IT Security using the designated incident reporting number — do not use email, which may be compromised.
- Do not shut down the computer — a running computer preserves forensic evidence that shutdown destroys.
The incident reporting channel — Make the reporting mechanism specific and easy to remember: a dedicated IT Security phone number, a Slack channel, a security email alias. Employees who do not know how to report a suspected incident will delay reporting out of uncertainty, and delay is the primary driver of incident severity.
HIPAA-Specific Training Elements
For organizations handling Protected Health Information (PHI), add the following to the base security training:
PHI definition — Covered under HIPAA: 18 specific identifiers including name, address, birthdate, Social Security Number, medical record number, health plan beneficiary number, account numbers, certificate/license numbers, vehicle identifiers, web URLs, IP addresses, biometric identifiers, and photographs. PHI is PHI regardless of whether it is linked to health data — a list of patients' names and email addresses is PHI even if it contains no clinical information.
Minimum necessary standard — HIPAA requires using, disclosing, and requesting only the minimum PHI necessary to accomplish the intended purpose. An employee who needs to confirm a patient's appointment does not need access to their complete medical history.
Breach notification obligations — HIPAA requires covered entities to notify affected individuals within 60 days of discovering a breach of unsecured PHI. Breaches affecting 500 or more individuals must also be reported to HHS and, in some cases, to prominent media in the affected area. Employees should understand that unreported security incidents involving PHI carry significant legal and financial consequences.
Completion Documentation for Audit Evidence
The compliance requirement is not just that training occurred — it is that you can prove it occurred, for whom, and when. For audit purposes, capture:
- Completion attestation: each employee acknowledges they completed the training and understand their responsibilities. This should be a digitally signed document or a recorded click-through agreement.
- Completion date and timestamp
- Version of the training completed (if the content changes, prior completions should be tracked by version)
- List of employees who have not completed training within the required window (typically 30 days after hire for new employees, annual completion for all employees)
Store completion records for a minimum of three years (SOC 2 and ISO 27001 standard audit lookback); HIPAA recommends six years.
Board-Level Security Posture Presentation
The board-level security presentation serves a different purpose: it gives the board the governance-level information they need to fulfill their fiduciary responsibility for cybersecurity risk oversight. This is increasingly a legal requirement. SEC disclosure rules require public companies to describe board-level cybersecurity expertise and oversight processes.
This presentation covers: current threat landscape relevant to your industry (specific, not generic), key security metrics (phishing simulation rates, vulnerability remediation time, security control coverage, incident response time), significant incidents or near-misses in the period, budget allocation vs. industry benchmarks, compliance status, and the top three security risks and the controls in place for each.
Keep the board presentation to 20 minutes of content with 10 minutes of Q&A. Board members are not reviewing technical implementation details — they are exercising oversight of risk, investment, and accountability. Give them the information to do that clearly.
Build your next presentation with AI
Generate editable .pptx decks in minutes. Free to start — no card required.
Try it free →