In-Depth Guide
Security Awareness Training: What to Buy, What to Build, and Where the Two Meet
Most organisations buy security awareness training once and never notice that the half nobody sells is the half their own incidents turn on. This guide separates the two layers, and sets out how to source each one.
Security awareness training is sold as one product and is really two. One half is global: phishing, passwords, device hygiene, the behaviours that are identical at every organisation on earth and that a bought library covers well. The other half is local: your password manager, your file-sharing tool, your reporting route, your data labels. No vendor can write that half, because it is specific to you. This guide separates the two and sets out how to source each one.
What Is Security Awareness Training?
Security awareness training is training that changes what employees do when they meet a security decision. It is not training that makes employees into security specialists, and the distinction matters when you are choosing a supplier.
A useful programme changes behaviour at four moments: when an unexpected message arrives, when a credential is created or shared, when data moves somewhere new, and when something has already gone wrong and somebody has to decide whether to report it. Everything else in the category is supporting material for those four moments.
The category has a second, quieter job. In most organisations, security awareness training is also the evidence produced for insurers, customers and certification assessors that the workforce was told. That is why completion records matter as much as content quality, and why a programme that teaches brilliantly but records nothing tends to get replaced.
The Two Layers, and Why Only One of Them Is for Sale
This is the split that decides your buying decision, and it is rarely drawn explicitly.
Layer one is global threat behaviour. How to recognise a phishing message, why credential reuse is dangerous, what social engineering sounds like on a phone call, why a USB stick found in a car park is a bad idea. None of this is specific to your organisation. It is the same at a dental practice and a shipping line, which is exactly why it can be mass produced, and why the off-the-shelf libraries are good at it.
Layer two is your own policy. Which password manager your organisation licences and how to get a vault. Which file-sharing tool is approved and which one people actually use instead. Who to contact when a laptop goes missing at 9pm on a Friday. What your data classification labels mean in practice rather than in the policy document. Which third parties are allowed to request a payment change, and through what channel.
Layer two is the layer your incidents turn on. When an incident post-mortem says somebody sent client data through a personal account, the gap was almost never "did not know phishing exists". It was "did not know which tool to use, or did not know who to tell". Layer two is also the layer nobody can sell you, because the content is your own documents.
Most programmes buy layer one, run it annually, and never build layer two at all.
Why Microlearning Suits Security Awareness
Security awareness is the training category microlearning fits best, for reasons specific to the subject rather than general enthusiasm for short courses.
- The decisions are momentary. A phishing decision takes four seconds. Training that mirrors the decision is closer to the task than a forty-minute module that covers the history of social engineering.
- The content dates quickly. Attack patterns change, your tooling changes, and your policy changes. Short modules can be replaced one at a time. A single long annual course has to be rebuilt whole or left stale.
- It has to reach everybody, including people without a desk. Security awareness is one of very few programmes that genuinely applies to every employee, contractor and temp. Short mobile modules reach a warehouse or a ward in a way a scheduled classroom session does not.
- Annual delivery fights the forgetting curve. A once-a-year session is the industry default and it is the worst possible cadence for retention. Our guide to managing the forgetting curve covers why, and what spacing does about it.
- Short modules can be role-specific without multiplying the build. Finance needs payment-diversion content that nobody else needs. A twelve-module library lets you assign six modules to everyone and two more to finance, rather than building two full courses.

Library, Platform or Authoring Tool: Which Are You Actually Buying?
Three different kinds of product are sold under the same search term. They do not compete with each other as directly as their marketing suggests.
| Dedicated security awareness platform | General microlearning library | Authoring tool | |
|---|---|---|---|
| What you are buying | Ready-made modules plus simulation and risk reporting | Ready-made modules across many subjects | The means to make modules from your own material |
| Who writes the content | The vendor | The vendor | You, or your AI assistant working from your documents |
| Covers layer one | Yes, and it is the category's strength | Usually, at a shallower depth | Only if you write it |
| Covers layer two, your own policy | No | No | Yes, this is the whole point |
| Simulated phishing | Normally included | No | No |
| Pricing basis | Per user, per year | Per learner, per month or year | Per author, with a learner allowance |
| When your policy changes | Raise it with the vendor, or leave it | Not applicable | Re-upload the policy and regenerate |
| Handover to your own LMS | Varies, check by plan | Varies, check by plan | SCORM export is the normal output |
The row that decides most purchases is the fourth. If your requirement is genuinely "our people must be able to recognise a phishing email", a dedicated platform is the efficient answer and you should buy one. If your requirement is "our people must follow our information security policy", no library contains your policy and buying one will not make it true.
Naming the category honestly: SC Training, formerly EdApp and now part of SafetyCulture, ships over 1,000 prebuilt courses, weighted towards US and OSHA-centric content. Dedicated security awareness vendors such as KnowBe4, Proofpoint and Hoxhunt sell the same three things as each other: a module library, simulated phishing, and reporting that scores individual risk. Published pricing in that group varies and several quote rather than publish, so get a figure for your exact headcount rather than working from a list price you found in a blog post.
What an Off-the-Shelf Library Cannot Contain
This is the list worth taking into a vendor meeting. None of these can appear in a course written before the vendor met you, and every one of them is a real cause of real incidents.
- The name of your password manager, and how an employee gets a vault on day one.
- Your approved file-sharing route, and the specific unapproved one people default to instead.
- Your incident reporting route out of hours, including the phone number and who answers it.
- Your data classification labels, and what each one means for a document somebody is about to email.
- Your payment change verification procedure, which is the single control that stops business email compromise and is different at every organisation.
- Your joiner, mover and leaver process, and what a manager is supposed to do on the day somebody resigns.
- Your acceptable use position on personal devices, which is a policy decision, not a security fact.
- Your approved AI tools, and what staff are permitted to paste into them. This one is new, it is changing quarterly, and almost no library has caught up with it.
- Your named owners. Training that says "contact your security team" teaches nothing. Training that names the team, the channel and the response time changes what happens at 9pm on a Friday.
What to Check Before You Buy
Work through these with the vendor's documentation open. Each one has caught a real purchase out.
- Does the licence cover everybody, including contractors and temps? Security awareness is one of the few programmes that genuinely has to reach non-employees, and per-user pricing on a fluctuating contractor population is where budgets break.
- Can you edit the vendor's modules? Many libraries are read-only. If you cannot insert one screen naming your own reporting route, you cannot close the layer two gap inside the product you just bought.
- How is a user counted? Per named user, per active user and per credit are three different models. Get the arithmetic for your headcount rather than the headline.
- Does the reporting produce the evidence you actually need? Ask what an assessor or an insurer will be shown. A completion percentage and a per-person record are different artefacts.
- Does it reach people without a corporate login? Field staff, ward staff and warehouse staff often have no desktop and sometimes no company email address.
- What language coverage do you need? A multilingual workforce that trains in a second language is being assessed on comprehension as much as on security.
- Can you get your completion records out? Ask the exit question at the start. Records that live only in a vendor's dashboard are records you can lose at renewal.
- Does it export SCORM, and on which plan? If you already run an LMS, the course has to reach it. Several microlearning platforms restrict SCORM export to an enterprise contract, and some ship a link-based wrapper rather than a standalone file.
How to Choose: A Short Decision Guide
Work down this list and stop at the first line that describes your situation.
- You need simulated phishing as the core of the programme. Buy a dedicated security awareness platform. Simulation is a delivery mechanism, not a course, and an authoring tool including QuikAuthor does not provide it.
- You need broad off-the-shelf coverage across many compliance subjects and have no appetite to write anything. Buy a library. SC Training is the largest of the ones aimed at this market.
- You already have a written information security policy and need people assessed on it. You want an authoring tool, because the content already exists and the job is conversion rather than writing. This is what Compliance Builder does.
- You bought a library and your incidents are still about internal process. You have layer one covered and layer two missing. Add three or four short policy-specific modules rather than replacing the library.
- You need the output inside an LMS you already run. Check SCORM export by plan before anything else, and confirm the package is a standalone file. Our SCORM export page covers how that works here.
- You need drip-fed reinforcement over weeks as the core mechanism. You want spaced repetition, which QuikAuthor does not have. Name the feature in your requirements and check for it explicitly.
- You have no budget and need to prove the idea before asking for one. Convert one policy into one course on a free plan and show somebody the completion report.
How to Build the Policy Half From What You Already Have
If layer two is the gap, the content already exists. It is in your policy documents. The work is conversion, not authorship.
- Start from the policy, not from a blank page. Upload the information security policy or acceptable use policy as a PDF. Compliance Builder extracts the text and generates knowledge checks from it, so every question traces back to a specific clause rather than to generic security trivia.
- Cut it to the decisions. A thirty-page policy contains perhaps eight things an employee has to do differently. Build the course around those eight, and link to the full policy for the rest.
- Name the tools and the people. Replace every "contact the relevant team" with the actual channel. This is the step that makes the course yours and the step a library structurally cannot do for you.
- Embed the policy in the course. The policy PDF can sit inside the course as a viewable document, so learners read the source before being assessed on it, and the course links back to the live policy location on exit.
- Set the pass mark deliberately. Compliance Builder courses default to a 100% pass rate, on the basis that a course exists to prove understanding of the whole policy rather than most of it. A TestOut option lets experienced staff prove they already know it and skip the review.
- Assign it, with dates. Assign to individuals or whole teams, set a due date, and let the automated reminders chase the incomplete ones. That is the audit trail, and producing it by hand is where L&D time actually goes.
- Translate it if your workforce needs it. Courses translate into 20 languages including video transcripts and subtitles, with layout and branding preserved.
- Regenerate when the policy changes. Upload the new version and rebuild, then track completion of the updated version separately from the old one. This is the maintenance cost that kills hand-built compliance training, and it is the one that conversion removes.
Where QuikAuthor Fits, and Where It Does Not
QuikAuthor is an authoring tool, not a security awareness platform, and the difference is worth stating plainly before the useful part.
What it does not do. QuikAuthor does not run simulated phishing campaigns. It does not score individual human risk. And it does not ship a ready-made security awareness course library: the starter library currently covers Display Screen Equipment, AI Foundations and building with Gemini Canvas, not information security. If any of those three things is your requirement, buy a dedicated platform and do not let anyone talk you out of it.
What it does do. It turns your own policy into assessed, trackable training. Upload a policy PDF and Compliance Builder produces a course with knowledge checks grounded in the policy text, in formats that run from multiple choice to swipe games to Millionaire-style rounds drawn from 70+ interactive templates. Courses are mobile-first, so field and frontline staff can complete them on a phone, and there are native iOS and Android learner apps with offline access. Courses export as SCORM 1.2 and SCORM 2004 for an LMS you already run, or you can assign them directly, set due dates and export completion reports.
The arithmetic. QuikAuthor prices per author rather than per user, which changes the shape of the cost for a programme that has to reach everyone. The free plan covers 25 courses and up to 50 active monthly learners with every AI feature, custom branding, 10 lifetime SCORM exports and no credit card. PRO is $69 per month or $799 per year for one author and up to 200 active monthly learners, which works out at just under $4.00 per learner per year if you use the full allowance. TEAM is $2,000 per year for three authors on otherwise identical terms. Full detail is on the pricing page.
The honest comparison is not "cheaper than a security awareness platform". It is that you are buying a different thing: the platform writes the content and charges per head, and the authoring tool charges per author and expects you to bring the policy. Many organisations that take security seriously end up running both, and that is a reasonable answer rather than a failure to decide.
Frequently Asked Questions
What is security awareness training?
Security awareness training is training that changes what employees do at a security decision point, rather than training that turns employees into security specialists. It targets four moments: when an unexpected message arrives, when a credential is created or shared, when data moves somewhere new, and when something has gone wrong and somebody must decide whether to report it. In most organisations it also produces the completion evidence shown to insurers, customers and certification assessors.
What is microlearning security awareness training?
Microlearning security awareness training delivers the same material as short focused modules rather than one long annual course. It suits the subject because security decisions are momentary, because the content dates quickly and short modules can be replaced one at a time, and because the programme has to reach every employee including people who have no desk and no corporate login.
Can you build your own security awareness training instead of buying a library?
You can, and for one specific half of the programme you have to. Global threat behaviour such as phishing recognition and password hygiene is identical at every organisation and is what bought libraries do well. Your own policy is not: your password manager, your approved file-sharing route, your out-of-hours reporting contact and your data classification labels cannot appear in a course written before the vendor met you. That half only exists if you build it from your own documents.
Does QuikAuthor provide ready-made security awareness courses?
No. QuikAuthor is an authoring tool rather than a course library, and its starter library currently covers Display Screen Equipment, AI Foundations and building with Gemini Canvas rather than information security. What QuikAuthor does is turn your own security policy into an assessed course: upload the policy PDF and Compliance Builder generates knowledge checks grounded in the policy text.
Does QuikAuthor run simulated phishing campaigns?
No. Simulated phishing is a delivery mechanism rather than a course, and it is the defining feature of the dedicated security awareness platform category. If simulation is the core of your programme, buy a platform that provides it. QuikAuthor covers the training and assessment side, including the policy-specific content those platforms cannot write for you.
How much does security awareness training cost for a small business?
It depends which of the three product types you buy, because they are priced on different bases. Dedicated security awareness platforms and microlearning libraries charge per user per year, so the cost scales with headcount and with your contractor population. Authoring tools charge per author, so the cost scales with how many people build courses rather than how many take them. QuikAuthor PRO is $799 per year for one author and up to 200 active monthly learners, which is just under $4.00 per learner per year at the full allowance, and the free plan covers 50 active monthly learners with no credit card.
How often should security awareness training run?
Once a year is the common default and it is the weakest possible cadence, because a single session in January is largely gone by March. A more defensible pattern is a short module whenever the thing it describes actually changes: a new tool, a revised policy, a new attack pattern your organisation has actually seen. Set the rhythm from your own policy review cycle and your own incident log rather than from the calendar.
Does security awareness training need to export SCORM?
Only if you already run a learning management system and want the completion records in it. SCORM is the handover format between the tool that builds a course and the system that delivers and records it. If you have an LMS, check SCORM export by plan before buying, because several microlearning platforms restrict export to an enterprise contract and some ship a link-based wrapper that stops working when the subscription does.
How do you measure whether security awareness training worked?
Completion rates measure delivery, not effect, so treat them as the audit artefact rather than the result. The measures that indicate behaviour are the ones drawn from your own operations: how many suspicious messages get reported rather than deleted, how long a reported incident takes to reach the security team, and whether repeat incidents cluster in the same team. A programme that raises the reporting rate is working even if the incident count has not moved yet.
Where This Guide Stops
Two limits are worth naming rather than glossing over.
This guide does not rank security awareness vendors. Product comparisons in that category date within a quarter, pricing is frequently quoted rather than published, and a ranked list written today would mislead somebody reading it in six months. The decision guide above is deliberately about matching a product type to a requirement, which changes far more slowly.
And no training programme is a control on its own. Security awareness reduces the frequency of human error; it does not remove it, and a programme sold on the promise that it will is being oversold. The measurable win is usually a higher reporting rate rather than a lower incident count, which is a less satisfying number to put in a board pack and a more honest one.
Turn One Policy Into One Course
Upload your information security policy and see what comes back. The QuikAuthor free plan includes Compliance Builder and every other AI feature, 25 courses, 50 active monthly learners and 10 lifetime SCORM exports, with no credit card and no expiry.
Related reading: Convert Policy to Course · Compliance Training Solutions · Rapid Authoring Tools