Security Awareness
The Security Awareness module provides interactive cyber security training for your workforce. Employees complete guided courses with real-world scenarios and knowledge checks, helping your organisation meet compliance requirements and build a security-conscious culture.
Key features
- Interactive courses — step-by-step training with content, scenarios, and quizzes
- Built-in course library — pre-built courses covering phishing, AI threats, password security, social engineering, and more
- Knowledge checks — quiz questions with instant feedback and explanations
- Compliance dashboard — see completion rates across your organisation at a glance
- Due dates and reminders — assign courses with deadlines and track overdue completions
- Certificates — employees earn certificates on passing, recorded in their profile
- Mandatory courses — auto-assign courses to all employees
How it works
For employees
- Go to Security Awareness from the sidebar
- You'll see your assigned courses with their status (to complete, in progress, passed, or failed)
- Click Start on a course to begin the training journey
- Work through the steps — each course includes:
- Content — educational material about the threat
- Scenarios — real-world examples to consider
- Quiz questions — test your understanding with multiple-choice questions
- At the end, your answers are scored and you're told how many you got right and how many you needed. The pass mark is 80%, applied sensibly to short quizzes: a three- or four-question quiz allows one wrong answer, a two-question quiz needs both, and longer quizzes follow the percentage
- If you don't pass, you can retry the course
Course topics
Luna HR comes with nine built-in courses, written for the staff of a small UK company — no assumption of an IT department, pounds rather than dollars, and UK places to report things (Report Fraud, the NCSC's report@phishing.gov.uk, 7726 for texts, 159 for your bank). Each has five questions, so the 80% pass mark means four right.
| Course | Duration | What it covers | |--------|----------|----------------| | Spotting phishing emails | 12 min | Pressure to act, fake sign-in pages, "don't use the link", QR codes, what to do if you clicked | | Scams on your phone | 10 min | Parcel, HMRC and bank texts, the "safe account" call, "Hi Mum" and WhatsApp code scams | | Passwords and two-step sign-in | 10 min | Password reuse, three random words, password managers, code-sharing and approval-prompt tricks | | Payment and invoice fraud | 12 min | Changed bank details, the urgent request from a director, the bank's name check, what to do if money has gone | | When someone is trying to manipulate you | 10 min | Fake IT support calls, remote-access requests, what's public about you, visitors at the door | | AI: fake voices, fake video and using AI tools safely | 12 min | Cloned voices and faked video calls, checking by a second route, what not to paste into an AI tool | | Looking after your devices, in and out of the office | 12 min | Updates, lost laptops and phones, working from home and on the move, ransomware and backups | | Handling personal data (UK GDPR) | 12 min | What personal data is, mis-sent email and the 72-hour clock, Bcc, subject access requests | | Security around the workplace | 8 min | Screen locking, paper and shredding, found USB sticks, visitors, disposing of old equipment |
Wherever a course says who to tell, it uses the contact you set under Who staff should tell (below).
Admin setup
Who staff should tell
Every course ends with the same advice: if something looks wrong, tell someone quickly. Admin > Security has a Who staff should tell card where you name that someone:
- Someone in the company — pick an employee. Their name and work email are read from their profile, so a name change follows through; add a phone number if you want one shown
- Someone outside, such as an IT provider — give a name and an email address or phone number
The contact appears in the security courses wherever the text says who to report to, and on every employee's Security page in a Seen something that doesn't look right? card with click-to-email and click-to-call links. Until you name someone, courses tell people to speak to their manager. If the person you chose leaves the company, staff see the manager wording again and the card asks you to choose someone else.
Course library
Manage your course library from Admin > Security Training. You can:
- View all available courses with their completion statistics
- Toggle courses active/inactive — inactive courses aren't assigned to new employees
- Mark courses as mandatory — switching this on assigns the course straight away to every active employee who doesn't already have it, with a 30-day due date, an in-app notification and an email. People who join later are picked up automatically overnight. Switching it off stops new assignments; it doesn't remove anyone's existing course
- Assign a course to particular people — each person gets an in-app notification and an email, and the assignment is recorded in the activity log. Someone who already has the course is not told again.
- Emails — assignment and refresher-due emails use the Course Due template under Admin > Email templates > Security Awareness, where you can reword them or switch them off. People can also turn them off for themselves with their training email preference. The 30-day "refresher coming up" notice stays in-app only.
- Assign to specific employees — select individuals and set a due date
- Import built-in courses — load the pre-built course library with one click
Compliance dashboard
The compliance dashboard (second tab in the admin page) shows:
- Overall compliance rate — percentage of assigned courses that have been completed
- Completion heatmap — employee-by-course matrix showing who has completed what
- Overdue tracking — identify employees who haven't completed their assigned training
- CSV export — download compliance data for auditing
Setting due dates
When assigning a course, you can set a due date (7, 14, 30, 60, or 90 days from assignment). Overdue courses are flagged on the employee's dashboard and in the admin compliance view.
Course validity
Each course has a validity period (default 12 months; AI threats is 6 months, to keep knowledge current). A pass shows its Valid until date on the employee's Security page.
- 30 days before a pass runs out, the employee gets an in-app heads-up and the course shows Refresher soon
- When it runs out, the course goes back to To complete, marked Refresher, with a 30-day due date and a notification. The date and score of the previous pass are kept on the record
- Until then the pass counts towards compliance as normal; afterwards the compliance dashboard shows the course as outstanding again
This runs overnight. Passes earned before expiry was tracked are picked up automatically — anything already older than its validity period becomes a refresher the first night after the update.
Course updates
The built-in courses are copied into your company when you first import them, so you can switch them on and off independently. When Luna improves a course or adds a new one, Admin > Security shows an Updated course content is available banner. Review update lists what will change; applying it keeps every pass already earned and your active and mandatory settings, and sends anyone part-way through an improved course back to its start.
Related
- Training — for general training and certifications
- Roles & Permissions — admin access to manage courses