Security awareness training is one of the most audited sections of CTDISR-2025 because the evidence requirement is specific and the common implementation gap is well known to auditors: training that happened but wasn't recorded. Section 18 mandates annual training for all staff, role-specific training for technical and privileged users, phishing simulation exercises, and maintained training records. The record-keeping requirement is as important as the training itself.

Annual Security Awareness Training

All staff with access to organisational systems must complete security awareness training at least annually. The content requirement covers: phishing and social engineering recognition, password security and credential management, incident reporting procedures (critically, staff need to know what to report, to whom, and how), acceptable use of organisational systems, and data handling responsibilities.

The training format is not prescribed: it can be a formal instructor-led session, an online training module, a structured team meeting with documented content, or a combination. What matters is that it covers the required topics, that completion is recorded per individual, and that the records are retained and available for audit.

For small ISPs where formal training platforms represent disproportionate cost, a structured annual training session with an agenda covering the required topics and an attendance sheet signed by participants satisfies the requirement. Larger operators benefit from a platform like KnowBe4, Proofpoint Security Awareness Training, or similar that provides automated delivery, completion tracking, and reporting.

The annual cadence means training records need to show coverage within the previous 12 months for each staff member. An auditor conducting a CTDISR audit in November will look for training completed since the previous November, not just in January. Scheduling the annual training for the same period each year and maintaining year-labelled records makes this straightforward to demonstrate.

Role-Specific Training for Technical Staff

Staff with elevated access or operational responsibility need training that goes beyond general awareness. This includes NOC engineers, network administrators, security staff, and anyone with privileged system access. Role-specific training should cover the specific risks and responsibilities of their function: for NOC engineers, incident classification and escalation procedures; for network administrators, secure configuration management and change control; for security staff, specific threat actor tactics and technical indicators of compromise.

The role-specific training doesn't need to be a separate formal course for each role. Incorporating role-relevant security content into technical onboarding, regular team stand-ups with documented discussion of relevant topics, and sharing post-incident reviews as learning materials all contribute to role-specific training with appropriate documentation.

Phishing Simulation Exercises

Phishing simulations are specifically mandated under Section 18, distinguishing CTDISR-2025 from frameworks that only require awareness training. A simulation involves sending realistic but harmless simulated phishing emails to staff and measuring the response: who opened the email, who clicked the link, who submitted credentials to a simulated phishing page.

The simulation results serve two purposes: they identify staff who need additional targeted training (those who clicked or submitted credentials), and they provide a baseline and trend metric for the organisation's overall phishing resilience that can be reported to the ISSC.

For implementation, a commercial simulation platform like KnowBe4 makes running simulations straightforward and produces the documented results that audits require. For operators who want to run simulations without a commercial platform, manual simulations using free tools like GoPhish are possible but require more setup effort and careful documentation of results.

Simulation frequency is not explicitly defined in CTDISR-2025, but quarterly simulations are the industry standard and what auditors expect to see. Annual simulations are likely the minimum that satisfies the spirit of the requirement. The key is producing documented results showing simulations were conducted, when, with what scenario, and what the results were.

Training Records as Audit Evidence

The training record requirement is where most ISPs fail Section 18 despite having conducted training. The records needed are: for each staff member, evidence of completion of the annual awareness training with a date, the content covered, and some form of individual acknowledgement (signature, platform completion record, or similar). For phishing simulations, a report showing the date, the simulation scenario, the number of staff tested, and the results.

Records need to be retained and accessible, not just created. A training completion spreadsheet that was produced but saved somewhere nobody can find it two years later doesn't satisfy the requirement. Maintain training records alongside your other CTDISR evidence in a location that can be accessed quickly during an audit.

For operators running a full CTDISR compliance programme, ComplianceIQ manages Section 18 evidence alongside all other sections, with reminders for renewal and audit-ready reporting. For operators who need support building the training programme and managing the Section 18 obligations as part of the CISO function, CISO-as-a-Service covers training programme oversight as part of its scope. For a scored assessment of your Section 18 compliance alongside all 19 sections, ISP Audit identifies the gaps before the external auditor does.