Complete level
SORT SecurityAcademy: awareness that leaves evidence, not just attendance
A self-service security awareness platform with role-based learning paths, assessments, named certification and a real-time metrics panel by user, department and organisation.
What problem it solves
The typical awareness programme starts at the end: a platform is bought, courses are assigned to everyone, and a completion percentage is reported. The next year it repeats. Nobody knows whether it worked, because nothing other than attendance was ever measured. SecurityAcademy is built around the opposite idea: content is assigned according to each person’s role and real exposure, and what gets measured is the outcome.
Who it is for
- Organisations that must evidence competence and awareness in an ISO audit.
- Teams with very different profiles —board, IT, front desk— that should not all receive the same content.
- Existing programmes that cannot demonstrate anything beyond a completion percentage.
Capabilities
01
Role-based paths
Each profile receives the content its exposure calls for: training the board is not the same as training the support team or front-of-house staff.
02
Assessment and certification
Assessments at the end of each path with named certification, which serves as a competence record within the management system.
03
Real-time metrics
A panel by user, department and organisation showing progress, results and gaps. The board sees where the risk is, not just how many people logged in.
04
Audit-ready evidence
Records export with the detail the auditor asks for: who, what content, when, and with what result.
What the rollout includes
- Organisation onboarding and user loading by department.
- Definition of learning paths by role and exposure.
- Progress tracking and support with internal communications.
- Export of evidence for internal and external audit.
Frequently asked questions
Does it work as competence evidence for ISO/IEC 27001?
Yes. The standard requires determining the necessary competence, ensuring it, and retaining documented information as evidence. Named certification per path, with date and assessment result, is exactly the record an auditor looks for against that requirement.
Can it be combined with simulated phishing exercises?
Yes, and it is the recommended approach. A controlled phishing exercise before assigning content shows where the real exposure is and allows the training to be targeted rather than distributed uniformly. After the programme, a second exercise measures whether anything changed.
How much time does it take each person?
The paths are built as short modules, a few minutes each, completed over weeks rather than in one sitting. Retention from a single two-hour annual session is markedly worse than from twelve brief contacts spread across the year.
