← Back to blog
Guides

Running Security Awareness Training in Slack

The Poplearn TeamJul 13, 2026 · 3 min read

Security awareness training has a well-known shape: one long module every year, usually in the same month, largely ignored, completed in a rush before a deadline. It satisfies an obligation and changes very little.

The problems are cadence and delivery, and both are fixable.

Annual is the wrong interval

Two things break the annual model.

Recall decays fast. Whatever someone learns about phishing indicators in March is substantially gone by July, which is roughly when they'll receive the message that matters.

And the threat landscape moves. Annual content is written months before it's delivered, so it describes last year's techniques. The specific patterns worth recognising — a particular payroll-diversion approach, a vendor impersonation making the rounds — have a shelf life measured in weeks.

Shorter, more frequent modules solve both. The same total annual training time, distributed across the year, produces meaningfully better recall and lets you respond to what's actually happening.

Why Slack specifically

For most training, delivering in Slack is about removing friction. For security awareness there's a sharper reason: the response you want happens in Slack too.

When someone receives a suspicious message, you want them to report it quickly and without embarrassment. If the training lived in a portal they visited eight months ago and reporting means finding an email address for the security team, most people will hesitate, decide it's probably fine, and move on.

If the training arrived in Slack and the reporting channel is in Slack, the distance between "this looks odd" and "reported" is very short. That distance is the thing that determines whether you hear about incidents.

Haekka is worth knowing about here — it's Slack-first for compliance and runs phishing simulations that route failures into Slack-based just-in-time training, which closes that loop directly.

What to cover, in what order

Front-load what's most likely and most damaging:

  • Phishing and pretexting, with recent, specific examples rather than generic advice. This is the majority of real incidents.
  • Credential handling — password managers, MFA, and why credential reuse matters.
  • Data handling — what can go where, particularly around customer data and AI tools.
  • Device and physical security — briefly; it's lower frequency.
  • Reporting — how, where, and an explicit statement that reporting something harmless is always fine.

That last point deserves its own module. The main obstacle to reporting isn't ignorance of the process, it's the fear of looking foolish. Saying plainly that false positives are welcome changes behaviour more than a process diagram does.

Measure reporting, not just completion

Completion tells you the training was delivered. It says almost nothing about whether anyone is safer.

The better signal is reporting behaviour. If the number of suspicious messages reported to your security channel rises after training — including harmless ones — the training worked. People are noticing and acting.

A flat report rate alongside 100% completion means you have compliance without effect, which is the outcome the annual model usually produces.

Keep the record

Security awareness training is often an audit requirement under SOC 2 or similar, so the evidence layer matters as much as the content. You need per-person, timestamped, exportable records — and historical ones, retained rather than overwritten when the training re-runs.

Running it

If your security team has already written the material, the gap is delivery and cadence.

Poplearn takes that document, splits it into modules and writes the quizzes, and delivers them as Slack direct messages. Assign to #general plus everyone who joins from a date forward, so new starters are covered automatically, and use /progress for live completion by team, exportable when an auditor asks.

If your security team hasn't written it and you need maintained, regulated content, buying that content is the right call — Poplearn converts what you give it rather than supplying the material.

Free under 20 seats, installs in about a minute.

Your next hire starts Monday.

Free under 20 seats. Installs in a minute.

Add to Slack