Security awareness training glossary
27 terms, defined plainly. The vocabulary this category uses in vendor conversations, client reviews and renewal negotiations.
Where Hook Security uses a different word than the rest of the industry, the entry says so and explains why.
Program models
Security awareness training is any structured program that teaches people to recognize and respond to cybersecurity threats — phishing, social engineering, malware and password hygiene.
A managed security awareness program in which training, phishing simulations, reinforcement and client-ready reporting all run continuously without an administrator operating the platform.
A service model where the vendor designs, runs and reports on the entire security awareness program, end to end.
A functional synonym for done-for-you: the vendor operates the program and the customer receives the outcomes.
A hybrid model where the MSP makes design decisions and the vendor handles execution.
A platform-only model where the customer or MSP operates the program themselves.
Phishing simulation
A controlled, safe phishing email sent to your own people so they can practise recognising a real one.
A pre-built simulated phishing email that mimics a specific attack type, such as credential harvesting, business email compromise or brand impersonation.
The percentage of people who clicked the link in a simulated phishing email.
The percentage of people who reported a suspicious message rather than ignoring or clicking it.
The average time between a phishing email arriving and the first person reporting it.
An approach to phishing simulation that responds to a click with a private, educational moment rather than public embarrassment.
The opposite of coaching-first: phishing programs built on embarrassment, failure leaderboards or punitive consequences.
Targeted training that fires automatically when someone clicks a simulated phishing email, matched to the specific attack type they encountered.
Metrics
The percentage of people who report suspicious messages instead of ignoring or clicking them.
The percentage of assigned training that people actually finish.
Measuring how an organization performs against each manipulation tactic — urgency, authority, scarcity, trust, helpfulness and social proof — rather than scoring individual people.
The likelihood that everyday human behavior leads to a security incident.
Delivery & operations
Security training built on psychology rather than fear — people are treated as partners, and clicks become coached learning moments instead of infractions.
The short, friendly micro-lesson someone sees the instant they click a phishing simulation.
Training delivered in short segments — typically a few minutes — on a continuous cadence rather than as an annual block.
A platform architecture that lets a service provider run many client organizations from one console, with client data and reporting kept separate.
Configuring a client’s mail filters so simulated phishing emails reach the inbox instead of being blocked.
Attack types
Phishing delivered over SMS text messages.
Voice phishing — phone calls impersonating IT support, an executive or a vendor.
An attack that impersonates a trusted person — usually an executive or a supplier — to trigger a payment or a data transfer.
Phishing delivered through QR codes, usually in email attachments or printed materials.
Vocabulary is the easy part. Behavior is the job.
Thirty minutes, a live account, and a straight answer about where your people actually stand.