In its Baseline cyber security controls for small and medium organizations, the Canadian Centre for Cyber Security writes that "human error while using information systems remains an element of too many cyber security incidents" and that "as a first line of defence, organizations should train employees on basic security practices."
Short answer
You describe your team, your tools and your concerns: your request is reviewed by the Courtier TI team, then entrusted to the IT services company that will prepare your quote. The content, format and simulations are set with you.
What a training mandate can cover
- Basic training for all staff, new and existing
- Role-based modules: payments and accounting, system administrators, management
- Managed phishing simulations, followed by explanations
- A simple reporting procedure, tested with employees
- Short online refreshers and a component for onboarding new hires
- Follow-up: participation, reports received and topics to reinforce
The minimum topics to cover
According to the Canadian Centre for Cyber Security publication Offer tailored cyber security training to your employees (ITSAP.10.093), training should include at least the following topics:
- Identifying and handling phishing attempts
- Strengthening passwords
- Updating and patching systems
- Securing IT assets and sensitive information
- Reporting incidents
The Centre's baseline controls add the use of approved software, appropriate use of the Internet and safe use of social media. We recommend illustrating each topic with your own tools and realistic situations for your industry, such as a fake invoice or a request to change a supplier's banking details.
How a training program works
- Assessment: your tools, sensitive roles, existing policies and any incidents or attempts you have already faced.
- Choosing formats: the Centre mentions basic training for all staff, computer-based training for refreshers and role-based training.
- Tailoring the content: examples drawn from your reality, in French and in your team's other languages as needed.
- Sessions and practical exercises: the Centre suggests practical exercises such as learning to spot phishing emails or reviewing incident response processes.
- Simulations: fake emails sent under agreed rules, followed by a short explanation.
- Follow-up and updates: results, topics to revisit and new scenarios as threats change.
Phishing simulations: setting the right rules
In its Foundational cyber security actions for small organizations (ITSAP.10.300), the Centre asks whether the organization has a phishing awareness program. Simulations are often part of one. To make them helpful rather than harmful, we recommend:
- Announcing that the program exists, without revealing when emails will be sent
- Treating a click as a chance to learn, never as a fault to punish
- Limiting access to individual results and how long they are kept: they are personal information about your employees
- Coordinating with whoever manages IT so fake emails are neither blocked nor mistaken for a real attack
- Measuring reports as well, not just clicks
From reporting to the incident register
An employee who quickly reports a suspicious email or a misdirected message gives the business time to react. Québec's Act respecting the protection of personal information in the private sector requires a register of confidentiality incidents (s. 3.8) and, if an incident presents a risk of serious injury, prompt notice to the Commission d'accès à l'information and to the persons concerned (s. 3.5).
Training should therefore make clear what to report, to whom and how, and remind staff not to delete the suspicious message. In its publication on generative AI (ITSAP.00.041), the Centre recommends giving users an easy way to report phishing attacks or suspicious communications. Our guide Law 25: what Quebec SMBs must do on the IT side explains the register.
Questions to ask yourself before requesting a quote
- How many people need training, in which roles, and who works remotely or in the field?
- Which training languages are needed?
- Which tools does your team use daily: email, Teams, mobile phones, line-of-business software?
- Have you already faced a fraud attempt or incident that could serve as an example?
- Is there a reporting procedure and a designated person to receive reports?
- Do you want phishing simulations, and who will see the results?
Pitfalls to avoid
- A single session, then nothing: habits fade and attacks change
- Generic content that looks nothing like your tools or suppliers
- Simulations perceived as a trap, which discourage reporting
- Leaving out management and contractors: the Centre targets all personnel, including contractors, managers and executives
- Teaching staff to report without naming who receives reports or what happens next
What to specify in your request
- The approximate number of people and their roles
- The preferred format: in person, remote, self-paced online, or a mix
- Training languages
- Whether you want phishing simulations and results tracking
- Priority topics, such as payment fraud, remote work or AI
- Your email platform and whether a report button or address exists
- Client, insurer or contract requirements to meet
Frequently asked questions
Who should take security awareness training?
Everyone. The Canadian Centre for Cyber Security publication ITSAP.10.093 covers all personnel, including employees, contractors, managers and executives. People who approve payments or administer systems benefit from additional role-based training.
How often should employees be trained?
The Centre does not set a frequency. It describes basic training for new and existing personnel and computer-based training to refresh key topics. We suggest training at hiring, short refreshers spread over the year and an update whenever a new form of attack hits your industry.
Are phishing simulations a good idea?
Yes, when they are well managed. The Centre suggests practical exercises such as learning to spot phishing emails. Announce the program, explain each mistake without punishing it, protect individual results and reward reporting.
Does Quebec's Law 25 require employee training?
The Act requires reasonable security measures (s. 10) and policies that define the roles and responsibilities of staff throughout the life cycle of personal information (s. 3.2). It does not prescribe specific training, but training staff is a concrete way to apply these rules and to feed the incident register properly.
Should training cover artificial intelligence?
It is a good idea. The Centre mentions awareness training on artificial intelligence technologies, and notes that generative AI enables more realistic phishing emails. If your employees use these tools, training can also present your internal rules. See our page AI governance and oversight.