Security Awareness Training and Testing Policy

POLICY #: CR 26-7

DATE OF BOARD OF TRUSTEES APPROVAL: 9/28/2026

RESOLUTION #: 26-7

Purpose:

This policy establishes Herkimer County Community College’s (HCCC) Information Security Awareness and Training Program to ensure that members of the College community understand their information security responsibilities and are equipped to recognize, prevent, and appropriately respond to information security threats and incidents.

Technical security controls are an essential component of the College’s information security framework but, by themselves, cannot fully protect the College’s information assets. Effective information security also depends on the awareness, vigilance, and active participation of the College community. This is particularly important in addressing social engineering, phishing, and other threats that exploit human behavior rather than technical vulnerabilities.

Without adequate information security awareness and training, employees and students may be less likely to recognize and respond appropriately to security threats and incidents, increasing the risk of unauthorized access, disclosure, loss, or compromise of College information assets. The College therefore must ensure that all individuals with access to College information and Information Technology (IT) Resources receive relevant, timely, and appropriate information security awareness and training and understand their responsibility to help protect those resources.

Scope:

This policy and all policies referenced herein, shall apply to all members of the College community, including employees, students, alumni, authorized guests, and independent vendors who use, access, or otherwise employ, locally or remotely, the College’s IT Resources, whether individually controlled, shared, stand-alone, or networked. This policy will be updated and re-issued at least annually to reflect, among other things, changes to applicable law, updates or changes to HCCC requirements, technology, and the results or findings of any audit.

All personnel is personally accountable for completing required information security awareness and training activities and for complying with applicable College policies, laws, regulations, and contractual obligations at all times. All supervisors are responsible for ensuring that employees, student, and vendors under their supervision participate in required information security awareness, training, and educational activities.

The HCCC IT Department shall monitor compliance with this policy and report training completion, awareness results, and social engineering exercise results to the Cabinet, as appropriate. Reports shall focus on identifying trends, risks, and opportunities for improving the College’s overall information security awareness. Consequences for non-compliance with this policy are described in Appendix A.

Policy Requirements:

All information security awareness and training activities must meet the following requirements:

  • The Director of IT shall ensure that all employees and students receive appropriate training to establish and maintain a basic understanding of information security responsibilities. Training shall address, as applicable, the College’s information security policies, standards, procedures, guidelines, applicable laws and regulations, contractual obligations, and generally accepted standards of ethical and acceptable behavior.
  • Additional or specialized training shall be provided to individuals whose job responsibilities require information security knowledge or skills beyond the basic awareness training. This may include, as appropriate, personnel responsible for information risk and security, physical/site security, IT, network administration, or other specialized functions. Additional training requirements shall be identified based on job responsibilities, applicable risks, prior experience, professional qualifications, and anticipated job requirements. Departments are responsible for supporting and funding required specialized training, as appropriate.
  • Security awareness and training shall begin as soon as practicable after a faculty member, staff member, or student is granted access to College information or IT Resources. For employees, this should generally occur as part of the onboarding or orientation process. Awareness activities shall continue on a recurring basis to reinforce security practices and maintain an appropriate level of awareness.
  • Training shall be appropriate to the intended audience and may vary based on the individual’s role, responsibilities, access to information and IT Resources, and level of technical knowledge. The College may use a common foundational awareness program for all members of the College community while providing additional or role-specific training when warranted by the individual’s responsibilities or level of access.
  • HCCC shall provide faculty, staff, and students with information regarding the location and availability of security awareness training materials, as well as applicable information security policies, standards, procedures, and guidance.
  • Training content and delivery methods will be reviewed periodically and updated as necessary to address changes in technology, emerging threats, applicable requirements, audit findings, and identified areas of risk.

HCCC Information Security Awareness Training:

The HCCC IT Department requires all employees to successfully complete assigned KnowBe4 security awareness training upon hire and at least annually thereafter. Employees with job responsibilities that present additional information security risks or require specialized knowledge may be required to complete additional training modules upon hire and at least annually thereafter. Employees will be provided a reasonable amount of time to complete required training while minimizing disruption to normal College operations.

Simulated Social Engineering Exercises:

The HCCC IT Department shall conduct periodic simulated social engineering exercises to assess awareness and readiness and to identify opportunities for improvement. Exercises may include, but are not limited to, simulated phishing (email), vishing (voice), smishing (SMS), removable media/USB testing, and physical security assessments.

Exercises may be conducted throughout the year without advance notice and without a predetermined schedule or frequency. The HCCC IT Department may conduct targeted exercises involving specific departments, roles, or individuals when warranted based on a documented risk assessment or identified security concern.

Remedial Training Exercises:

Employees who do not successfully complete required security awareness training or who demonstrate a heightened risk through training results or simulated social engineering exercises may be required to complete remedial training. Remedial training may include additional courses, targeted awareness activities, or exercises conducted in coordination with the HCCC IT Department. Remedial requirements shall be determined based on the nature and severity of the identified risk.

Non-Compliance Actions:

Certain actions or failures to take required actions by HCCC personnel may result in a non-compliance event (failure).

A failure includes, but is not limited to:

  • Failure to complete required information security awareness training within the allotted timeframe.
  • Failure of a simulated social engineering exercise.

A failure of a simulated social engineering exercise includes, but is not limited to:

  • Clicking a URL contained in a simulated phishing message.
  • Replying to a simulated phishing message with any information.
  • Opening an attachment included in a simulated phishing message.
  • Enabling macros contained in an attachment used as part of a simulated phishing exercise.
  • Allowing an exploit code to execute as part of a simulated phishing exercise.
  • Entering information or other data into a landing page associated with a simulated phishing exercise.
  • Providing or transmitting information during a simulated vishing exercise.
  • Replying to a simulated smishing exercise with any information.
  • Connecting or inserting a USB device or other removable media as part of a social engineering exercise.
  • Failing to follow applicable HCCC policies or procedures during a social engineering exercise.

A single social engineering exercise may result in multiple failure events. However, no more than two failure events may be counted for an individual for any single social engineering exercise.

The HCCC IT Department may determine, on a case-by-case basis, that a reported failure constitutes a false positive or otherwise should not be counted toward an individual's total failure count. Any such determination shall be documented as appropriate.

Compliance Actions:

Certain actions or failures to take an action by HCCC personnel may result in a compliance event (pass). A pass includes, but is not limited to:

  • Successfully identifying or recognizing a simulated social engineering exercise.
  • Not taking an action that would constitute a failure during a simulated social engineering exercise.
  • Reporting an actual or suspected social engineering attack to the HCCC IT Department or through an approved reporting mechanism.

Removing Failure Events through Passes:

Each failure shall result in remedial training or coaching, as described in Appendix A of this policy. Subsequent failures may result in escalation of the required training or coaching. De-escalation shall occur after an individual successfully completes three consecutive passes. Upon achieving three consecutive passes, the individual's compliance status shall be returned to the applicable level established for individuals without recent failure events.

Chief Information Security Officer/Chief Information Officer:

The Chief Information Security Officer (CISO) / Director of IT is accountable for maintaining an effective information security awareness and training program that informs and motivates workers to protect HCCC’s information assets and those of its customers. The CISO / Director of IT is also responsible for developing, maintaining, and overseeing a comprehensive suite of information security policies, standards, procedures, and guidelines, including this policy. In coordination with appropriate College functions, the CISO / Director of IT will provide information security awareness, training, and educational activities that promote understanding of employees’ responsibilities under applicable College policies, laws, regulations, and contractual obligations.

Appendix A – Corrective Actions for Non-Compliance:

The following table outlines the consequences associated with non-compliance with this policy. An individual's accumulated Failure count shall reset to zero on January 1 of each calendar year. Failure events occurring on or after January 1 shall be counted toward the new calendar year's Failure count. The HCCC IT Department may take additional actions not specifically identified in this table when necessary to reduce or mitigate information security risks to the College.

Failure count and resulting level of remediation action
Failure Count Resulting Level of Remediation Action
First Failure Mandatory completion of Phishing Your Inbox.
Second Failure Mandatory completion of Security Awareness Training - 45 minutes.
Third Failure In person meeting with direct supervisor
Fourth Failure In person meeting with their direct supervisor and Director of IT
Fifth Failure In person meeting with their supervisor, Director of IT, and Director of Human Resources. Additional administrative and technical controls may be implemented to prevent further failure events.
Sixth Failure Meeting with President, Director of IT, Director of HR, and Union Representative. Possibility that additional administrative and technical controls will be implemented to prevent further failure events.
Seventh Failure Disciplinary action up to and including termination of employment. Please refer to the applicable bargaining unit contract.

Appendix B – Methods for Determining Staff Risk Ratings:

The following is a list of situations that may increase a risk rating of a HCCC employee. Higher risk ratings may result in an increased sophistication of social engineering tests and an increase in frequency and/or type of training and testing.

  • Employee email resides within a recent Email Exposure Check report.
  • Employee is an executive (High value target).
  • Employee possesses access to significant HCCC confidential information.
  • Employee uses a Windows or Apple-based operating system.
  • Employee uses their mobile phone for conducting work-related business.
  • Employee possesses access to significant HCCC systems.
  • An employee’s personal information can be found publicly on the internet.
  • Employee maintains a weak password.
  • Employee has repeated HCCC policy violations.

Appendix C - Referenced Documents:

Documents that are relevant to this policy include the following:

Referenced documents and their policy owners
Policy Policy Owner
Information Security Protocol Information Security
Faculty/Staff Handbook Human Resources