Security & trust

Training

Building security awareness into how our team works.

Security awareness

Information-security training is required at induction and at least annually. Induction covers policy acknowledgement, incident reporting, authentication, device security, remote working and the handling of classified information.

Annual refreshers cover phishing and social engineering, data protection, current threats and policy changes. This connects security requirements with the situations staff encounter during day-to-day work.

  • Induction introduces security duties during the first week.
  • Annual refresher training reinforces awareness and changing requirements.
  • Staff learn how to recognise and report a security concern.

Training for responsibilities

Training is shaped around the responsibilities people hold. Staff need to understand the information and systems they work with, the controls relevant to their role and how to raise a concern when something goes wrong.

Role-specific training and follow-up support the application of those requirements. Assessment helps reinforce understanding and identify where someone needs additional guidance or support.

  • Match training to development, operations, support and information-handling responsibilities.
  • Use assessment and follow-up to check understanding.
  • Revisit training needs as duties, systems or policies change.

Security awareness for technical work

Technical staff receive secure-development content within the annual refresher programme. This supports the decisions made while building, testing and supporting the platform, alongside the team’s wider security responsibilities.

Application testing, secret management and controlled releases provide practical processes that technical teams use to apply security awareness. Working with test information and limiting access help protect customer services during development and investigation.

  • Apply secure-development awareness during implementation and review.
  • Handle credentials through approved secret-management arrangements.
  • Use isolated testing and controlled promotion when assessing changes.
Explore application development controls

Keeping training accountable

A training register records completion and the next refresher requirement. Policy acknowledgements, assessment and follow-up help maintain a clear record of the security awareness expected for each role.

Training is part of the management system alongside policy review and internal assessment. Changes to threats, responsibilities or working practices can inform future content and additional guidance.

  • Record induction and refresher activity through the training programme.
  • Track follow-up where assessment identifies a need for more support.
  • Use policy and risk changes to inform subsequent training.
Explore policy review
Build with confidence

Secure services start with a conversation.

Talk to our team about your organisation’s security requirements, hosting choices and the services you want to deliver.