How Often Should Insurance Agency Employees Receive Cybersecurity Training?
An insurance agency should provide formal cybersecurity awareness training at least once every 12 months, short refresher training at least quarterly, and simulated phishing exercises approximately monthly or quarterly, depending on the agency’s risk, cyber insurance requirements, and employee performance.
New employees should complete security training during their first 5–10 business days, before receiving unrestricted access to sensitive systems whenever practical. Employees who fail phishing simulations, mishandle data, or work in high-risk roles should receive additional targeted coaching.
For an insurance agency with 25–50 employees, the strongest program is not a single annual presentation. It is a recurring process that combines training, realistic testing, clear reporting procedures, measurable results, and follow-up coaching.
The 6-Part Cybersecurity Training Framework
- Train every new employee during onboarding.
- Provide comprehensive training annually.
- Deliver short refresher lessons throughout the year.
- Run realistic phishing simulations.
- Provide targeted coaching based on risk and performance.
- Measure, document, and improve the program.
This framework keeps security visible without requiring employees to sit through long sessions every month. The goal is to build reliable habits employees can use during real client and vendor interactions.
1. Train Every New Employee During Onboarding
New employees are especially vulnerable because they are learning unfamiliar systems, names, procedures, vendors, and communication patterns. Attackers may exploit that uncertainty with fake password-reset messages, executive requests, payroll changes, and Microsoft 365 invitations.
New-hire training should occur before or shortly after the employee receives access to:
- Microsoft 365
- Agency-management systems
- Carrier portals
- Shared files
- Client information
- Accounting systems
- Remote-access tools
- Agency email and phone systems
What New Employees Should Learn
Onboarding training should explain:
- How to create and protect passwords
- How multi-factor authentication works
- What to do after receiving an unexpected MFA prompt
- How to identify phishing and impersonation
- How to verify payment and banking changes
- How to handle client and policy information
- Which file-sharing tools are approved
- Whether personal devices are allowed
- How to report a lost device
- How to report suspicious email or account activity
- Who to contact during a suspected incident
Employees should acknowledge the agency’s acceptable-use, data-handling, remote-work, and incident-reporting requirements.
Include Contractors and Temporary Workers
Training should apply to anyone with access to agency systems or sensitive information, including contractors, temporary workers, interns, outsourced accounting staff, and third-party personnel when appropriate.
2. Provide Comprehensive Training at Least Annually
Annual training establishes a common security baseline and provides an opportunity to update employees on new threats, technology, and agency procedures.
A complete annual session should generally take approximately 30–60 minutes. It may be delivered as one course or divided into several shorter modules.
Core Annual Training Topics
- Phishing and malicious links
- Business email compromise
- Password and multi-factor authentication security
- Client-data handling
- Secure file sharing
- Remote-work security
- Mobile-device protection
- Social engineering by phone, text, and email
- Payment and banking verification
- Incident reporting
The training should use examples that match the agency’s daily work rather than generic scenarios that employees do not recognize.
Use Insurance-Specific Examples
Relevant examples may include:
- A fake carrier portal login
- A fraudulent request to change commission deposit information
- An executive impersonation requesting gift cards or a wire transfer
- A client asking for policy documents from a new email address
- A malicious attachment disguised as a claim document
- A fake Microsoft 365 password-expiration notice
- A vendor requesting a last-minute banking change
- A producer receiving an unexpected file-sharing invitation
- A caller pretending to be an employee who needs an MFA reset
Specificity helps employees connect security training to actions they perform every day.
3. Deliver Short Refresher Training Throughout the Year
Employees forget information that they do not use regularly. Short refresher lessons help reinforce important behaviors between annual training sessions.
A practical schedule is one 5–15-minute lesson each quarter. Agencies with elevated risk may deliver monthly microtraining.
Example Quarterly Training Schedule
| Quarter | Training Topic | Practical Outcome |
|---|---|---|
| Quarter 1 | Phishing and suspicious links | Employees recognize and report deceptive messages. |
| Quarter 2 | Payment fraud and impersonation | Employees verify financial changes through a trusted channel. |
| Quarter 3 | Client-data handling and file sharing | Employees use approved tools and correct recipients. |
| Quarter 4 | MFA, password resets, and account compromise | Employees report unexpected prompts and suspicious account activity. |
Training should also be updated when the agency introduces new technology, experiences an incident, identifies a recurring mistake, or observes a new threat affecting insurance organizations.
4. Run Simulated Phishing Exercises
Phishing simulations allow the agency to measure whether employees apply their training when a message looks realistic.
A simulation may test whether employees:
- Open an unexpected message
- Click a suspicious link
- Enter credentials into a fake login page
- Open an attachment
- Reply with sensitive information
- Report the message through the approved process
How Often Should Phishing Tests Run?
A practical testing frequency is:
- Monthly: Appropriate for agencies with elevated risk, recent incidents, poor results, or cyber insurance requirements.
- Quarterly: Appropriate for many agencies with a mature program and stable performance.
- Annually: Usually too infrequent to build and measure consistent habits.
The agency should vary the timing and subject matter so employees do not simply recognize a predictable monthly test.
Test Realistic Insurance Scenarios
Examples include:
- Carrier portal password reset
- Claims document notification
- Policy renewal attachment
- Microsoft 365 storage warning
- Shared file from a producer
- Voicemail transcription
- Executive payment request
- Benefits enrollment notice
- Updated direct-deposit form
- Cyber insurance questionnaire
Simulations should educate employees rather than embarrass them. The purpose is to improve behavior and identify where additional support is needed.
5. Provide Targeted Coaching Based on Risk
Employees do not all face the same threats. Training should reflect the information and authority associated with each role.
High-Risk Roles
Additional training may be appropriate for:
- Agency owners and executives
- Accounting and finance employees
- Human-resources personnel
- Employees who manage payroll
- Employees who process payments
- Employees who change client or vendor banking information
- Microsoft 365 administrators
- Employees with broad access to client records
- Remote employees
- Employees who frequently communicate with outside vendors
Role-Specific Training Examples
| Role | Primary Risk | Training Emphasis |
|---|---|---|
| Executive | Impersonation and account takeover | Payment verification, MFA, confidential requests, travel-related risk |
| Accounting | Wire and invoice fraud | Independent verification, vendor changes, payment approvals |
| Human resources | Payroll and employee-data theft | Direct-deposit changes, tax records, identity verification |
| Producer | Remote and mobile exposure | Public Wi-Fi, mobile devices, client documents, carrier portals |
| IT administrator | Privileged account compromise | Separate admin accounts, MFA, logging, access control |
| Customer service | Client impersonation and document exposure | Identity verification, secure sharing, suspicious requests |
Respond to Failed Simulations Constructively
An employee who fails a simulation should receive prompt education. A useful response may include:
- An immediate explanation of the warning signs
- A short refresher module
- A private coaching conversation after repeated failures
- A follow-up simulation
- Additional controls when the employee manages sensitive functions
Repeated high-risk behavior should be addressed according to agency policy, but fear-based programs can discourage employees from reporting real mistakes.
6. Measure and Document the Training Program
A cybersecurity training program should produce measurable evidence. Documentation may support internal management, cyber insurance applications, client security questionnaires, and incident investigations.
Training Records to Maintain
- Employee name
- Course or session completed
- Completion date
- Assessment score
- Policy acknowledgment
- Phishing simulation results
- Reported phishing messages
- Required remedial training
- Completion of follow-up coaching
Important Program Metrics
| Metric | What It Measures |
|---|---|
| Training completion rate | Whether employees finish required courses on time |
| Simulation click rate | How often employees interact with test phishing messages |
| Credential-submission rate | How often employees enter information into simulated malicious pages |
| Reporting rate | How often employees report suspicious messages correctly |
| Time to report | How quickly suspicious activity reaches the security team |
| Repeat-failure rate | Whether the same employees continue making similar mistakes |
| Remediation completion | Whether required follow-up training is completed |
The agency should not rely on click rate alone. A rising reporting rate and faster reporting time may indicate meaningful improvement even when occasional mistakes continue.
What Should Cybersecurity Training Cover?
Phishing and Malicious Email
Employees should learn to recognize:
- Unexpected login requests
- Urgent language
- Unusual sender addresses
- Lookalike domains
- Unexpected attachments
- Shortened or mismatched links
- Requests to bypass normal procedures
- Messages involving secrecy or pressure
Business Email Compromise
Employees should understand that a message can be fraudulent even when it comes from a real vendor, executive, client, or coworker account. A criminal may have compromised the sender’s mailbox.
High-risk requests should be independently verified, especially when they involve:
- Wire transfers
- Direct-deposit changes
- Banking details
- Gift cards
- Confidential records
- Password resets
- Multi-factor authentication changes
- New payment instructions
Multi-Factor Authentication
Employees should be taught to:
- Approve only expected prompts
- Deny unexpected requests
- Report repeated prompts immediately
- Never share authentication codes
- Protect authenticator applications
- Verify identity before approving an MFA reset
Password Security
Training should reinforce:
- Using unique passwords
- Using an approved password manager
- Never sharing passwords by email or chat
- Reporting suspected exposure
- Avoiding reused personal passwords
- Using separate administrator accounts
Client-Data Protection
Employees should know:
- Which information is sensitive
- Where information may be stored
- Which sharing tools are approved
- How to confirm recipients
- How to dispose of records securely
- When encryption or additional protection is required
- How to report accidental disclosure
Remote-Work Security
Remote employees should understand:
- How to secure home Wi-Fi
- When public Wi-Fi should be avoided
- How to protect screens from viewing
- Why agency devices should not be shared
- How to store printed documents
- How to report a lost or stolen device
- How to contact the help desk securely
Social Engineering by Phone and Text
Attackers may impersonate employees, clients, vendors, Microsoft support, or the agency’s IT provider. Employees should verify identity before:
- Resetting a password
- Changing MFA methods
- Providing account information
- Installing remote-access software
- Sharing client records
- Approving a payment change
Create a Simple Suspicious-Message Reporting Process
Employees are more likely to report suspicious activity when the process is fast and obvious.
The agency may use:
- A report-phishing button in Microsoft Outlook
- A dedicated security email address
- A help desk phone number
- An urgent incident hotline
- A support portal category
The reporting process should clearly distinguish routine support from urgent security incidents.
What Employees Should Report Immediately
- An unexpected MFA prompt
- A password entered into a suspicious page
- A suspicious attachment that was opened
- A lost or stolen device
- An email sent to the wrong recipient
- An unusual payment or banking request
- A caller requesting account access
- Unexpected mailbox behavior
- A suspected malware infection
- A message sent from the employee’s account without permission
Employees should be praised for fast reporting, even when they made the original mistake. Early reporting can significantly reduce the effect of an incident.
How Should the Agency Respond After an Employee Clicks a Real Phishing Link?
- Contact the IT or security team immediately.
- Disconnect the device if instructed.
- Identify whether credentials were entered.
- Reset the affected password through a verified process.
- Revoke active sessions where appropriate.
- Review multi-factor authentication methods.
- Inspect mailbox rules and forwarding.
- Review recent sign-in activity.
- Scan or isolate the device.
- Search for related messages sent to other employees.
- Preserve relevant evidence.
- Document the incident and corrective actions.
A password change alone may not remove an attacker. Active sessions, mailbox rules, connected applications, and unauthorized MFA methods should also be reviewed.
Learn more about layered protection through 911 IT’s cybersecurity services.
How Cybersecurity Training Supports Cyber Insurance
Cyber insurance applications may ask whether the organization provides security awareness training, phishing testing, or role-based education. Requirements vary by carrier, policy, and underwriting process.
The agency should be prepared to document:
- Training frequency
- Who is required to participate
- Completion rates
- Phishing simulation frequency
- Remedial training procedures
- Training topics
- Program ownership
- Records and reports
Answers should reflect the agency’s actual practices. Do not state that monthly testing or annual training occurs unless the agency can demonstrate that the program is active.
Review Requirements Before Renewal
Review the cyber insurance application and required controls at least 60–90 days before renewal. This gives the agency time to correct missing documentation or incomplete training instead of rushing through a last-minute project.
A 12-Month Training Calendar for an Insurance Agency
| Month | Training or Testing Activity |
|---|---|
| January | Annual security training and policy acknowledgment |
| February | Phishing simulation involving Microsoft 365 credentials |
| March | Microtraining on unexpected MFA prompts |
| April | Phishing simulation involving a carrier portal |
| May | Training on payment fraud and vendor banking changes |
| June | Phishing simulation involving an invoice or payment request |
| July | Microtraining on secure client-data sharing |
| August | Phishing simulation involving a shared document |
| September | Training on remote work and mobile-device security |
| October | Phishing simulation and Cybersecurity Awareness Month activity |
| November | Training on holiday fraud and executive impersonation |
| December | Annual metrics review and next-year improvement plan |
New-hire training and targeted remediation should occur throughout the year rather than waiting for the scheduled annual session.
What Should a Cybersecurity Training Policy Include?
A written policy should define:
- Who must complete training
- When new-hire training is required
- Annual training frequency
- Refresher-training frequency
- Phishing simulation frequency
- Required completion deadlines
- Consequences for non-completion
- Targeted training after failed simulations
- Role-based training requirements
- Record-retention procedures
- Program ownership
- Reporting and escalation procedures
The policy should be practical enough to follow consistently. A modest program completed every quarter is more valuable than an ambitious policy the agency does not implement.
Common Cybersecurity Training Mistakes
| Mistake | Potential Result |
|---|---|
| Training occurs only once during hiring | Employees forget procedures and do not learn about new threats. |
| Training is generic | Employees do not connect the material to insurance workflows. |
| Phishing tests occur only once per year | The agency receives limited performance data and weak reinforcement. |
| Employees are embarrassed publicly | They may hide mistakes instead of reporting them quickly. |
| Executives are exempt | High-value accounts and payment authority remain exposed. |
| Contractors are excluded | People with system access may not understand agency procedures. |
| Completion records are missing | The agency cannot demonstrate that training occurred. |
| Only click rates are measured | Reporting behavior and response speed are overlooked. |
| Repeated failures receive no follow-up | High-risk behavior continues without correction. |
| Training is not updated after incidents | The agency misses an opportunity to address real weaknesses. |
A Practical Training Scenario for a 40-Person Insurance Agency
Consider a 40-person independent insurance agency with one office, remote producers, Microsoft 365, a cloud-based agency-management system, and no formal training program beyond a brief annual presentation.
The agency runs its first phishing simulation and finds:
- Nine employees click the link.
- Four enter credentials.
- Only three report the message.
- No employee reports the message within the first 15 minutes.
- Two executives are among the employees who interact with the test.
The agency implements a six-month improvement plan:
- Deliver role-specific phishing and payment-fraud training.
- Add a report-phishing button to Outlook.
- Run monthly simulations with varied scenarios.
- Provide immediate microtraining after each failure.
- Give accounting and leadership additional verification training.
- Review reporting rate and response time each month.
After six months, the agency records:
- A lower click rate
- Fewer credential submissions
- A higher reporting rate
- Faster reporting
- Improved employee confidence
The agency now has measurable evidence of improvement rather than relying on annual course completion alone.
Questions to Ask a Cybersecurity Training Provider
- Can training be customized for insurance agencies?
- How often do you recommend formal training?
- How often can phishing simulations run?
- Can simulations test Microsoft 365 and payment fraud?
- Do you provide immediate education after a failed test?
- Can training be assigned by employee role?
- How are new employees enrolled?
- Can completion deadlines be automated?
- What reports are available?
- Can we track reporting rate and response time?
- How are repeat failures handled?
- Can executives receive specialized training?
- Can the platform support cyber insurance documentation?
- How is employee information protected?
- Who helps us interpret the results?
Questions to Ask Your Managed IT Provider
- Is security awareness training included in our agreement?
- How often is training delivered?
- How often are phishing simulations conducted?
- Who reviews simulation results?
- What happens after an employee fails?
- How are new employees enrolled?
- How do employees report suspicious messages?
- Who investigates reported phishing?
- Can you remove malicious messages from other mailboxes?
- Can you document training for cyber insurance?
- How do you train high-risk roles?
- What metrics will leadership receive?
- How do you coordinate training with Microsoft 365 security?
- How quickly do you respond after a real employee mistake?
- Which services cost extra?
Cybersecurity Training Checklist for Insurance Agencies
- New employees complete training within 5–10 business days.
- All employees complete formal training at least annually.
- Short refresher training occurs at least quarterly.
- Phishing simulations occur monthly or quarterly.
- Training uses insurance-specific scenarios.
- Executives and accounting employees receive role-based training.
- Contractors with access are included.
- Employees know how to report suspicious messages.
- Unexpected MFA prompts are covered.
- Payment and banking verification procedures are covered.
- Client-data handling is covered.
- Remote-work and mobile-device security are covered.
- Failed simulations trigger follow-up training.
- Repeat failures receive additional coaching.
- Training completion is documented.
- Simulation click, reporting, and credential-entry rates are measured.
- Leadership reviews results at least quarterly.
- The program is reviewed before cyber insurance renewal.
- Training is updated after incidents and major technology changes.
- The annual program includes an improvement plan.
Frequently Asked Questions
Is annual cybersecurity training enough?
Annual training is an important baseline, but it is usually not enough by itself. Quarterly refreshers and recurring phishing simulations help employees retain and apply the information.
How often should phishing simulations occur?
Monthly or quarterly testing is appropriate for many insurance agencies. The frequency should reflect the agency’s risk, employee results, recent incidents, and cyber insurance requirements.
How long should cybersecurity training take?
Annual training may take approximately 30–60 minutes. Quarterly refresher lessons can often be completed in 5–15 minutes.
Should executives complete cybersecurity training?
Yes. Executives are frequent impersonation targets and may have access to sensitive information, financial authority, and privileged systems.
Should employees be punished for failing phishing tests?
The first response should usually be education and coaching. Repeated risky behavior may require additional action according to agency policy, but public embarrassment can discourage reporting.
What is a good phishing simulation click rate?
There is no universal target because simulation difficulty varies. The agency should focus on sustained improvement, lower credential submission, higher reporting, and faster reporting.
What should an employee do after clicking a suspicious link?
The employee should report the event immediately and follow the IT provider’s instructions. Fast reporting can allow the security team to reset access, revoke sessions, inspect the device, and limit further damage.
Does cybersecurity training help with cyber insurance?
It may. Carriers may ask about training, phishing testing, and documentation. Requirements vary, so the agency should review the current application and policy with its broker.
Who should manage the training program?
Agency leadership should approve the policy and expectations. A qualified internal IT team, managed service provider, or security provider can operate the platform, testing, reporting, and technical response.
Should training include personal email and devices?
Training should address personal-device and personal-email risks when they could affect agency accounts, passwords, remote work, or client information.
How often should training records be reviewed?
Review completion, phishing results, repeat failures, and reporting trends at least quarterly. Conduct a full program review annually.
Can technical security replace employee training?
No. Email filtering, endpoint protection, MFA, and monitoring are essential, but employees still make decisions involving payments, data sharing, password resets, and unusual requests.
Build Security Habits Through Consistent Training
Insurance agencies should treat cybersecurity awareness as an ongoing business process rather than an annual compliance exercise.
Use the six-part framework:
- Train new employees promptly.
- Provide comprehensive annual education.
- Reinforce key behaviors every quarter.
- Run realistic phishing simulations.
- Provide targeted coaching based on risk.
- Measure and document improvement.
A practical program for a 25–50 employee agency may include annual training, quarterly microtraining, monthly or quarterly phishing simulations, and immediate coaching after risky behavior.
911 IT provides cybersecurity services, managed IT support, Microsoft 365 and cloud services, and business continuity planning for organizations that need layered protection, employee education, and responsive incident support.
Not sure whether your cybersecurity training program is frequent, specific, or measurable enough? Schedule a discovery call with 911 IT to review your training schedule, phishing testing, Microsoft 365 security, reporting process, cyber insurance requirements, and incident response plan.
