Back to Home

Solutions · Security awareness programs

Awareness tells them. The prompt box is where they listen.

Annual training says "don't paste client data into AI." Eleven months later, at 4:55 p.m., that guidance is competing with a deadline. A control at the moment of paste is what makes the training real.

The duty you carry

Awareness programs are judged on behavior change, and AI misuse is now the behavior auditors ask about. The frameworks are consistent: ISO 27001 and SOC 2 treat awareness as one control among several, never a substitute for enforcement. A prompt-level checkpoint does two things for a program. It prevents the incident during the teachable moment — a nudge at the paste beats a module eleven months prior. And it produces the metric — attempts caught, trends by team, repeat patterns — that turns "we trained everyone" into evidence the training works.

The moment it breaks

Synthetic example. The real version happens on your busiest day.

TypedQuick favour — dedupe this export for me: customers_q3_full.csv (it has names, emails, and card last-4 for about 18,000 accounts).
SentQuick favour — dedupe this export for me: [FILE] (it has [PII] for about 18,000 accounts).

The employee gets a nudge and a clean path forward. The export never leaves — and your program gets a data point instead of an incident.

Caught, in your vocabulary

Credentials and secrets

Passwords, keys, and tokens pasted for a quick fix — the shortest path from helpful to breached.

Customer PII in exports

The spreadsheets and CSVs people paste whole, names and card digits included.

Internal documents and plans

Strategy, financials, and HR material that ends up in prompts because summarizing is what AI is best at.

The rules you answer to

01

ISO 27001 and SOC 2

Both expect awareness plus technical controls. A prompt-level checkpoint is the enforcement half auditors look for.

02

Privacy breach duties

Prevention at the prompt turns would-be notifiable incidents into coaching moments with a log entry.

03

Program measurement

Catches by team and trend lines are the awareness metrics leadership actually understands — and budget follows measurement.

Also relevant: NIST AI RMF · ISO/IEC 42001

Answers for your situation

All guides

What the rules say

Can federal government suppliers use generative AI with Protected B information?

Not into a public AI tool. Suppliers are bound by the security requirements in their contract and by the Contract Security Program, which only allow protected information to be processed on IT systems the program has approved and only by people with the right screening and a need to know. The Treasury Board guide on generative AI speaks to public servants rather than suppliers, but it points the same way and is a sensible floor for what a department will expect of its contractors.

Read the guide

Governance in practice

Our cyber insurance renewal is asking about AI controls: how do we answer?

Answer only what you can support with evidence. Renewal applications increasingly ask whether you know which AI tools staff use, whether a written AI policy exists, whether technical controls stop sensitive data from reaching those tools, and whether staff are trained. Gather the inventory, policy, training records, and control records before you fill in the form, and ask your broker how the insurer treats answers you cannot fully support.

Read the guide
Our interns and co-op students use their personal AI accounts for work. What should we do?

Assume they will use AI, and plan for it from day one. Privacy law makes the host organization responsible for training the people who handle personal information and for safeguarding it, whether that person is a permanent employee or a four-month co-op student. Give interns a clear rule on what never goes into AI, an approved tool for ordinary tasks, and a safety net that catches sensitive data before it leaves.

Read the guide

From our research