← All posts
GuideSeptember 1, 2026 · 11 min read

New Hire Security Training: Onboarding That Sticks

Why the first 90 days are the riskiest, what regulators require at hire, and a six-step onboarding model that builds reporting habits instead of ticking a box.

A day-one onboarding checklist card with a highlighted 90-day risk window on a navy NOUSEC-branded background

A new employee's first week is a strange combination of maximum exposure and minimum defenses. They have just been given a mailbox, a laptop, a collaboration login and a set of credentials to a dozen systems — and they know almost nothing about how the organization actually communicates. They cannot tell whether the "quick favor" from the CEO is normal, whether the HR portal link is the real one, or whether the vendor asking to update bank details is a supplier the company even uses. Everything is unfamiliar, and unfamiliar is precisely the condition social engineering needs.

Most onboarding programs treat security as one more compliance module in a queue of twenty. This guide argues for treating it as the single highest-leverage training moment in an employee's tenure: what regulators actually require at hire, why the first 90 days deserve a different design from annual training, and a six-step model that builds a reporting habit rather than a completion record.

The 90-day window is measurably different

The case for a dedicated onboarding program rests on a simple observation: tenure changes susceptibility. Vendor simulation data makes the size of the gap visible. Keepnet's 2025 New Hires Phishing Susceptibility Report, drawn from simulation results across 237 companies according to Help Net Security's summary, found that 71% of new hires clicked on a simulated phishing email within their first 90 days, that new hires were 44% more likely to fall for phishing and social engineering than longer-tenured staff, and — most tellingly — 45% more likely to click on emails impersonating the CEO. As with any single vendor dataset, treat the exact figures as a benchmark band rather than a universal constant; the direction is what matters, and it is consistent with what security teams see in their own numbers.

The attackers have noticed the same thing. In July 2025 the US Federal Trade Commission published a consumer alert, New job? How to spot boss imposter scams, describing a pattern in which scammers watch social media for job announcements and then contact the new starter posing as their manager or HR — often before the first day — with urgent requests for gift cards or personal and banking details. The FTC's advice is the same advice a good onboarding program teaches: "your employer might need your Social Security or bank account number for your new job, but the new boss or HR aren't likely to call, text, or email you out of the blue."

Why does tenure matter so much? Three things a new hire lacks:

  • A baseline of normal. Experienced staff detect pretexting because the request deviates from a pattern they know. New hires have no pattern yet — every request is equally plausible.
  • Relationships to verify against. A tenured employee can walk over to the CFO's desk. A new hire may never have spoken to the CFO and will hesitate to "bother" them to confirm a message.
  • Permission to say no. New employees are optimising for being seen as responsive and cooperative. CEO fraud is built on that instinct.

None of these are knowledge gaps that a policy PDF fixes. They are situational, and the onboarding program has to be designed for the situation.

A new hire is the only employee who cannot tell a strange request from a normal one — and the attacker knows their start date.

What the frameworks actually require at hire

Security onboarding is rarely optional, though it is often treated as if it were. The main frameworks are unusually explicit about timing:

Framework What it says about new starters Practical implication
NIST SP 800-53 Rev. 5, AT-2 Literacy training "as part of initial training for new users" and at an organization-defined frequency thereafter Training is a precondition of being a system user, not a follow-up
PCI DSS v4.0.1, Req. 12.6.3 Personnel receive security awareness training "upon hire and at least once every 12 months"; 12.6.3.1 requires content on phishing and social engineering Anyone touching cardholder data is trained before they do so, with a record
HIPAA, 45 CFR 164.530(b)(2)(i)(B) Training "to each new member of the workforce within a reasonable period of time after the person joins" "Reasonable" is undefined; regulators judge it against what the person could access in the meantime
ISO/IEC 27001:2022, Annex A 6.3 Personnel "shall receive appropriate information security awareness, education and training" relevant to their job function Auditors check whether new starters were trained before or immediately after being granted access
NIST SP 800-50 Rev. 1 (2024) A life-cycle model for cybersecurity and privacy learning programs, with role-based training and measurement of impact Onboarding is the entry point of a continuous program, not a standalone event
NIS2, Art. 21(2)(g) "Basic cyber hygiene practices and cybersecurity training" as a minimum risk-management measure Workforce training is a baseline control for in-scope EU entities

The common thread is that training is expected to happen at or before the point of access. That is a stronger requirement than most onboarding programs meet, where the security module often sits in a learning-management queue that a new hire may not reach until week three — long after their mailbox went live. If your organization is in scope for SOC 2, ISO 27001 or PCI DSS, the gap between access date and training date is exactly the kind of evidence an assessor will pull.

Why annual training design fails at onboarding

The obvious solution — assign the annual awareness course on day one — is the one most organizations use, and the evidence suggests it does little. In an eight-month study of roughly 19,500 employees, Ho et al. (IEEE S&P 2025) found no significant relationship between recent completion of annual training and the likelihood of failing a simulated phish, and observed that around 75% of employees spent under a minute on the embedded training they were shown. Onboarding week makes this worse: the security module competes with benefits enrollment, expense policy, the code of conduct and a dozen tool walkthroughs. Attention is the scarcest resource an onboarding program has, and a 45-minute generic course spends it badly.

Timing and decay matter too. Reinheimer et al. (SOUPS 2020) found that phishing-detection ability improved sharply right after training but had lost statistical significance by six months. For a new hire, that means the knowledge from a day-one course is fading at roughly the moment they become confident enough to stop asking questions — which is the point in tenure where the Keepnet data suggests susceptibility is still elevated.

The SANS 2025 Security Awareness Report, based on more than 2,700 practitioners, adds the staffing constraint: 80% of organizations rank social engineering as their top human risk, yet most programs have well under the 2.8 full-time equivalents SANS found necessary to change behavior. Onboarding cannot be a manual, bespoke effort for every start date. It has to be a designed sequence that runs itself and reports back.

A six-step onboarding model for the first 90 days

The model below is built around one goal: by day 90, the new hire should have reported something suspicious at least once, and should know that reporting was welcomed. Everything else supports that.

1. Train the three behaviors before access, not the policy after

Before the mailbox and collaboration tools are activated, run a focused 15–20 minute session that teaches three things and nothing more: how to verify any request involving money, credentials or data (call back on a known number, never on the number in the message); how to report a suspicious message and what happens when you do; and the short list of things the company will never ask for by email, text or chat — gift cards, one-time codes, password resets, personal banking details. Tie completion to provisioning so the record is generated automatically, which is what PCI DSS 12.6.3 and HIPAA assessors will later ask to see.

2. Give them a person, not a portal

Every new hire should be introduced, by name, to two people in week one: their team's security champion and the contact who answers "is this real?" questions. The FTC's boss-imposter pattern works because the new starter has no one to check with. A named colleague who explicitly says "message me about anything that feels off — it is never a bother" removes the social cost of verification at the moment it is highest.

3. Layer role-based content in week two

Once the generic behaviors are in place, add the module that matches the job. Finance and accounts payable get invoice fraud and vendor bank-change verification. Help desk and IT get caller identity verification and the help desk fraud playbook. HR and recruiting get payroll-diversion and employment scam patterns. Executives and their assistants get whaling and deepfake voice. Role-based training is what NIST SP 800-50r1 and ISO 27001 A.6.3 mean by "relevant for their job function", and it is where most of the value lives.

4. Simulate early, and make the debrief about reporting

Send a realistic simulation in the first month — a "welcome to the team, can you do me a quick favor" from the manager is the most faithful to what attackers actually send. The purpose is not to catch the new hire out; it is to give them a safe first experience of reporting. Whatever they do, the follow-up should be warm and short: if they reported, say so publicly to their manager; if they clicked, the just-in-time moment is a 60-second explanation of what to look for next time. Run a phishing simulation again around day 60 and day 90 to check whether the behavior held.

5. Reinforce with nudges, not modules

Between day 15 and day 90, the most effective touchpoints are small: a two-line message when the new hire first receives an external email with an attachment; a reminder in the expense tool that gift cards are never a valid purchase request; a banner on the first calendar invite from outside the domain. These security nudges cost seconds of attention rather than minutes and arrive at the moment the behavior is relevant, which is what the decay research says training needs.

6. Measure the cohort, and feed the score

Track new hires as a cohort: simulation report rate, time-to-report, first real report, and completion-to-access gap in days. A program that works shows the 0–90 day cohort converging toward the tenured population's report rate by the end of the window. Feed these signals into each employee's human risk score so that a new hire in a high-exposure role — finance, help desk, admin access — is visible as elevated risk until the data says otherwise, and so the security team can prioritise where a champion's attention goes.

Three mistakes that undo the program

Treating completion as the metric. A 100% completion rate on the day-one module tells you the LMS works. It says nothing about behavior, and the training ROI evidence is clear that completion does not predict resilience. Measure reporting.

Punishing the first click. A new hire who is embarrassed by their first simulation learns to stay silent, which is the worst possible outcome — the Verizon DBIR still puts the human element in 62% of breaches, and silence is what turns a click into an incident. Make the first debrief the safest conversation of onboarding.

Stopping at day one. The framework requirement is met on day one; the risk is not. The Keepnet figures cover 90 days, and the decay research says whatever was taught on day one is fading by month six. Onboarding is the start of a continuous program, and a security culture is built in the weeks after the checklist is signed.

Done well, security onboarding is not a compliance module. It is the moment the organization tells a new colleague what normal looks like, who to ask when it doesn't, and that asking is always the right call.

Sources

Frequently asked questions

Should security training happen before or after a new hire gets system access?

Before, or at least in the same session. NIST SP 800-53 (control AT-2) requires literacy training 'as part of initial training for new users', and ISO 27001 auditors check whether new starters are trained before or immediately after access is granted. Practically, the core module — how to verify a request, how to report a suspicious message, what the company will never ask for — should be completed before email and collaboration tools are activated. Role-specific training can follow in the first weeks.

How long should new hire security training be?

Shorter than most programs make it. Onboarding week is the highest-cognitive-load period of an employee's tenure, and one long compliance video competes with dozens of other modules. Aim for a focused 15–20 minute core session on day one that covers three behaviors, a role-based follow-up in week two, and short reinforcement touchpoints through day 90. The evidence on annual training shows length and completion do not predict phishing resilience; timing and repetition do.

Why are new employees more likely to fall for phishing?

They do not yet know what normal looks like. A new hire cannot tell a strange request from a routine one, does not recognise the real CFO's writing style, does not know which portals are legitimate, and is strongly motivated to appear helpful and responsive. Attackers exploit exactly this: they watch job-change announcements on social media and impersonate the new boss or HR in the first days, a pattern the FTC warned about in July 2025.

How do we prove onboarding training happened for an audit?

Keep a per-person record with the date of hire, the date of system access, the date each module was completed, the policy acknowledgment, and the results of any onboarding simulation. Frameworks that require training at hire — PCI DSS 12.6.3, HIPAA 45 CFR 164.530(b), ISO 27001 A.6.3 — all expect a defensible record, not just a certificate. Tie completion to access provisioning so the record is generated automatically rather than reconstructed later.

See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo