CyberTrustWorks — One Platform. Total Trust.

Fussion_GRC domain 8 of 15

Security Awareness

Govern training completion, phishing results and policy acknowledgement across every employee and contractor.

Fussion_GRC consumes data from your existing tools. It does not perform security scanning.

The problem

What problem this domain solves

Security awareness governance tracks whether the right people completed the right training, how they perform in phishing simulations and whether they acknowledged key policies.

Training data in an LMS that nobody reconciles with the HR headcount.
Phishing results not linked to departments or follow-up training.
Policy acknowledgements chased manually before audits.
Contractors left out of training entirely.

For the CISO

Why this matters to the CISO

People remain the most common entry point. Auditors check training completion for joiners and annually; the board wants to know whether behaviour is improving.

Completion and phishing trends with the departments that need attention.

How it works

How Fussion_GRC works in this domain

Fussion_GRC consumes data from your existing tools. It does not perform security scanning. It connects to the tools that already hold awareness data, then does the following:

  1. 01Reconciles training completion against the full HR headcount.
  2. 02Assigns role-based training automatically for joiners and role changes.
  3. 03Links repeat phishing failures to targeted follow-up.
  4. 04Measures behaviour trends per department.

Data in

Exactly where the data comes from

Source toolData receivedTypical sync
LMS (KnowBe4, Proofpoint, Cornerstone)Course completion and scoresDaily
Phishing simulation platformClick, report and credential-submit ratesPer campaign
HRISJoiners, departments, contractorsDaily
Policy modulePolicy acknowledgementsReal time

Typical frequencies; exact intervals depend on each tool's API limits and your configuration. Connector availability varies — see integrations.

Data flow

From your tools to the boardroom

Your existing tools
LMS (KnowBe4, Proofpoint, Cornerstone)
Phishing simulation platform
HRIS
Policy module
Fussion_GRC
  1. 1. HRIS headcount
  2. 2. Fussion_GRC
  3. 3. Training assignment
  4. 4. LMS completion
  5. 5. Phishing results
  6. 6. Evidence
Outputs
Controls & evidence
Risk updates
Owner workflows
Executive reporting
Fussion_GRC consumes data from your existing tools. It does not perform security scanning.

Automation

Automation and workflows

Workflows created

  • Joiner → training assigned → reminders → manager escalation
  • Phishing failure → micro-training → re-test
  • Policy update → acknowledgement campaign

Actions for leaders

  • Escalate overdue training to managers
  • Approve the annual training plan
  • Review high-risk departments

Controls & evidence

Controls and evidence

Controls are defined once and mapped across frameworks. See supported frameworks.

Controls

  • Security training within 30 days of joining
  • Annual refresher training
  • Regular phishing simulations
  • Policy acknowledgement

Evidence generated

  • Completion reports reconciled to HR
  • Phishing campaign results
  • Acknowledgement records
  • Training content versions

AI assistance

How Fussion AI helps

Answers come from your own Fussion_GRC data, with sources. Learn about Fussion AI.

Questions you can ask

  • "Which departments have the lowest training completion?"
  • "Is our phishing performance improving?"
  • "Draft a reminder to managers with overdue staff."
Fussion AIIllustrative
Which departments have the lowest training completion?
Based on the latest data from LMS (KnowBe4, Proofpoint, Cornerstone) and Phishing simulation platform, here is what needs attention:
  • Training data in an LMS that nobody reconciles with the HR headcount.
  • Phishing results not linked to departments or follow-up training.
  • Policy acknowledgements chased manually before audits.

Every point links to its source record. Recommendation only — a named owner approves decisions.

Dashboard

Dashboard example

Roles

Who uses this domain

CISO

People remain the most common entry point. Auditors check training completion for joiners and annually; the board wants to know whether behaviour is improving.

CIO

Sees how awareness affects IT services, investment priorities and the systems the business depends on.

Security Manager

Runs day-to-day awareness operations from one queue instead of separate tool consoles.

GRC Manager

Maps awareness controls to frameworks, tracks evidence freshness and prepares audits.

Control Owner

Managers see their team's outstanding training and acknowledgements.

Auditor

Completion evidence reconciled against HR records, including joiners and contractors.

Technical Owner

Receives specific, prioritised tasks in Jira or ServiceNow with the context needed to fix them.

Executive

Completion and phishing trends with the departments that need attention.

Integrations

Tools you can connect

  • KnowBe4
  • Proofpoint
  • Cornerstone
  • Workday
  • Darwinbox
  • Microsoft Teams

Named tools show typical sources; availability may be planned, roadmap or custom connector. Confirm during a demo.

See all integrations

Outcomes

Business outcomes

Completion and phishing trends with the departments that need attention.
Completion evidence reconciled against HR records, including joiners and contractors.
Managers see their team's outstanding training and acknowledgements.
Less manual effort: 4 processing steps and 3 workflows run automatically instead of in spreadsheets.

Example

Example workflow

  1. 1
    System

    New signal from LMS (KnowBe4, Proofpoint, Cornerstone)

  2. 2
    Fussion_GRC

    Reconciles training completion against the full HR headcount.

  3. 3
    Control owner

    Joiner → training assigned → reminders → manager escalation

  4. 4
    GRC manager

    Evidence attached: Completion reports reconciled to HR

  5. 5
    CISO

    Escalate overdue training to managers

FAQ

Frequently asked questions

Do we need a new training platform?

No. Fussion_GRC reads from your existing LMS and phishing tools.

Are contractors included?

Yes, as long as they are present in your HR or identity system.

Does Fussion_GRC scan our environment?

Fussion_GRC consumes data from your existing tools. It does not perform security scanning.