CIS Safeguard 14.9: Conduct Role-Specific Security Awareness and Skills Training

CIS Safeguard 14.9: Conduct Role-Specific Security Awareness and Skills Training

By Steve Gold
Posted in Security
On September 15, 2026

In The Bear, every station in the kitchen has a different job, a different set of skills, and a completely different set of things that can go wrong. You do not train the pastry chef the same way you train the expeditor. You do not pull the sous chef aside to explain how to plate a salad. Everyone needs to know the basics, but the role-specific skills are what keep the kitchen from catching fire. Your security training program works the same way.

What Is Conduct Role-Specific Security Awareness and Skills Training?

CIS Safeguard 14.9 is part of CIS Critical Security Control 14, Security Awareness and Skills Training, and it applies to organizations in Implementation Group 2 (IG2) and above. The safeguard requires organizations to:

"Conduct role-specific security awareness and skills training. Example implementations include secure system administration courses for IT professionals, developer training for secure coding, and advanced social engineering training for high-risk profiles."

General security awareness training covers the fundamentals: phishing, passwords, clean desks. Role-specific training goes further. It targets the actual risks that come with a person's specific job function and gives them the skills to handle those risks in context. A developer writing application code faces different threats than an executive approving wire transfers. Treating them identically in training means one of them is unprepared.

Why It Matters

Most breaches have a human element. That is not a new statistic. What is often overlooked is that the human element is not evenly distributed across the organization. Developers introduce vulnerabilities at the code level. Finance teams are targeted by business email compromise. System administrators have the privileged access that attackers want most. Help desk staff get social engineered into password resets.

If your training program treats all of those people the same, you are spending money without managing risk. Role-specific training is how you close the gap between general awareness and functional security competency.

It also matters for compliance. Regulations like HIPAA, PCI-DSS, and SOX increasingly expect organizations to demonstrate that employees with access to sensitive systems or data have received training appropriate to that access.

Key Details or How It Works

  • Role mapping: The foundation of the program. Identify every role in the organization and the specific security risks, responsibilities, and tools associated with that role.
  • Developer training: Covers secure coding practices, OWASP Top 10, input validation, and how to use security testing tools like SAST and DAST. The goal is to shift security left, before vulnerabilities make it into production.
  • IT and system administrator training: Covers privileged access management, hardening, patch workflows, and responding to endpoint alerts. These are the people with the keys to the kingdom.
  • Executive and high-value target training: Covers advanced phishing simulation, business email compromise, wire fraud, and how to verify out-of-band requests. Attackers know who the high-value targets are.
  • Help desk and customer-facing staff training: Covers social engineering tactics, identity verification procedures, and how to handle requests to reset credentials or bypass access controls.
  • Frequency and format: Role-specific training should happen at onboarding and at least annually, with targeted refreshers when new threats or significant role changes occur.

How to Implement Conduct Role-Specific Security Awareness and Skills Training

  1. Map roles to risk profiles. Document every significant role and the security risks that come with it. Developers, admins, finance, executives, help desk, and general users all have different profiles. This is the foundation everything else is built on.
  2. Define training requirements per role. For each role, specify what security knowledge and skills are required, at what depth, and how often training needs to be refreshed. Tie this to the actual threats that role faces.
  3. Source or build role-specific content. Use a combination of vendor-provided training platforms, internally developed scenarios, and hands-on exercises. Generic content is a starting point, not a finish line. Simulated phishing, capture-the-flag exercises for developers, and tabletop scenarios for executives all belong here.
  4. Integrate training into onboarding and role transitions. Role-specific training should not be an afterthought after someone has been in a seat for six months. It should be part of day one for every new hire and triggered automatically when someone moves into a new role with different access or responsibilities.
  5. Track completion and competency, not just attendance. Training records need to show who completed what and when. Better programs include assessments that verify comprehension, not just seat time. Integrate tracking with your HR or LMS platform so records are auditable.
  6. Review and update content at least annually. The threat landscape changes. Your training content should change with it. Review curriculum once a year at minimum, and update immediately when a new threat vector starts hitting your industry.

Final Thoughts

In The Bear, the best kitchens run because everyone knows their station and is trained for it specifically. The risks in a kitchen are not evenly distributed. Neither are the risks in your organization. General awareness training is the baseline. Role-specific training is what actually builds the skills your people need to defend the systems they are responsible for.

Know your roles. Train to them. Test what you taught.

Resources

Here is a link to the Policy Templates provided free of charge from the fine folks at the Center for Internet Security.

Looking for even more detail? Here you go. If this still does not satisfy your curiosity, DM me.

Official CIS Text

CIS Control 14: Security Awareness and Skills Training Establish and maintain a security awareness program to influence behavior among the workforce to be security conscious and properly skilled to reduce cybersecurity risks to the enterprise.

CIS Safeguard 14.9: Conduct Role-Specific Security Awareness and Skills Training Conduct role-specific security awareness and skills training. Example implementations include secure system administration courses for IT professionals, developer training for secure coding, and advanced social engineering training for high-risk profiles.

Shameless Marketing Information

Gotham Technology Group helps organizations design and deliver security awareness programs that go beyond the annual checkbox, including role-specific training tailored to your workforce. Reach out to learn how we can help you build a program that actually reduces risk.

Steve Gold

Steve Gold

Steve Gold is the Cybersecurity Practice Director at Gotham Technology Group (Gotham). He is responsible for providing the vision and thought leadership to expand Gotham’s legacy of success and build a world-class cybersecurity practice. He works closely with Gotham’s customers, industry partners, and subject matter experts to develop relevant solutions for Gotham’s clients and prospects.

Prior to joining Gotham, Steve worked with the Center for Internet Security (CIS), where he expanded the global reach, revenue, and impact of the CIS Benchmarks, CIS Controls, and CIS Hardened Images. He led the efforts to promote the CIS portfolio of low-cost and no-cost cybersecurity products and services that help private and public organizations stay secure in the connected world. He grew a team of security specialists from 12 to over 40 to assist organizations with implementing security best practices in their continual journey of cybersecurity maturity.

During his more than 20-year career, Steve led teams responsible for developing and implementing technology solutions at some of the industry’s most recognized companies such as Varonis, VMware, Dell & Wyse Technology

Steve is a frequent speaker/moderator at industry conferences and webinars, covering a wide array of information security topics. He resides and works remotely in Baltimore, MD.