Aligned to NIST SP 800-50 Rev. 1

Most breaches start with one person and one click.

Six in ten breaches last year involved a person, according to the Verizon 2025 DBIR, and stolen passwords led the way. A firewall cannot stop an employee from handing over a login. Training can. DMS keeps a dated record of who finished, so when your insurer asks at renewal whether you train your people, you can prove you do.

Every roleA track built for how each person gets attacked
Per employeeVerifiable certificate on completion
12 monthsAudit and renewal ready records
QuarterlyCadence and completion built in
See the training

Watch a scene from the all-staff module.

Every employee takes the all-staff core first. Finance, executives, HR, developers, and IT then get a track built around how their job gets targeted. Below is one all-staff scene on passwords. The captions carry it, so turn the sound off if you are at your desk.

All-staff

What NIST says about passwords in 2025

NIST dropped forced ninety-day resets and the symbol-and-number rules years ago. Length is what holds up. This scene teaches SP 800-63B, the guidance most workplaces still have not caught up to.

The role tracks

Finance moves money. IT holds the admin keys. Each track covers the attack those people face, from wire fraud to credential theft.

Finance

Business email compromise and the call back that stops a fraudulent wire before it leaves.

Executives

Targeted impersonation and voice phishing, including the urgent ask that lands while you travel.

Human Resources

Opening resumes and files from people you do not know, without letting an attacker in.

Developers

Secure development habits, drawn from real incidents like Log4Shell.

IT and privileged access

Protecting elevated access, from MFA fatigue to admin credentials left in code.

The sample is one scene from a real module. The platform tracks completion and issues a certificate to everyone who finishes.

Why it works

You cannot patch a person. You can train one.

The Verizon 2025 Data Breach Investigations Report found the human element in roughly six of every ten breaches, with stolen and misused credentials a leading way in. That is the gap firewalls do not close. NIST treats awareness and role-based training as a managed program in SP 800-50 Revision 1, and maps it to the Awareness and Training controls, AT-1, AT-2, and AT-3, in SP 800-53. DMS is that program, ready to run.

~60%of breaches involve the human element, Verizon 2025 DBIR
AT-1 / 2 / 3the NIST 800-53 controls this program satisfies

What "current" looks like, using passwords as the example

Length over complexity. A 15 character minimum for a password used on its own, support for up to 64.
No scheduled resets. Change a password when there is a sign it was exposed, not every ninety days.
Block what is already breached. Known-compromised passwords get rejected the moment a user picks one.
No more security questions. No hints, no mother's maiden name.

Source: NIST SP 800-63B, Digital Identity Guidelines, Section 3.1.1.2. Our all-staff module teaches it.

Compliance

One program. The training line on most of your audits.

Security awareness training is not a nice to have in these frameworks. It is named, by citation, in each one. DMS gives you the training and the dated, per-employee records that show it happened.

HIPAA Security Rule
45 CFR 164.308(a)(5)(i)

A security awareness and training program for the workforce.

PCI DSS v4.0
Requirement 12.6

A formal security awareness program for all personnel.

FTC Safeguards Rule, GLBA
16 CFR 314.4(e)(1)

Security awareness training for staff, a binding requirement.

NY DFS Cybersecurity Reg
23 NYCRR 500.14(a)(3)

Regular cybersecurity awareness training for personnel.

ISO/IEC 27001:2022
Annex A 6.3

Information security awareness, education, and training.

NIST SP 800-53 Rev. 5
AT-1 · AT-2 · AT-3

The Awareness and Training control family, literacy and role-based.

Sample DMS certificate of completion for Marcus Hale at Northwind Logistics, Q2 2026 training cycle, showing credential ID, role track, issue date, and a verification QR code.
Proof, per person

A record your broker can verify, for every employee.

Cyber-insurance applications now ask whether you run security awareness training. The honest answer needs evidence. Every employee who finishes a cycle earns a certificate like this one, and your admin can export a twelve month proof packet to hand your broker at renewal.

A unique credential ID and a scannable verification link on every certificate.
Per-employee completion dates, quiz scores, and the role track they trained on.
Quarterly cadence and a completion threshold built in, because annual and one and done is what gets flagged.

Sample certificate. Name and company are illustrative.

How it works

Three steps from sign up to renewal ready.

1

Onboard your org

Sign up as the admin and invite your team by email. Employees sign in with a magic link, so there are no passwords for them to forget or reuse.

2

Each person trains for their job

Everyone takes the all-staff core. Finance, executives, HR, developers, and IT also get the track for their role. You buy a pool of seats and reassign them as people join or leave.

3

Hand the proof to your broker

Your twelve month packet is ready to download at renewal. It carries each employee's completion date, quiz score, and certificate. That is the evidence the insurance form asks for.

When the renewal form asks if you train your staff, answer yes with a record.

Sign up as the admin and invite your team. Every employee who finishes earns a certificate, and your twelve month proof packet is ready the day your broker asks for it.

Start your organization