Cyber security awareness training for PR and communications firms

Build cyber security awareness training for PR and communications firms, covering client confidentiality, social accounts, contractors and phishing.

PR and communications firms work with information that is valuable before it becomes public: campaign plans, launch dates, crisis statements, media lists, executive schedules, client credentials, creative assets and drafts under embargo. Staff also move quickly across email, cloud documents, messaging platforms, social accounts and external contractors. Cyber security awareness training for PR and communications firms must protect confidentiality without blocking the speed that clients expect.

This guide builds a role-based programme around the decisions that create the most risk: sharing a draft, approving a statement, granting access, responding to a journalist, changing a supplier or publishing from a client account.

TL;DR

Why communications work attracts targeted attacks

A communications firm sits close to authority, deadlines and public attention. An attacker can impersonate a client executive, journalist, spokesperson, agency colleague or platform provider and use a credible deadline to make the request feel normal. The request might be to review a document, approve a payment, share a contact list, grant access to a social account or publish a statement.

The business may also have a small core team supported by freelancers and specialist partners. A former contractor may still have access to a client folder. A social operator may manage several brand accounts from one browser. An urgent crisis response may cause staff to use personal devices or copy content into an unapproved channel. These are process and human-risk issues as much as technical ones.

The NIST Cybersecurity Framework provides a useful structure: identify important assets and dependencies, protect them, detect unusual activity, respond with clear ownership and recover without losing evidence. Training should translate that structure into the moments when a communications professional has to choose between speed and verification.

What belongs in scope

Map both the firm’s own systems and the client environments it can affect:

The OAIC small-business privacy guidance is relevant when a firm holds media contacts, client staff details, customer lists or campaign audiences. The training point is simple: know what information is held, use the approved purpose and audience, and escalate a misdirected share or exposed file quickly.

A cyber security gap assessment can map these assets to owners and controls. Include client-account access and contractor offboarding; a firm’s risk does not stop at its own domain.

Role-based training

Account directors and client leads

Account leads receive high-authority requests and often decide what can be shared. Train them to verify unusual executive requests, confirm the scope of a client approval, challenge urgency and use a second approver for high-impact publication, payment or access changes.

A realistic scenario is a message that appears to come from a client executive asking for a confidential draft to be sent to a new personal address. Another is a request to publish a crisis statement immediately while the usual approver is unavailable. The correct response is to use the established client contact and approval route, not to treat the message’s tone as authority.

Media relations and PR teams

Media teams may receive links, documents, interview invitations and contact requests from unfamiliar people. Teach them to inspect the sender, avoid opening unexpected files on a production device and verify a journalist or partner through a known publication or contact route when the request involves confidential information.

Training should distinguish a legitimate media request from an unsafe file or credential prompt. A journalist does not need a login to a client data room to ask a question. A request for a full media list or unreleased statement should be treated according to the client’s disclosure rules.

Social, content and advertising operators

Social and content staff may have direct publishing power. Teach them to use named accounts, MFA, approved business managers, password managers and a documented publishing checklist. Practise a fake platform-support message asking for a verification code or a new application connection.

Use separation of duties for sensitive accounts. The person creating a post should not be the only person who can approve a crisis statement or change the recovery email. Keep backup administrators and recovery procedures documented outside the account being protected.

Designers, developers and web partners

Creative files, websites and analytics accounts often sit with specialists. Training should cover safe file sharing, client-folder permissions, secrets and API keys, staging versus production, change approval and the removal of access at project close.

Do not paste credentials into a design brief, issue tracker or chat. Do not assume that a freelancer’s personal account is an acceptable place to store a client asset. Give each person the minimum access and a clear route for requesting more.

Executives and spokespeople

Executives are frequent impersonation targets and may be asked to approve payments, publish statements or share sensitive information. Give them a concise response rule: pause, use the known channel, involve the second approver and report the attempt. Make it normal for a junior staff member to challenge an urgent request from a senior person.

Freelancers and contractors

Include copywriters, photographers, media buyers, developers, monitoring providers and temporary staff. Record what each person can access, issue named accounts where possible and set an end date. Remove access to client accounts, shared folders, calendars, social profiles and credentials when the work ends.

The scenarios worth practising

Build exercises around the firm’s highest-impact decisions:

  1. Fake client executive: a message requests a confidential draft or media list through a new address.
  2. Fake journalist: a supposed reporter sends an attachment or asks for a portal login before an interview.
  3. Embargo pressure: a person asks staff to publish or share a launch asset before the approved time.
  4. Social-platform support: a message asks for an MFA code or requests a new application connection.
  5. Cloud-share invitation: a document link leads to an unfamiliar login page or unexpected file download.
  6. Supplier payment: an invoice or bank account changes just before a deadline.
  7. Crisis impersonation: an attacker asks for a statement, customer list or executive contact while an incident is unfolding.
  8. Freelancer handover: a former contractor still has access to a client folder or recovery email.
  9. Deepfake or voice request: an apparent executive asks for an urgent action that bypasses normal approval.

The Scamwatch business email compromise guidance supports the payment and impersonation part of this programme. Independent verification is essential when a familiar supplier, client or executive appears to request a payment or change in bank details.

Verification before speed

Create an approval matrix for common actions:

For each action, name the approver, the second channel and the evidence that must be recorded. A short delay is cheaper than a public post that cannot be withdrawn or a leaked draft that cannot be recalled.

Use a five-step response in training:

  1. Stop the requested action.
  2. Check the request against the project, client, deadline and normal process.
  3. Verify using a known contact or approval route.
  4. Report the message, file, account alert or unusual request.
  5. Record what happened and protect any account or document that may have been exposed.

Client separation and least privilege

A communications firm should be able to answer “which people can access this client’s information today?” Build that answer through:

Training should point to the technical control. If people are told not to share a credential but the team has no password manager, the programme is creating a workaround problem instead of solving one.

Phishing simulations for communications firms

Start with a harmless cloud-share or platform-support simulation. It should teach staff to inspect the URL, use the known application directly and report unexpected access requests. Follow with a fake client-approval or supplier-payment scenario for the relevant group.

The phishing simulation workflow can support recurring campaigns and targeted follow-up. Avoid using real client names, real embargo dates or realistic crisis content that could cause an actual post or disclosure. Use synthetic campaigns, safe landing pages and a debrief that explains the control being practised.

For social and account teams, consider a tabletop exercise instead of only an email simulation. Ask who can revoke access, which client contact is trusted, how a post is paused and where evidence is retained. A high-quality response is more valuable than a low click rate with no operational learning.

Personal devices and remote collaboration

Set a clear boundary for personal devices:

Do not expect a remote worker to remember a policy that provides no alternative. Give them a secure portal, a reporting channel and a fast way to ask whether a request is legitimate.

A practical 30-60-90 day rollout

Days 1–30: map authority and assets

List client accounts, folders, credentials, publishing routes, suppliers and contractors. Identify the actions that can disclose information, move money or publish publicly. Deliver a baseline to the entire firm and confirm the reporting owner.

Days 31–60: practise high-impact workflows

Assign role paths to account leads, media teams, social operators, developers, executives and contractors. Run a safe cloud-share simulation and a client-impersonation tabletop. Fix access, approval and offboarding gaps discovered during the exercises.

Days 61–90: repeat and review

Run a comparable exercise, review reports and verification by role and project, close overdue training and update the approval matrix. Record the content version, cohort, result, follow-up owner and next review date.

What to measure

Track:

Human risk reporting can bring training, quiz and phishing signals together for prioritisation. Use the data to decide where coaching, process changes or technical controls are needed; do not treat a score as proof that a person or client is safe.

Common mistakes

Assuming a known client name makes a request safe

Names, signatures and writing style can be copied. Verify through a known channel before releasing a draft, changing access or publishing.

Giving every freelancer the same access

A project contributor may need one folder, not the whole client account. Least privilege limits the damage of a compromised account and makes offboarding possible.

Keeping client credentials in chat

Chats are easy to forward, export and search. Use a controlled password manager or the client’s approved access method instead.

Training only permanent staff

Contractors often have direct access to documents, websites and social profiles. Include them in assignments, policies and offboarding.

Measuring clicks without measuring reports

A low click rate can coexist with low reporting or a small audience. Compare similar cohorts and look at the whole response: pause, verify, report and recover.

FAQ

What should cyber security awareness training for PR firms cover?

Cover client impersonation, phishing, cloud-sharing, confidential drafts, embargoes, media-list handling, social-account security, payment redirection, credentials, contractors and incident reporting. Match examples to the roles that can publish or share information.

How should a communications firm verify an urgent client request?

Use an established contact or approval route already held by the firm. Do not reply to the message and treat the sender name, signature or voice as proof. Record who verified the request and what was approved.

Should freelancers receive security awareness training?

Yes, when they can access client data, files, accounts or publishing tools. Give them the minimum access, the required training and a clear end date, then remove access when the work ends.

How can a PR firm protect social-media accounts?

Use named accounts, MFA, a password manager, separate roles, backup administrators and a publishing approval process. Train staff to reject unexpected app connections and requests for one-time codes.

How often should communications teams run phishing simulations?

Use recurring, role-specific practice rather than one annual exercise. Vary the scenario across cloud files, client approvals, platform support, journalists and supplier payments, while keeping every exercise safe and reviewable.

What should happen after a confidential draft is sent to the wrong person?

Report it immediately, preserve the message and recipient details, notify the client or incident owner under the agreed process, request deletion where appropriate and assess whether links, credentials or other material need to be revoked. Do not hide the mistake while trying to fix it alone.

Can training prevent a deepfake executive request?

Training cannot prove that every voice or video is genuine. It can teach staff that identity cues are not enough and that high-impact actions require an independent approval route. Use the same pause-and-verify rule for voice, video, email and chat.

One last thing

A communications firm’s most valuable control is not a warning about hackers. It is a shared agreement that no deadline removes the need to verify a high-impact request. Protect the client relationship by making the second channel, second approver and reporting route part of the creative and publishing workflow.

Related guides

Sources

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.