PR and communications firms work with information that is valuable before it becomes public: campaign plans, launch dates, crisis statements, media lists, executive schedules, client credentials, creative assets and drafts under embargo. Staff also move quickly across email, cloud documents, messaging platforms, social accounts and external contractors. Cyber security awareness training for PR and communications firms must protect confidentiality without blocking the speed that clients expect.
This guide builds a role-based programme around the decisions that create the most risk: sharing a draft, approving a statement, granting access, responding to a journalist, changing a supplier or publishing from a client account.
TL;DR
- Train account teams, creatives, media relations, social operators, executives, freelancers and web partners against their real access.
- Treat embargoed documents, client credentials, media lists, crisis communications and payment requests as high-risk assets.
- Verify unusual requests through a known channel before releasing a draft, granting access or publishing content.
- Use least privilege, MFA, password managers and named accounts for every client environment.
- Practise fake journalist, fake client, supplier-payment, cloud-share and social-account takeover scenarios.
- Measure reporting and verification behaviour, not just whether a person completed a course.
Why communications work attracts targeted attacks
A communications firm sits close to authority, deadlines and public attention. An attacker can impersonate a client executive, journalist, spokesperson, agency colleague or platform provider and use a credible deadline to make the request feel normal. The request might be to review a document, approve a payment, share a contact list, grant access to a social account or publish a statement.
The business may also have a small core team supported by freelancers and specialist partners. A former contractor may still have access to a client folder. A social operator may manage several brand accounts from one browser. An urgent crisis response may cause staff to use personal devices or copy content into an unapproved channel. These are process and human-risk issues as much as technical ones.
The NIST Cybersecurity Framework provides a useful structure: identify important assets and dependencies, protect them, detect unusual activity, respond with clear ownership and recover without losing evidence. Training should translate that structure into the moments when a communications professional has to choose between speed and verification.
What belongs in scope
Map both the firm’s own systems and the client environments it can affect:
- Email, calendars, messaging, video calls and cloud storage.
- Client folders, data rooms, media lists, contact databases and project-management tools.
- Social media, advertising, website, domain, analytics and newsletter accounts.
- Client credentials, API keys, passwords, recovery codes and approved publishing routes.
- Draft press releases, crisis plans, financial information, launch dates and embargoed material.
- Proposals, contracts, invoices, supplier details and freelancer records.
- Personal devices, home networks and collaboration tools used by staff or contractors.
- IT, web-development, design, monitoring, media-buying and printing partners.
The OAIC small-business privacy guidance is relevant when a firm holds media contacts, client staff details, customer lists or campaign audiences. The training point is simple: know what information is held, use the approved purpose and audience, and escalate a misdirected share or exposed file quickly.
A cyber security gap assessment can map these assets to owners and controls. Include client-account access and contractor offboarding; a firm’s risk does not stop at its own domain.
Role-based training
Account directors and client leads
Account leads receive high-authority requests and often decide what can be shared. Train them to verify unusual executive requests, confirm the scope of a client approval, challenge urgency and use a second approver for high-impact publication, payment or access changes.
A realistic scenario is a message that appears to come from a client executive asking for a confidential draft to be sent to a new personal address. Another is a request to publish a crisis statement immediately while the usual approver is unavailable. The correct response is to use the established client contact and approval route, not to treat the message’s tone as authority.
Media relations and PR teams
Media teams may receive links, documents, interview invitations and contact requests from unfamiliar people. Teach them to inspect the sender, avoid opening unexpected files on a production device and verify a journalist or partner through a known publication or contact route when the request involves confidential information.
Training should distinguish a legitimate media request from an unsafe file or credential prompt. A journalist does not need a login to a client data room to ask a question. A request for a full media list or unreleased statement should be treated according to the client’s disclosure rules.
Social, content and advertising operators
Social and content staff may have direct publishing power. Teach them to use named accounts, MFA, approved business managers, password managers and a documented publishing checklist. Practise a fake platform-support message asking for a verification code or a new application connection.
Use separation of duties for sensitive accounts. The person creating a post should not be the only person who can approve a crisis statement or change the recovery email. Keep backup administrators and recovery procedures documented outside the account being protected.
Designers, developers and web partners
Creative files, websites and analytics accounts often sit with specialists. Training should cover safe file sharing, client-folder permissions, secrets and API keys, staging versus production, change approval and the removal of access at project close.
Do not paste credentials into a design brief, issue tracker or chat. Do not assume that a freelancer’s personal account is an acceptable place to store a client asset. Give each person the minimum access and a clear route for requesting more.
Executives and spokespeople
Executives are frequent impersonation targets and may be asked to approve payments, publish statements or share sensitive information. Give them a concise response rule: pause, use the known channel, involve the second approver and report the attempt. Make it normal for a junior staff member to challenge an urgent request from a senior person.
Freelancers and contractors
Include copywriters, photographers, media buyers, developers, monitoring providers and temporary staff. Record what each person can access, issue named accounts where possible and set an end date. Remove access to client accounts, shared folders, calendars, social profiles and credentials when the work ends.
The scenarios worth practising
Build exercises around the firm’s highest-impact decisions:
- Fake client executive: a message requests a confidential draft or media list through a new address.
- Fake journalist: a supposed reporter sends an attachment or asks for a portal login before an interview.
- Embargo pressure: a person asks staff to publish or share a launch asset before the approved time.
- Social-platform support: a message asks for an MFA code or requests a new application connection.
- Cloud-share invitation: a document link leads to an unfamiliar login page or unexpected file download.
- Supplier payment: an invoice or bank account changes just before a deadline.
- Crisis impersonation: an attacker asks for a statement, customer list or executive contact while an incident is unfolding.
- Freelancer handover: a former contractor still has access to a client folder or recovery email.
- Deepfake or voice request: an apparent executive asks for an urgent action that bypasses normal approval.
The Scamwatch business email compromise guidance supports the payment and impersonation part of this programme. Independent verification is essential when a familiar supplier, client or executive appears to request a payment or change in bank details.
Verification before speed
Create an approval matrix for common actions:
- Releasing an embargoed asset.
- Publishing a crisis or executive statement.
- Sharing a media list or client export.
- Granting access to a social, website or advertising account.
- Changing a recovery email, password or MFA method.
- Paying an invoice or changing supplier bank details.
- Sending a credential, API key or private link.
For each action, name the approver, the second channel and the evidence that must be recorded. A short delay is cheaper than a public post that cannot be withdrawn or a leaked draft that cannot be recalled.
Use a five-step response in training:
- Stop the requested action.
- Check the request against the project, client, deadline and normal process.
- Verify using a known contact or approval route.
- Report the message, file, account alert or unusual request.
- Record what happened and protect any account or document that may have been exposed.
Client separation and least privilege
A communications firm should be able to answer “which people can access this client’s information today?” Build that answer through:
- Separate client folders and groups.
- Named accounts rather than shared credentials.
- MFA for email, cloud, social, advertising and administrator accounts.
- A password manager with controlled sharing and audit history.
- Permission reviews at project milestones and account changes.
- Client-specific publishing and approval roles.
- Link-expiry and download restrictions where the platform supports them.
- A leaver and contractor offboarding checklist.
Training should point to the technical control. If people are told not to share a credential but the team has no password manager, the programme is creating a workaround problem instead of solving one.
Phishing simulations for communications firms
Start with a harmless cloud-share or platform-support simulation. It should teach staff to inspect the URL, use the known application directly and report unexpected access requests. Follow with a fake client-approval or supplier-payment scenario for the relevant group.
The phishing simulation workflow can support recurring campaigns and targeted follow-up. Avoid using real client names, real embargo dates or realistic crisis content that could cause an actual post or disclosure. Use synthetic campaigns, safe landing pages and a debrief that explains the control being practised.
For social and account teams, consider a tabletop exercise instead of only an email simulation. Ask who can revoke access, which client contact is trusted, how a post is paused and where evidence is retained. A high-quality response is more valuable than a low click rate with no operational learning.
Personal devices and remote collaboration
Set a clear boundary for personal devices:
- Which client data may be accessed from a personal phone or laptop.
- How MFA and screen locks are required.
- Where files may be downloaded, edited and stored.
- How to report a lost device or a suspicious login.
- Which collaboration tools are approved.
- How access is removed when a freelancer changes project.
- How staff work safely from public Wi-Fi, events and shared spaces.
Do not expect a remote worker to remember a policy that provides no alternative. Give them a secure portal, a reporting channel and a fast way to ask whether a request is legitimate.
A practical 30-60-90 day rollout
Days 1–30: map authority and assets
List client accounts, folders, credentials, publishing routes, suppliers and contractors. Identify the actions that can disclose information, move money or publish publicly. Deliver a baseline to the entire firm and confirm the reporting owner.
Days 31–60: practise high-impact workflows
Assign role paths to account leads, media teams, social operators, developers, executives and contractors. Run a safe cloud-share simulation and a client-impersonation tabletop. Fix access, approval and offboarding gaps discovered during the exercises.
Days 61–90: repeat and review
Run a comparable exercise, review reports and verification by role and project, close overdue training and update the approval matrix. Record the content version, cohort, result, follow-up owner and next review date.
What to measure
Track:
- Completion by role, project team and due date.
- Overdue work and active access held by leavers or contractors.
- Phishing report rate, click rate and time to report.
- Requests independently verified before a share, payment, access change or publication.
- Number of unexpected account alerts escalated.
- Time to revoke access after a leaver or suspected compromise.
- Repeated questions about client approval, file sharing or publishing.
Human risk reporting can bring training, quiz and phishing signals together for prioritisation. Use the data to decide where coaching, process changes or technical controls are needed; do not treat a score as proof that a person or client is safe.
Common mistakes
Assuming a known client name makes a request safe
Names, signatures and writing style can be copied. Verify through a known channel before releasing a draft, changing access or publishing.
Giving every freelancer the same access
A project contributor may need one folder, not the whole client account. Least privilege limits the damage of a compromised account and makes offboarding possible.
Keeping client credentials in chat
Chats are easy to forward, export and search. Use a controlled password manager or the client’s approved access method instead.
Training only permanent staff
Contractors often have direct access to documents, websites and social profiles. Include them in assignments, policies and offboarding.
Measuring clicks without measuring reports
A low click rate can coexist with low reporting or a small audience. Compare similar cohorts and look at the whole response: pause, verify, report and recover.
FAQ
What should cyber security awareness training for PR firms cover?
Cover client impersonation, phishing, cloud-sharing, confidential drafts, embargoes, media-list handling, social-account security, payment redirection, credentials, contractors and incident reporting. Match examples to the roles that can publish or share information.
How should a communications firm verify an urgent client request?
Use an established contact or approval route already held by the firm. Do not reply to the message and treat the sender name, signature or voice as proof. Record who verified the request and what was approved.
Should freelancers receive security awareness training?
Yes, when they can access client data, files, accounts or publishing tools. Give them the minimum access, the required training and a clear end date, then remove access when the work ends.
How can a PR firm protect social-media accounts?
Use named accounts, MFA, a password manager, separate roles, backup administrators and a publishing approval process. Train staff to reject unexpected app connections and requests for one-time codes.
How often should communications teams run phishing simulations?
Use recurring, role-specific practice rather than one annual exercise. Vary the scenario across cloud files, client approvals, platform support, journalists and supplier payments, while keeping every exercise safe and reviewable.
What should happen after a confidential draft is sent to the wrong person?
Report it immediately, preserve the message and recipient details, notify the client or incident owner under the agreed process, request deletion where appropriate and assess whether links, credentials or other material need to be revoked. Do not hide the mistake while trying to fix it alone.
Can training prevent a deepfake executive request?
Training cannot prove that every voice or video is genuine. It can teach staff that identity cues are not enough and that high-impact actions require an independent approval route. Use the same pause-and-verify rule for voice, video, email and chat.
One last thing
A communications firm’s most valuable control is not a warning about hackers. It is a shared agreement that no deadline removes the need to verify a high-impact request. Protect the client relationship by making the second channel, second approver and reporting route part of the creative and publishing workflow.
Related guides
Sources
- NIST Cybersecurity Framework, National Institute of Standards and Technology.
- NIST Cybersecurity for Small Business, National Institute of Standards and Technology.
- Small business, Office of the Australian Information Commissioner.
- Business email compromise scams, Scamwatch.
- NIST SP 800-50 Rev. 1: Building a Cybersecurity and Privacy Learning Program, National Institute of Standards and Technology.