New hires should complete their first security awareness training within 10 days of starting, before they receive broad access to sensitive systems, based on onboarding guidance published by security awareness providers in 2026. That first module is a baseline, not the finish line — most onboarding plans then layer role-specific training and a first phishing simulation across the 30, 60 and 90-day marks, so a new hire isn't considered fully onboarded from a security standpoint until roughly three months in.
TL;DR
- New hires should finish baseline security awareness training within 10 days of starting, before broad system access is granted.
- A 30-60-90 day plan is the common 2026 structure: baseline training in week one, role-based modules by day 30, a first phishing simulation by day 60.
- Human error is a leading cause of security breaches, which is why onboarding-stage training matters more than a policy document nobody reads.
- Auto-enrolment from Microsoft 365 or Google Workspace removes the manual step of remembering to assign training to a new starter.
Why this matters
New hires are a known soft target. They don't yet know internal reporting channels, they're eager to respond quickly to anything that looks official, and they often lack the context to spot an email that doesn't quite match how the company normally communicates. Every day between a person's start date and their first security training is a day they're operating on guesswork. A security awareness training programme that auto-enrols new hires on arrival removes the single biggest failure point: forgetting to assign training at all.
Global Learning Systems' onboarding guidance is explicit on the point: every employee should complete security awareness training within the first 10 days of employment, specifically because that window covers the period before a new hire has built up any pattern-recognition for how real internal communication looks.
How long until new hires finish onboarding training?
The honest answer is that "finishing" onboarding training isn't a single event — it's a sequence. A practical 2026 timeline looks like this:
| Milestone | Timeframe | What happens |
|---|---|---|
| Baseline training | Within 10 days | Core modules: phishing basics, password hygiene, reporting process |
| Role-based modules | By day 30 | Finance, IT, executive or customer-facing content specific to the role |
| First phishing simulation | By day 60 | A live test to see whether baseline training actually changed behaviour |
| Full onboarding review | By day 90 | Manager check-in on completion, quiz results and any repeat gaps |
A new hire who has only completed the day-10 baseline module is partway through onboarding, not finished with it — role-based content and the first simulated test are what actually confirm the training worked.
Day 1-10: baseline security training comes first
Before a new hire touches sensitive systems, they should know the basics: how to spot a suspicious email, what the password policy requires, and — most importantly — exactly where to report something that looks wrong. Adaptive Security's guidance on small-team onboarding puts this even earlier, framing it as operating rules established before a new employee receives access, rather than squeezed in after they're already working unsupervised.
Verdict: treat baseline training as a gate before system access, not a follow-up task for whenever there's time.
Day 30: role-based modules narrow the risk
A generic phishing-awareness module doesn't prepare a finance hire for invoice fraud or an executive assistant for a fake calendar invite pretending to be from the CEO. By day 30, onboarding plans should assign content matched to the new hire's actual exposure — finance, HR, IT admin and customer-facing roles all see meaningfully different scam types.
Verdict: generic training covers the first 30 days; role-specific training is what closes the gap that matters for that particular job.
Day 60: the first phishing simulation is the real test
A quiz score proves someone read the material. A phishing simulation proves whether it changed their behaviour under pressure — which is the only outcome that actually matters. Running the first simulated test by day 60 gives a new hire enough runway to absorb the baseline and role-based content first, without leaving them untested for months.
Verdict: don't skip this step because it feels early — a new hire who fails their first simulation at day 60 is far cheaper to correct than one who fails a real phishing email at day 160.
Day 90: review, don't assume
By the 90-day mark, a manager or IT lead should have visibility into completion status, quiz results, and whether the new hire clicked or reported the first simulation. Human risk reporting exists specifically to surface this without a manual chase — overdue courses and failed simulations both feed into a score that shows who still needs support.
Verdict: the 90-day mark is a checkpoint for the whole onboarding sequence, not a rubber stamp that training happened.
Why onboarding training timelines vary between businesses
- Access timing. A business that grants system access on day one needs training to land before day one, not within it.
- Role complexity. A finance or admin hire with payment authority needs role-based content faster than a role with no financial access.
- Enrolment automation. Manual enrolment slips when HR forgets to flag a new starter; automatic enrolment tied to Microsoft 365 or Google Workspace removes that failure point.
- Company size. Smaller teams often onboard faster because there are fewer approval layers, but they also have less redundancy if one person misses a step.
- Existing culture. A business with an established reporting culture gets new hires up to speed faster, because the reporting habit is visible from day one.
What should new hire security training cover in the first week?
The first week should cover phishing basics, the password and MFA policy, acceptable use of company systems, and — above everything else — exactly how and where to report something suspicious. Anything role-specific can wait until week two or three; the first week is about establishing the baseline habits every employee needs regardless of job title.
Does onboarding training replace ongoing training?
No. Onboarding training gets a new hire to a starting baseline; it does not replace the recurring training and phishing simulation cadence that applies to every employee afterward. A new hire who finishes onboarding at day 90 then joins the same ongoing monthly or quarterly cycle as everyone else.
FAQ
How long until new hires finish onboarding training?
Baseline security training should finish within 10 days of a new hire starting, with role-based modules by day 30 and a first phishing simulation by day 60. Full onboarding is typically reviewed at the 90-day mark.
Should security training happen before or after system access is granted?
Before. Onboarding guidance treats baseline security training as a gate that happens before a new hire receives broad access to sensitive systems, not a follow-up task.
What should new hire security training cover in the first week?
The first week should cover phishing basics, password and MFA requirements, acceptable use policy and the reporting process. Role-specific content follows by day 30.
When should a new hire take their first phishing simulation?
By day 60 is a common 2026 benchmark, giving the new hire enough time to complete baseline and role-based training first before being tested.
Does onboarding training replace ongoing security awareness training?
No. Onboarding brings a new hire to the same baseline as everyone else; they then join the company's regular monthly or quarterly training and phishing simulation cycle.
Why does new hire security training matter more than training for existing staff?
New hires lack the pattern-recognition for how a company normally communicates internally, which makes them a common target for scams impersonating HR, IT or company leadership in the first weeks of employment.
One last thing
The riskiest gap isn't a slow onboarding schedule — it's an inconsistent one. A new hire who slips through without any training because HR forgot to flag them is a bigger exposure than a new hire who finishes baseline training on day 12 instead of day 10. Automating enrolment removes that single point of failure.