Floor staff, warehouse crews and franchise teams often never get a corporate inbox — and that still is not a free pass to skip security. This guide shows how to deliver security awareness training without company email in 2026 with SMS, kiosk logins and manager codes.
TL;DR
- Security awareness training without company email needs identity first: phone, employee ID or kiosk PIN.
- Freeze a mobile enrolment path before day one for non-desk roles.
- Run one medium phishing drill only where mailbox or SMS receives it.
- Track completion in human risk reporting the same as desk staff.
- Drop ghost accounts when finish dates hit so seats do not stick forever.
Why this matters
In 2026 retailers, logistics brands, construction firms and multi-site hospitality still leave hundreds of workers untrained because HR assumes no email means no seat. Attackers do not care. Shared tablets, WhatsApp shift groups and personal Gmail forward chains become the real attack surface.
Verizon's 2026 DBIR finds the human element in 62% of breaches. If you only train people with company mailboxes you are measuring the easy half of the roster.
What you'll need
- HR roster with mobile number or employee ID for every non-email worker
- A short baseline path inside security awareness training or equivalent
- SMS or app invite path, plus a kiosk option for shared devices
- Manager codes so supervisors can unlock training on the floor
- Clarity on whether those roles can receive phishing sims at all
- Seat plan that can grow and shrink with casual hours
The steps
1. Decide identity before content
Pick one durable identifier: mobile number, payroll ID, or SSO via roster. Never rely on a shared floor Gmail.
Expected outcome: every learner has a unique login path even without a mailbox.
Common mistake: one warehouse login shared by twelve people.
2. Enrol with SMS or manager code, not only email
Send the invite as an SMS link or print a QR that binds to the employee ID during induction. Manager codes unlock accounts in under two minutes on a kiosk.
Expected outcome: 90%+ enrolled before the first unsupervised shift.
Common mistake: parking folders of paper reminders that nobody scans.
3. Cut the pack to mobile-length modules
Keep baseline under 30 minutes on a phone screen: passwords and MFA, payment or portal scams, how to report. Save multi-hour tracks for desk staff.
Expected outcome: finish rate above 85% inside seven days of hire.
Common mistake: forcing a 90-minute LMS module on a handheld at 5am load-out.
4. Separate channels for drills
Only run classic email phishing simulations for people who receive work email. For SMS-first cohorts, use smishing drills or tabletop call-backs with supervisors.
Expected outcome: fail metrics that map to the channel people actually use.
Common mistake: declaring zero click rate because you never mailed the cohort that has no inbox.
5. Make reporting work offline
Give a one-tap report number, portal button on team phones, or a manager hotline card. Celebrate report acts in the same pack as desk staff.
Expected outcome: report events logged even when there is no Outlook add-in.
Common mistake: only measuring email report buttons.
6. Prove completion for insurers and landlords
Export certificates and attendance with employee ID. Store under the same client or site code as desk learners.
Expected outcome: one insurer pack with both cohorts.
Common mistake: two spreadsheets that never meet before renewal.
7. Deprovision on last shift
Turn off the seat when the finish date hits. Casual workers churn; seats should too.
Expected outcome: seat count tracks live headcount each Monday.
Common mistake: billing for exited casuals until next true-up panic.
Troubleshooting
Union site blocks personal phone use. Offer paid kiosk time during paid induction only.
Language mix on floor. Ship baseline in the two busiest languages first.
Managers lose the unlock codes. Rotate weekly codes into the supervisor app, not a paper sticky.
Surveys show suspicion of tracking. Position training as site safety like induction first aid, not surveillance.
Sim SMS lands as spam. Pre-register the sender ID and warm traffic before the first live drill.
Franchisees refuse shared spend. Bill per-site seats with a simple monthly true-up rather than one HQ licence dump.
Tools and resources
- Mobile-friendly lesson player
- SMS or QR enrolment
- Kiosk mode for shared tablets
- Human risk view that includes non-email IDs
- Certificate export by site
What to do next
This week: map every non-email role, pick identity, and pilot SMS enrol on one site. Side-by-side platform options that handle multi-tenant floors live on compare.
FAQ
How do you deliver security awareness training without company email in 2026?
Use mobile number or employee ID as identity, enrol via SMS or kiosk, keep modules under 30 minutes, and track completion the same way you track desk staff.
Can people without email sit phishing simulations?
Only if they have a channel you can safely simulate — email, SMS, or voice. Skip email sims for pure floor roles and use tabletop drills instead.
Is a shared tablet login acceptable?
No. Unique IDs are required so completion and fail data mean anything.
How long should the non-desk baseline take?
About 20 to 30 minutes in 2026. Longer packs get abandoned on shift change.
Do insurers accept non-email training records?
Yes when certificates show a unique worker ID, dates, and module names.
What about contractors with their own firm email?
Enrol them under your tenant if they touch your systems, or require proof from their employer's programme.
How do MSPs price sites with heavy casuals?
Per-seat monthly with fast up and down beats annual floors that lock January headcount.
What metric proves the model works?
Enrolment before first unsupervised shift, completion inside seven days, and fail close-out under 48 hours on any channel you do simulate.
One last thing
No email is an enrolment design problem, not a risk exemption. In 2026 the attacker will find the person who still approves pickups on a shared tablet. Give that person a 30-minute path and a unique ID.