HIPAA
Security Rule · Healthcare
Satisfies the Security Awareness & Training standard (45 CFR §164.308(a)(5)), including security reminders, malicious software protection, login monitoring, and password management.
52 weeks of story-driven cybersecurity awareness training your employees will actually complete. Five minutes a week, real characters, real lessons that stick.
Most companies do security awareness training the same way: once a year, two to four hours, generic slides, click “next” to finish. Employees check the box, forget what they saw by lunch, and the next phishing email still gets clicked. Meanwhile, attackers are using AI to write phishing emails that look better than your real internal ones.
The answer isn’t more training. It’s better training, delivered consistently — in a format people actually engage with.
Each episode is a five-minute story set at fictional Meridian Supply Co. — a small business facing the same threats your company does. Every episode ends with a practical action and a quick check to lock in the lesson.
You get a cohort code and admin dashboard. Share the code with your employees — they register, you approve.
One new episode per week, for 52 weeks. Short enough to fit in a coffee break. Long enough to change behavior.
Your dashboard shows who’s completing episodes, who needs a nudge, and how the team is improving over time.
Every episode follows real characters facing real threats. Your team remembers stories, not bullet points. By week 12 they’re asking what happens next.
Short enough that people actually do it. Long enough to change how they think about security. No multi-hour training days that nobody remembers.
Each episode ends with a quick check. Employees have to engage with the material, not just click through it. Quiz scores feed your admin dashboard.
Created by a working cyber fraud supervisor. Every scenario comes from real cases — phishing, ransomware, BEC, deepfakes, vendor compromise, insider threat.
Security awareness training is required under nearly every major cybersecurity framework. Sentinel Weekly is designed to satisfy that requirement — with documented weekly delivery, per-employee completion tracking, and quiz-based comprehension checks that produce the records auditors ask for.
Security Rule · Healthcare
Satisfies the Security Awareness & Training standard (45 CFR §164.308(a)(5)), including security reminders, malicious software protection, login monitoring, and password management.
PR.AT · General framework
Aligns with PR.AT-01: Personnel are provided with awareness and training. Weekly drip delivery with completion tracking provides the documented evidence CSF 2.0 assessors request.
Federal systems · FedRAMP
Supports AT-2 Literacy Training & Awareness, including insider threat (AT-2(2)), suspicious communications (AT-2(4)), APT awareness (AT-2(5)), and practical exercises (AT-2(1)).
Defense contractors · CUI
Addresses 3.2.1, 3.2.2, 3.2.3 — risk awareness, role-specific training, and insider-threat awareness. Maps to CMMC Level 2 practices AT.L2-3.2.1 through AT.L2-3.2.3.
Payment processors · Merchants
Satisfies Requirement 12.6 security awareness training, including phishing and social engineering (12.6.3.1) and annual reinforcement (12.6.3.2). Dashboard provides acknowledgement records.
SaaS · Enterprise vendors
Provides training evidence for SOC 2 CC1.4 / CC2.2 and ISO 27001:2022 Annex A 6.3 (information security awareness, education, and training). Completion records export for audit packages.
Financial institutions
Meets the updated 16 CFR §314.4(e) personnel security awareness training requirement. Content covers financial-fraud-specific threat patterns: BEC, vendor impersonation, wire fraud.
General baseline
Addresses Control 14.1–14.8: awareness program, social engineering recognition, authentication training, data handling, incident reporting, and role-specific skills.
Nearly universal requirement
Most policies now require documented security awareness training as a condition of coverage (and favorable premiums). Sentinel Weekly provides the per-employee completion records carriers ask for at renewal.
Ten themed blocks across the year, each building on the last: foundations, email threats, passwords & access, social engineering, AI & deepfakes, device & data safety, reporting & response, leadership, and resilience.
Per-seat annual pricing. The more seats you add, the lower the per-seat rate. Adjust the slider below to see your price — Stripe applies the right tier automatically.
Need to talk first? Contact us — we can help size your team.
Employees and admins log in at weekly.sentinelvault.net to access episodes and the admin dashboard.
Sentinel Weekly is built for your whole employee base. If you want a multi-day classroom course for executives, see Vault Cyber Academy. If you want a short in-person briefing for your leadership team, see Cyber Risk Briefings.