Create and manage security awareness training campaigns for user accounts targeted by account compromise and XDR detection risk events.
This playbook streamlines the delivery of training campaigns, reducing manual effort
and increasing efficiency. The playbook also allows you to tailor training materials
to educate your employees on specific threats and vulnerabilities relevant to your
organization.
Each execution of the playbook generates a training campaign, which can be tracked
in the Training Campaigns app under
.Each training campaign can be applied to a maximum of 15,000 user accounts. If the
risk events target more than 15,000 user accounts, multiple training campaigns will
be generated, each containing up to 15,000 users, upon approval.
![]() |
ImportantYou must have the Cyber Risk Exposure Management entitlement enabled and the required
data sources configured to create Security Awareness Training Campaign playbooks.
|
Procedure
- Go to .
- On the Playbooks tab, choose .
- On the Playbook Settings panel, select the Risk events type, specify a unique name for the playbook, and click Apply.
- On the Trigger Settings panel,
select the trigger type and click Apply.
-
Manual: Allows you to start the playbook execution by clicking the Run icon (
)
-
Scheduled: Allows you to schedule the playbook to run hourly, daily, weekly, or monthly
Important
To create Security Awareness Training Campaign playbooks, make sure that the trigger type is set to Manual or Scheduled with the Frequency set to Monthly. -
- On the Target Settings panel,
select and configure the Target for the playbook and
click Apply.You can add a maximum of 10 Target nodes for each Security Awareness Training Campaign playbook.
- In the Risk factor drop-down list, select Account compromise or XDR detection from the Risk factor drop-down list.
- In the Risk event drop-down list, select the risk events for which the user accounts need to receive
the necessary training.
Important
If you select All risk events, the playbook target automatically includes any future risk events associated with the selected risk factor.Only risk events with New and In progress states trigger playbook actions. - In the Risk level drop-down list, select the risk levels of the risk events.
- If you need to take actions when specific conditions are
met, configure the Condition node.
- Click the add node (
) on the right of the Target node and click Condition.
- Create a condition setting by specifying the
Parameter, Operator,
and Value.
-
IS: The condition is triggered if any of the values is matched
-
IS NOT: The condition is triggered if none of the values is matched
-
- Click Apply.
- If you need to add more than one parallel
Condition node, click the add node (
) on the right of the Target node.
- If you need to configure action settings for the
Condition node, add an
Action node by clicking the add node (
) on the right.
For details, see Step 7. - If you need to configure else-if conditions or
else actions, add an Else-If Condition or
Else Action node by clicking the add node
(
) under the Condition node.
For details, see Step 9.
- Click the add node (
- Configure actions by adding an
Action node.
- Click the add node (
) on the right of the Condition node and click Action.
- On the Action Settings panel, select Create training campaign and configure the training campaign settings.
Setting DescriptionTraining programThe training program you want to use for the campaignFor more information about the training programs, see Get started with training campaigns.CategoryThe category of the training program you selectedCampaign durationThe length of time the campaign will run - Select whether to send a notification to request
manual approval to create general actions, and then configure the
notification settings if you require manual approval.
Note
Actions pending manual approval for over 24 hours expire and cannot be performed.SettingDescriptionNotification method-
Email: Sends an email notification to specified recipients
-
Webhook: Sends a notification to specified webhook channels
Subject prefixThe prefix that appears at the start of the notification subject lineRecipientsThe email addresses of recipientsThe field only appears if you select Email for Notification method.WebhookThe webhook channels to receive notificationsThe field only appears if you select Webhook for Notification method.Tip
To add a webhook connection, click Create channel in the drop-down list. -
- Click Apply.
- If you need to add more than one parallel action,
use the add node (
) on the right of the Target or Condition node.
- Click the add node (
- Configure notification settings by adding the second
Action node.
- Click the add node (
) on the right of the first Action node and click Action.
- On the Action Settings panel, specify how to notify recipients of the playbook results.
- For email and webhook notifications, configure the
following settings.
Note
ServiceNow ticket notifications are not available to send playbook results.SettingDescriptionSubject prefixThe prefix that appears at the start of the notification subject lineRecipientsThe email addresses of recipientsThe field only appears if you select Email for Notification method.WebhookThe webhook channels to receive notificationsThe field only appears if you select Webhook for Notification method.Tip
To add a webhook connection, click Create channel in the drop-down list. - Click Apply.
- Click the add node (
- Configure Else-If Conditions or
Else Actions if necessary.
- Click the add node (
) below the Condition node and click Else-If Condition or Else Action.
- Configure a Condition node by following Step 6 or an Action node by following Step 7 or Step 8.
Note
-
The nodes that can be added by using an add node (
) vary depending on the preceding node. For example, an Action node can only be possibly followed by another Action node; a Condition node can be followed by an Action node or have an Else-If Condition or Else Action attached to it.
-
When a condition is false, the playbook performs the Else Action or checks if its Else-If Condition is met. If the Else-If Condition is met, the playbook continues to perform the corresponding Else Action.
-
Multiple Action nodes configured in a serial mode are taken sequentially.
- Click the add node (
- Enable the playbook by toggling the Enable control on.
- Click Save.The playbook appears on the Playbooks tab in the Security Playbooks app.