Security awareness for new-employee onboarding
New hires don't yet know what normal looks like at your organization. Assign baseline training and a first simulation automatically, before day 30.
Overview
New employees join without an instinct for what a normal email, message, or request looks like inside your organization. They don't yet recognize which senders are legitimate, which requests are unusual, or who to ask when something feels off. That unfamiliarity makes the first weeks of employment a period of elevated risk, and it is also the hardest window for a security team to cover manually. If baseline training depends on someone remembering to assign it, some new hires will start their first quarter with no training and no simulation at all.
Waiting for the next scheduled campaign to include new hires means weeks of exposure with no measurement and no coaching. It also means every cohort starts from a different point, so the organization never establishes a consistent baseline for how a new employee performs against a first phishing attempt. Onboarding should behave like access provisioning: something that happens automatically, on a fixed timeline, tied to a person's start date rather than an administrator's calendar reminder.
Because onboarding assignments are driven by rules rather than manual tasks, every cohort starts from the same repeatable point. You can layer department and group filters on top of the onboarding trigger, so a finance analyst, a branch teller, and an IT engineer each receive the baseline content that matches their real exposure, all fired from the same start-date logic. Pairing the onboarding rule with a short learning path gives new hires a structured sequence rather than a single isolated module, and the estimated time is visible up front, so the assignment reads as a manageable part of week one rather than an open-ended obligation.
Measurement begins immediately. The first simulation and the baseline modules feed a starting risk score, and if a new hire does click a simulated lure they land on a just-in-time awareness page that explains the specific red flags they missed, in English or Bahasa Indonesia, at the moment the lesson is most relevant. Reminders and overdue alerts keep assignments from being quietly ignored, and reporting a suspicious message is visible and rewarded from the first week, so the habit you most want, reporting rather than clicking, is established before any bad instinct has a chance to set in.
How Claro helps
Automatic onboarding rules
Assignment rules with an ONBOARDING trigger fire when a new user is created, so baseline training and a first simulation are assigned without an admin creating a task manually.
Baseline micro-training
Short, card-based modules cover phishing recognition, reporting, and safe habits, sized for a new hire's first week without competing with onboarding paperwork.
A calibrated first simulation
The first simulation a new hire receives can use a lower-difficulty template, so the exercise builds recognition skills instead of feeling like a trap in someone's first week.
Early risk score baseline
Each new hire gets a starting risk score from their first assignments, giving managers a consistent reference point to track improvement over the following months.
Just-in-time coaching the moment they click
If a new hire clicks a simulated phishing link, they are taken to a bilingual awareness page that walks through the exact red flags they missed, turning a mistake in week one into an immediate, low-stakes lesson.
Consistent across every joiner source
Onboarding rules fire from a user's creation date whether that person is added manually, imported by CSV, or synced through SCIM or LDAP, so no new hire slips through because of how they were added.
Frequently asked questions
The first simulation is meant to teach, not catch someone out. Pair it with a baseline module beforehand, use a lower-difficulty template, and make sure reporting the email is visible and rewarded, so the exercise reads as training rather than a trap.
Related pages
Board & Regulator Reporting
Turn simulation, training, and risk data into board-ready and audit-ready evidence for OJK, BSSN, UU PDP, and ISO 27001.
Learn moreProtecting Remote & Hybrid Teams
Reach distributed staff with consistent phishing simulation and awareness across email, WhatsApp, and phone.
Learn moreReducing Repeat Clickers
Identify the small group of repeat clickers and coach them with targeted, non-punitive intervention instead of one-size-fits-all training.
Learn moreSee Claro in action
Book a walkthrough tailored to your program and your regulatory context.
Request a demo