PCI DSS v4.0.1 · REQUIREMENT 12.6 · ROLE-BASED

PCI DSS Security Training
Tailored to Each Role That Touches Card Data

PCI DSS Requirement 12.6 isn't a generic PowerPoint presentation. Effective PCI security awareness means different things for a front-desk receptionist, an office manager, an IT administrator, and a business owner. ThreeShield delivers PCI training that speaks to what each person actually does - so it sticks, and so it actually reduces your risk.

12.6PCI DSS v4.0.1 Requirement 12.6 mandates security awareness training at least annually for all personnel
Every RoleTraining must reach everyone who handles cardholder data - not just IT staff
v4.0PCI DSS v4.0.1 adds new requirements around targeted training for phishing and social engineering threats
DocumentedTraining completion must be tracked and evidence provided during PCI assessments and QSA audits

Why Generic Security Training Fails PCI

A dental receptionist and a server administrator both touch systems in your cardholder data environment - but their security training needs are completely different.

Generic training typically covers:

  • Password complexity rules nobody follows
  • Phishing examples that don't match how your business uses email
  • Technical concepts that don't apply to most staff roles
  • No connection to what cardholder data actually looks like in your business
  • A checkbox that satisfies auditors but doesn't change behavior

ThreeShield PCI training covers:

  • What cardholder data looks like in your specific environment and systems
  • Social engineering attacks targeting your industry (healthcare, retail, hospitality)
  • Card-skimming awareness for staff who handle physical card terminals
  • Invoice and payment fraud scenarios relevant to your role
  • What to do - and who to call - when something looks wrong

Role-Based Training Tracks

🏥

Healthcare & Medical Offices

Dental practices, clinics, and medical offices accepting card payments. Covers front desk, billing staff, and office managers. Addresses the specific social engineering attacks targeting medical offices - including insurance fraud calls and fake vendor payment requests. Satisfies both PCI DSS and Alberta HIA / HIPAA security awareness requirements simultaneously.

📊

Accounting & Financial Services

CPA firms, bookkeepers, and financial advisors that process client payments. Wire fraud and invoice manipulation attacks specifically target accounting staff - training addresses the actual scenarios your team faces. Includes both PCI DSS and CPA Canada framework awareness requirements.

🏪

Retail & Hospitality

Merchants, restaurants, hotels, and retail businesses with point-of-sale environments. Training covers physical security of card terminals, skimming device identification, staff-facing social engineering (fake card processor calls, "system update" scams), and proper handling procedures for declined cards and chargebacks.

⚙️

IT & Technical Staff

System administrators, developers, and IT support staff with access to cardholder data environments. Covers network segmentation, secure coding practices for payment applications, log monitoring, and the technical requirements of PCI DSS that IT teams are accountable for. Includes PCI DSS v4.0.1 customized approach for developers.

💼

Managers & Business Owners

Decision-makers who set policy and respond to incidents. Covers compliance obligations, breach notification requirements under PCI DSS and Canadian privacy law, cyber insurance implications, and how to recognize and respond to payment fraud. Includes vendor and QSA assessment process overview.

📱

Remote & Mobile Workers

Staff processing payments or accessing cardholder data outside your main location. Covers secure remote access requirements, mobile device handling, public Wi-Fi risks, and the specific PCI DSS controls required for remote card-not-present processing environments.

PCI DSS v4.0.1 Specific Requirements

12.6.1 — Annual Training Program

At least annual security awareness training for all personnel. ThreeShield delivers and documents the annual training program with evidence suitable for SAQ completion and QSA review.

12.6.2 — Training Updates

Training content must be reviewed and updated at least annually to reflect current threats. PCI DSS v4.0.1 is explicit that training must address the actual threat landscape - not a static presentation from three years ago.

12.6.3 — Phishing Awareness

PCI DSS v4.0.1 added a specific requirement for phishing and social engineering awareness. ThreeShield's training includes phishing simulation as an optional add-on to verify that awareness training is actually changing behavior.

12.6.3.2 — Acceptable Use Policies

Personnel must acknowledge acceptable use policies at least annually. ThreeShield provides policy acknowledgment documentation that satisfies PCI DSS requirement 12.6.3.2 as part of the training engagement.

PCI Training That Actually Works

Generic security awareness training satisfies a checkbox. Role-specific PCI training actually reduces the likelihood that your staff will be the reason a cardholder data breach happens. ThreeShield delivers both - and the documentation to prove it.

Book PCI DSS Training Book a Time Online →

Also covers PCI DSS full compliance program · SAQ completion support · QSA audit preparation