Back to Blog

What Is Role-Based Learning?

Discover how Role-Based Learning tailors security training to individual job roles, ensuring employees are prepared for the specific cyber threats they face.

Role-Based Learning is a way to deliver security awareness training that fits each employee’s job. Instead of giving everyone the same general course, it matches the depth of training to the level of risk each role carries.

People who can approve payments, grant access to systems, or handle sensitive data face more targeted attacks than most coworkers. Role-Based Learning gives these people training built around the specific attacks most often aimed at them. Nimblr sums up the idea in one line: high risk roles demand high impact training.

Why does security training need to fit the job?

Attackers do not target every employee the same way. They go after the people who can move money, open access to systems, or expose data quickly. Training that ignores these differences leaves the highest risk roles underprepared.

Consider three common examples:

  • Finance: An accounts payable clerk receives an invoice from a known supplier with new bank details. The invoice is fake.

  • IT Helpdesk: A support agent gets a call from someone who claims to be a coworker locked out of their account and asks for a Multi Factor Authentication (MFA) reset.

  • Executives: A finance manager receives a voice message that sounds exactly like the CEO, asking for an urgent transfer. The voice is a deepfake.

A general course cannot cover each of these scenarios in depth. Role-Based Learning can, because each person receives the training that matches the attacks they are most likely to face.

Learn more about our role-based training →

How does Role-Based Learning work?

Employees answer two short questions at the end of a regular Nimblr course. Nimblr uses the answers to assign one or more learning tracks. From that point on, training adapts to the employee automatically.

  1. The employee completes a course. New users see the questions after their first course. Existing users see them after their next scheduled course.
  2. The employee answers two questions about their daily work and responsibilities. Both questions are required.
  3. Nimblr assigns one or more learning tracks and selects the most relevant courses.
  4. Admins and employees can review or update the answers at any time.

 

What are the two questions?

Question 1: What best describes your day to day work? (choose one)

Options include finance, accounting, or procurement; sales or business development; customer service or support; operations, logistics, or production; HR, people, or payroll; marketing, communications, or PR; IT, engineering, or technical operations; leadership, management, or strategy; and something else.

Question 2: Which of these are part of your job? (choose all that apply)

Options include approving payments or invoices, handling personal or customer data, dealing with suppliers or vendors, leading a team, admin access to IT systems, writing code or accessing production, being a public face of the company, and none of these options.

What are the six Role-Based Learning tracks?

Nimblr Role-Based Learning includes six tracks, each built for a role that attackers target often: Finance, Executives, HR & Payroll, IT Helpdesk, IT Admins, and DevOps.

Together, the tracks include more than 25 courses that cover real attack methods such as invoice fraud and deepfake voice and video scams. Nimblr adds new role specific courses as attack methods change.

Track Who is it for? Example course topics
Finance  Accounting, procurement and anyone who can approve or start payments Business E-mail Compromise (BEC), invoice fraud and payment redirection, phone fraud aimed at finance teams 
Executives  Senior leaders, directors, and top executives   NIS2 accountability for leaders, ISO 27001 for management, spear phishing, deepfake voice and video fraud, protecting your digital footprint 
HR and Payroll  People operations, payroll, and anyone who manages employee records   Direct deposit change fraud, new hire onboarding as an attack path, protecting employee data 
IT Helpdesk  Support staff who handle password resets and identity checks   Vishing and social engineering on the helpdesk, MFA reset fraud, remote access tool abuse 
IT Admins  System administrators and anyone with privileged or cloud access   Device code phishing and OAuth token theft, attacks on privileged accounts, spotting privilege escalation and lateral movement 
DevOps  Developers, engineers, and anyone with access to code repositories or pipelines   Secure coding, cloud security, secure backend development, secrets management, supply chain attacks, CI/CD pipeline security 

 

What are the benefits of Role-Based Learning?

  • More relevant training. Employees see content that matches their daily risk, which makes training more engaging.

  • Stronger protection where it matters most. The highest risk roles receive the deepest and most targeted training.

  • No added admin work. Role-Based Learning runs in the background and is on by default.

  • Content that keeps up with threats. New role specific courses are added as attackers change their methods.

  • Full visibility and control. Admins and employees can view and update role answers at any time.

Frequently asked questions

Is Role-Based Learning a paid extra?

No. Role-Based Learning is included in the Nimblr Base Package at no extra cost.

Does it need any setup?

No. Role-Based Learning is on by default. Admins do not need to prepare or activate anything.

Can employees skip the two questions?

No. Both questions are required. The second question includes a "None of these options" choice for employees whose job does not match any listed item.

Can admins change an employee’s role answers?

Yes. In the Nimblr Admin Portal, go to Users, then Edit for the employee. The Role section shows their answers, which admins can update and save.

Can employees update their own answers?

Yes. Employees can update their answers at any time in the Nimblr End User Portal.

How many role based courses are there?

There are more than 25 courses across the six tracks, and Nimblr adds new role specific courses on a regular basis.

Conclusion

Security awareness training works best when it reflects the real risks people face at work. Role-Based Learning gives every employee training that fits their job, with the deepest training going to the roles attackers target most. It requires no setup, runs automatically, and is included in the Nimblr Base Package.

Learn more about our role-based training →

Author

Nimblr Security Awareness

Nimblr Security Awareness

The Nimblr team is made up of people who are passionate about cyber security, developing training for real people, and tracking behavioral change.