
Key Takeaways
- Principal investigators hold grant authority, trusted relationships with federal program officers, and access to institutional financial systems, making them high-value targets for business email compromise attacks designed to redirect grant funds or steal credentials.
- NSF Important Notice No. 149 (effective December 2, 2025) requires senior and key personnel to certify they have completed research security training within 12 months before each proposal submission, and requires institutions to certify compliance at the time of submission.
- NSF Important Notice No. 149 requires research security training covering cybersecurity, foreign disclosure, malign foreign talent recruitment programs, and international collaboration. It does not require simulation-based phishing campaigns; that behavioral conditioning layer is what dedicated phishing awareness training adds on top of the required topic-level coverage.
- Business email compromise caused $55.5 billion in exposed losses globally between October 2013 and December 2023, according to the FBI's Internet Crime Complaint Center. Research institutions and PIs are targeted through impersonation of program officers, grant portal alerts, and wire redirect requests.
- KC Phishing delivers security awareness training through simulated phishing campaigns across email, Slack, and Teams, with auto-assigned microlearning on every click event, per-department risk scoring, and a one-click report button integrated into Outlook, Gmail, Slack, and Teams.
Your principal investigators hold budget authority on multi-year federal awards, along with agency relationships and a steady volume of email that really is urgent. That combination makes a PI inbox one of the most productive social engineering targets on any campus running federal awards. The fraud against that inbox begins with a message the PI was already expecting to see.
Nothing has to be breached for that message to work, which is what makes it so hard to defend against with the controls a security team already owns. No system is touched at all: the grants management platform stays as secure as it was the day before, and the money still leaves. That is why security awareness training software belongs in your research security program alongside the IN-149 policy curriculum.
Research institutions carry 2 distinct training obligations that are often treated as 1. The first is NSF's research security training requirement under Important Notice No. 149 and the CHIPS and Science Act of 2022. That requirement covers foreign disclosure, malign foreign talent recruitment programs and related interference risks.
The second obligation covers the email and messaging threat that the first one leaves alone. It covers spear-phishing, impersonation and the social engineering attacks aimed at research staff. A research security program that satisfies the NSF obligation can leave that second threat entirely open.
Why Principal Investigators Are High-Value Business Email Compromise Targets
The Combination of Authority, Trust, and Workflow That Makes PIs Attractive
A principal investigator occupies a position attackers actively look for. A PI authorizes expenditures, approves subcontract payments and directs wire transfers on a multi-year award, while communicating regularly with federal program officers who hold their own authority over that award. That mix of financial control and federal relationships is the same profile that makes corporate finance executives targets for business email compromise.
That same profile is extended further by a research environment. A single NSF award puts your PI in regular contact with collaborating institutions, foreign partners, equipment vendors and conference organizers. Any of those senders can be impersonated convincingly, and the display name is the only part of the header most recipients ever read. An unfamiliar institution is the normal case in that traffic.
The scale of that exposure is documented in federal crime reporting. Business email compromise caused $55.5 billion in exposed losses globally between October 2013 and December 2023, according to the FBI's Internet Crime Complaint Center. That total is spread across more than 305,000 separate reported incidents.
Those losses come from social engineering and nothing more technical. A convincing message, a familiar sender display name and the right urgency hook produce the action the attacker wants, with no malware anywhere in the chain. Every one of those 3 ingredients is easier to assemble against a PI than against a corporate finance team.
What Grant Administrators and Lab Staff Face Alongside PIs
The PI is the primary target, and the exposure in a research environment extends far past that one inbox. Each of the 3 surrounding roles handles requests with financial or data consequences. Each also receives mail that appears to come from institutional or federal sources:
- Grant administrators: process payments and manage budget modifications, which puts them directly in the path of a payment redirect.
- Lab managers: handle equipment purchasing, where a vendor banking change looks like routine business.
- Postdocs and graduate students: correspond with collaborators and upload deliverables to shared platforms, often under deadline pressure.
Those roles all need training, and most programs stop at the first one. An attacker blocked at the PI will often reach somebody else in that network with access to the same NSF award systems. Those systems do not record which of the 4 roles opened them.
What a Convincing Grant-Fraud Message to a Principal Investigator Looks Like
Attack Patterns Specific to the Research Environment
The messages that reach those roles are built around the specific workflows of federally funded research. They reference award numbers, proposal deadlines, compliance filings and NSF or NIH agency processes that only somebody inside the research environment would recognize as authentic detail. Their effectiveness comes from that specificity and not from technical skill.
Most of what reaches a research inbox follows 1 of 4 patterns. In the first, a federal program officer asks for a supplemental funding response. In the second, a grant portal alert demands immediate credential entry to avoid a payment hold. A vendor sends a subcontract payment redirect with new banking details, or a foreign institution extends a collaboration invitation on a compressed deadline.
Each one exploits a workflow the recipient manages every week. The urgency written into each message is calibrated to push the recipient past the verification step that would have exposed it, usually by naming a deadline 24 or 48 hours out. Train your staff on the verification step itself. Across all 4 patterns, that single step is the only part of the sequence your people control.
PI-Targeted Phishing Lures: Common Attack Patterns and What Phishing Awareness Training Should Cover
Attack Pattern | Sender Impersonated | The Urgency Hook | What Training Should Address |
|---|---|---|---|
Grant portal verification | University research office | "Your award account requires login to avoid a payment hold" | Distinguishing official portal links from credential-phishing pages |
Program officer outreach | NSF, NIH, or DOE program officer | "Please review the attached supplemental funding request by Friday" | Verifying agency communications through official channels before opening attachments |
Subcontract payment redirect | Institutional accounts payable or vendor | "Updated banking details for your active subcontract" | Wire transfer verification protocols and the two-step confirmation requirement |
Collaboration invitation | Foreign institution co-investigator | "Complete your joint proposal submission before the portal closes tonight" | Compressed-deadline tactics and external-sender display name verification |

What NSF Important Notice 149 Requires for Research Security Training
The Research Security Program Requirement and the Institutions It Covers
NSPM-33, signed in January 2021, directed federal science funding agencies to protect government-supported research against foreign interference. The CHIPS and Science Act of 2022 gave those requirements statutory force. Important Notice No. 149 implements the training requirement at NSF, issued July 10, 2025 and effective December 2, 2025 for all NSF-funded proposals.
Institutions receiving federal science and engineering support above $50 million a year must certify that they operate a research security program. The training component of that program reaches further than the $50 million threshold does. Certification and training are scoped differently on purpose, and the training side is the wider of the two.
That wider reach operates through proposal-level certification. Senior and key personnel named on any NSF award certify at submission that they completed research security training within the preceding 12 months. The institution certifies the same thing for everyone named on that proposal.
A PI on an active or pending NSF award counts as senior or key personnel for that purpose. The certification duty therefore covers your whole award portfolio. It reaches well beyond the handful of people a $50 million institutional test would catch.
What the Required Training Covers and What It Does Not
The notice names 4 topic areas that compliant training must address:
- Cybersecurity, taught at an awareness and policy level.
- International collaboration, covering how partnerships are formed and disclosed.
- Foreign interference, including malign foreign talent recruitment programs.
- Rules on disclosure, conflict of interest and conflict of commitment.
That list puts cybersecurity alongside the research-integrity subjects NSPM-33 defined. The resulting curriculum is structured, and it teaches all 4 topics at the level of policy. Policy is the right level for a disclosure rule and the wrong one for an inbox.
Policy level is also the point at which IN-149 stops. Simulation-based phishing training falls outside what the notice requires, and the difference between policy and simulation is behavioral. A course module on cybersecurity risk teaches a topic and tests recall.
A simulated campaign tests something that a module cannot reach. It puts a grant-portal credential request in front of your PI and records whether they click, then delivers microlearning at the moment of the click. The test and the remedy arrive inside the same minute, which is the whole difference between a curriculum that teaches a topic and a campaign that changes what somebody does next.
Those 2 approaches produce measurably different results in practice. An institution relying on the IN-149 curriculum alone has the topic coverage and none of the recognition habits. Those habits are what a member of staff draws on at 9am on a Monday, working through 40 messages in 20 minutes with a grant deadline that afternoon.
Train Research Staff on the Message That Reaches Them
See how KC Phishing runs simulated phishing campaigns across email, Slack, and Teams for research institutions, with per-department risk scoring and auto-assigned microlearning on every click.
Why Security Awareness Training for PIs Requires a Different Approach
Why Generic Phishing Tests Miss the Research Institution Threat Model
Standard phishing simulation templates are built around corporate workflows. They cover executive impersonation, IT help desk credential requests, payroll portal alerts and package delivery notifications. Those 4 templates work perfectly well for your general employee population.
Your research staff meet a different set of messages entirely. A PI who clicks a simulated package delivery notice and takes a module about that scenario is still unprepared for an NSF program officer impersonation. The grant portal credential request is the message that reaches their inbox in practice.
Simulation for research institutions has to mirror the attacks research staff receive. The scenarios worth running are the same 4 patterns, covering grant workflows, federal agency impersonation, subcontract payment processes and collaboration requests from abroad. A program using generic scenarios produces click rates that tell you nothing about how your staff will perform against a real message.
What Effective Phishing Awareness Training for Research Staff Looks Like
Effective training for research environments does 3 things a generic test does not:
- Uses research-shaped lures, mirroring real grant workflows and federal agency communication patterns.
- Assigns microlearning on the click, while the gap between what the recipient did and what they should have done is still visible to them.
- Tracks risk by lab or department, because the lab is the unit of operational trust and a high-click-rate lab is a systemic problem.
That third point is the one most institutions skip. Individual remediation will not fix a lab where everybody trusts the same forwarded message. The lab shares a habit, so the lab needs the campaign.
Reach matters as much as that content does, and both are usually scoped too narrowly. The training has to cover all 4 roles, from the PI to the graduate student watching a shared inbox. It also has to use the channels the attacks themselves use.
A one-click report button inside the email client lets staff flag a suspicious message without switching applications. Reporting rates rise when the process takes 1 step and not 4. You also gain visibility into attempts that never produced a click, which is the half of the picture click data cannot show.
How KC Phishing Delivers Security Awareness Training Across Research Environments
Simulation Campaigns, Microlearning on Click, and the Report Button
KC Phishing runs simulated campaigns across email, Slack and Teams. Its lure library covers the impersonation patterns and urgency hooks used against research staff, so the messages your PIs meet in a test resemble the ones they meet in practice. A research institution needs 4 capabilities from it:
- Research-shaped lures: program officer impersonation, grant portal verification and subcontract payment redirects, in place of package delivery notices.
- Microlearning on the click: assigned automatically and tied to the lure type, so the module explains the message the recipient just opened.
- Lab-level risk scoring: click and report rates aggregated by team and department, which is the unit a research institution can act on.
- Audit-trail export: completion records and campaign analytics in the form your award documentation needs.
A click assigns microlearning automatically, tied to whichever of the 4 lure types produced it. The module addresses the behavior itself, which is what makes it relevant to the gap the simulation just found. Repeat clickers move onto a refresher track without anyone arranging it, so nobody in L&D or IT has to identify them or assign the remediation by hand.
That same automation covers reporting across all 4 channels. The one-click Report Phishing button integrates with Outlook, Gmail, Slack and Teams, so staff flag a suspicious message inside the application it arrived in. Fewer steps in the workflow means more attempts captured before any of them produce a consequence.
Risk Scoring by Department, Lab-Level Visibility, and the Audit Trail
Those reports feed risk scores, which run per employee and aggregate by team, department and role. That gives you the lab-level view of security posture that a campus can act on. A lab with a high click rate on grant-portal lures is a named, addressable risk that a targeted campaign closes.
A department with low report rates is a different problem entirely. The reporting habit never took hold there, so attacks arrive in those inboxes and nobody hears about them. A department reporting nothing and a department clicking nothing produce the same flat line on a summary dashboard, and only one of those two is good news.
The same records enter the audit trail on their own. You can document which staff completed microlearning, which campaigns produced which click rates by department, and how risk scores moved across cycles. None of it is assembled by hand, which matters because a reconstruction built from memory and calendar entries is the thing that fails when an award review arrives at short notice.
For an institution managing multiple active awards, that trail turns security awareness training into a reportable practice. The platform holds those records beside the rest of your compliance and L&D data. One export then covers both the IN-149 curriculum and the simulation program.
How KnowledgeCity Builds Security Awareness into the Research Security Program
The NSF requirement sets a baseline for foreign-interference risk among senior and key personnel. Simulation and security awareness training address a second threat to those same people. Neither baseline covers what the other one is for.
Your PIs, grant administrators and lab staff face BEC attacks built around the workflows of federally funded research. Those attacks succeed where the recognition and reporting habits were never built. The payment is redirected or the credentials are taken, and the monthly reconciliation is usually the first sign anyone sees.
An institution that certifies under IN-149 and also runs a recurring simulation program has covered both obligations. Those 2 obligations do different work. IN-149 supplies the cybersecurity, foreign disclosure and MFTRP curriculum your certification depends on, while simulation supplies the behavioral conditioning a curriculum cannot produce.
Run both programs, and run them on 1 platform so the records stay together. Our guide to improving regulatory compliance training covers how that pairing is scheduled across an academic year. For what the resulting record has to show, compliance training courses that survive a multi-state audit works through the same test from the accreditation side.
Frequently Asked Questions
1. What is security awareness training for principal investigators?
Security awareness training for principal investigators is a structured phishing simulation and microlearning program designed to build the recognition and reporting behaviors PIs and research staff need to identify and respond to BEC attacks, impersonation attempts, and social engineering lures specific to the research environment. Unlike general employee phishing training, effective security awareness training for PIs uses lure templates built around grant workflows, federal agency impersonation, and payment redirect requests that reflect the actual threat patterns used against research institutions.
2. What does NSF Important Notice 149 require for research security training?
NSF Important Notice No. 149, effective December 2, 2025, requires senior and key personnel named on NSF proposals to certify that they have completed required research security training within the 12 months prior to each proposal submission. Institutions must also certify at submission that all named senior and key personnel have completed the training. The required training must address cybersecurity, international collaboration, foreign interference, and rules governing disclosure, conflict of interest, and conflict of commitment, per the CHIPS and Science Act of 2022. It does not require simulation-based phishing campaigns or the behavioral conditioning that recurring simulated-attack exercises produce.
3. How does phishing awareness training differ from NSF research security training?
NSF IN-149 research security training covers cybersecurity at the topic level alongside foreign disclosure, malign foreign talent recruitment programs, and international collaboration. Phishing awareness training delivers simulation-based behavioral conditioning through realistic simulated attacks, click-event microlearning, and measurable changes in how staff respond when a real BEC message arrives. Topic-level cybersecurity coverage and simulation-based conditioning are different modalities. A research institution with an active security posture runs both and documents each separately.
4. How does KC Phishing deliver security awareness training for research institutions?
KC Phishing delivers phishing simulation training for research institution environments through simulated campaigns across email, Slack, and Teams, using pre-built lure templates built around the impersonation patterns and urgency hooks used against research staff. When a recipient clicks a simulated message, KC Phishing automatically assigns a microlearning module specific to that lure type. Per-employee risk scores and click and report rates are tracked by team, department, and role, giving the institution lab-level visibility into security posture. Training records flow to the audit trail, and a one-click Report Phishing button integrates into Outlook, Gmail, Slack, and Teams.
References
- Federal Bureau of Investigation, Internet Crime Complaint Center. "Business Email Compromise: The $55 Billion Scam." PSA240911, September 2024.
- U.S. National Science Foundation. "Important Notice No. 149: Updates to NSF Research Security Policies." July 10, 2025.
- U.S. National Science Foundation. "FAQ: Important Notice No. 149: Implementation of Updates to NSF Research Security Policies.".
- U.S. National Science Foundation. "Research Security.".
- Federal Bureau of Investigation. "Spoofing and Phishing.".