An annual e-learning is not a security awareness program.
It's a part of the story.
If I help organisations with awareness, I'd rather start with the question:
What behaviour do we want to change because it reduces a real risk to this organisation?
This prevents awareness from becoming a collection of separate campaigns.
A good program works cyclically: determining risk, choosing behaviour, performing interventions, measuring and adjusting.
Start with risk
Not every organisation has the same human risks.
Remember:
- Phishing;
- BEC/invoice fraud;
- handling client data;
- passwords;
- parts of information;
- use of AI tools;
- work at home;
- reporting of incidents;
- dealing with suppliers.
Select topics based on:
- incidents;
- risk analysis;
- functions;
- sector;
- technical controls;
- previous measurements.
Then awareness becomes part of risk management.
Segment target groups
A receptionist, financial assistant, board member and system administrator have other risks.
Therefore, create target groups.
Examples include:
All employees
Basic behaviour, phishing, reporting, information.
Finance
BEC, payment fraud, bank account change.
HR
Personal data, applications, identity documents.
IT/Management
Privateized accounts, social engineering, change control.
Management/Directory
Targeted phishing, crisis decision-making, risk acceptance.
This makes training more relevant.
Formulating behaviour, not just knowledge
“Employees understand phishing” is difficult to measure.
Better:
- employees report suspicious email;
- finance checks account changes via second channel;
- employees use approved channels for sensitive data;
- administrators use separate management accounts;
- incidents shall be reported within the agreed time limit.
You can observe and improve behaviour.
Use different interventions
People don't all learn by the same form.
Combine, for example:
- short e-learning;
- Phishing simulation;
- Microlearning;
- team interview;
- workshop;
- scenario;
- posters/intranet;
- onboarding;
- Management communication.
The right mix depends on risk and target audience.
Phishing simulation: measures more than click percentage
Click percentage is a limited size.
I'd rather watch:
- reporting rate;
- speed of reporting;
- repeated errors;
- differences between departments;
- post-training response;
- trend over time.
Someone who does not click but never reports, helps the organisation less than someone who actively signals an attack.
Measure whether the program is working
Use a limited number of indicators.
Examples include:
- Phishing reporting rate;
- Repeat risk;
- participation of relevant training courses;
- incident reports;
- time to report;
- awareness questions in audits;
- behaviour signals from processes.
Link indicators to the risk.
A high training rate is nice, but says little about actual behaviour.
Make reporting easy
This is one of the most practical improvements.
If reporting is complicated, people report less.
Take care of:
- clear button or channel;
- rapid feedback;
- no guilt;
- identifiable communication;
- simple instruction.
Reporting behaviour is a strong measure of safety culture.
Use incidents as a learning moment
A real incident is a real risk.
Part anonymised where possible:
- what happened;
- how it was discovered;
- which went well;
- better;
- What behaviour helped.
That is often more credible than a generic campaign.
Involvement of management
Awareness becomes weak when management expects exceptions.
Examples include:
- emergency payment without control;
- password sharing;
- sensitive data via private channels;
- Getting around security process because it needs to be done quickly.
Behaviour of managers also determines what employees think is normal.
Build awareness in existing processes
A program will become stronger if it is not separate.
Integrate awareness into:
- onboarding;
- change of function;
- incident management;
- suppliers;
- HR cycle;
- risk analysis;
- internal controls;
- Management report.
Then it becomes part of the organisation.
What does a year cycle look like?
A simple cycle can be:
Q1
Risk analysis, baseline assessment, target groups, basic intervention.
Q2
Phishing/payment fraud, team calls, measurement.
Q3
Targeted floor per target group, onboarding check.
Q4
Scenario exercise, trend analysis, management evaluation.
It doesn't have to be crowded.
Consistency is more important than a new campaign every month.
What do you report to the board?
I wouldn't report how many modules have been sent.
I'd show you:
- the greatest human risk;
- relevant trends;
- reporting behaviour;
- recurrent vulnerable groups/processes;
- incidents;
- improvement actions;
- impact of measures.
Then awareness becomes board-level risk information.
When does e-learning work?
E-learning is fine for:
- basic knowledge;
- onboarding;
- repetition;
- demonstrability;
- scalability.
Use it as part of the program.
Not as a complete strategy.
My starting point
Awareness is for me ultimately about desired behaviour at the moment it matters.
An employee gets a suspicious e-mail.
A financial colleague receives a request to change a bank account.
A board member is being called in for an emergency.
An administrator must make an exception.
Then you want people to:
- recognising the risk;
- know what the deal is;
- safe conduct;
- Report anomalies.
That takes more than one training.
Do you want to see how your current awareness approach stands? So look at the existing article on cybersecurity awareness training and demonstrably safe behaviour.


