Making security awareness useful to busy staff
Part of a retrospective. The retrospective month groups the topic; it is not an earlier publication date. Published 18 September 2026.
Security awareness should help staff complete risky tasks safely and report uncertainty quickly, with practical feedback instead of punitive click-rate theatre.
A staff member notices a payment instruction that feels wrong but is not sure it is fraudulent. If reporting it requires finding a policy, opening a complicated form and defending the concern to a busy technician, the organisation has made hesitation expensive.
Awareness training should prepare people for that moment. The useful outcome is a safer decision and an easy route to help. Completion rates can show that training was delivered, but they do not establish whether staff can act sensibly under pressure.
Teach the task the person actually performs
Finance staff need to handle changed bank details, unusual urgency and requests that bypass approval. Reception staff may need a safe response to requests for personal information. An administrator needs a different understanding of privileged access and recovery requests.
NIST's framework distinguishes general awareness from training for specialised roles. That is a practical design choice, not a reason to build an enormous course catalogue. Start with a small number of tasks where a mistaken decision could matter and the correct response can be explained clearly.
Use the organisation's approved process. If a payment change requires independent verification through an established contact route, show that route. Do not teach people merely to inspect logos or trust a familiar name. A message can look plausible while the request still needs verification.
Keep examples synthetic and clearly identified as training. There is no need to expose actual employee mistakes, customer details or sensitive internal conversations to make the lesson recognisable.
Make reporting a service the organisation provides
Give staff a simple reporting path suited to the tools they use. Explain what happens after reporting and what to do if the usual channel is unavailable. Test the route from a normal user's account rather than assuming a published address is monitored correctly.
The person receiving reports needs a triage process and a way to provide feedback. A brief acknowledgement can tell the employee that the concern reached the right place. Where safe and useful, explain the outcome without sharing unnecessary investigation details.
Consider a hypothetical accounts officer who reports a supplier's unexpected bank-detail change. The response should support the established verification process, preserve relevant information and avoid approving the change merely because the email looks authentic. If the request is legitimate, the officer should still hear that following the process was appropriate.
That feedback matters to the next decision. An organisation that complains about false alarms may teach staff to remain silent until they are certain. Certainty is often not available to the person who first notices something unusual.
Use exercises to inspect the system around the employee
A controlled exercise can reveal whether staff know how to respond. It can also reveal that the reporting button is absent, the help desk is unsure what to do or the manager routinely pressures staff to skip verification. Record those findings rather than reducing the exercise to employee mistakes.
If simulated messages are used, set clear boundaries and obtain the appropriate organisational approval. Avoid humiliating individuals or exploiting sensitive personal circumstances for a dramatic response. The exercise should be proportionate to the learning objective and respectful of the workplace.
Do not publish a league table of people who clicked. A click can be a useful observation, but it does not capture the full task, whether reporting occurred or whether the surrounding controls worked. Treat measured results as local evidence with limitations, not a general forecast of breach risk.
Ask people to demonstrate the next action. Can they verify a request through a known contact? Can they report a suspicious message without forwarding it widely? Do they know how to get urgent help? Those observations can lead directly to changes in training and support.
Remove the friction the training exposes
Sometimes the safest instruction is difficult to follow because the organisation has not supplied the means. Staff cannot use an approved sharing portal if access takes days to obtain. They cannot verify a supplier change if the supplier register contains no trusted contact details.
Assign those problems to the relevant process owners. More training is not the answer to missing access, unusable tools or contradictory management expectations. Data loss prevention needs a workflow, not just a policy explores one example where a technical block needs a workable next step.
Keep guidance close to the task. A short instruction in a payment workflow or a useful support response may be more relevant than another general annual module. Review the instruction with staff who actually perform the work and revise it when the process changes.
Managers should model the same requirements. An executive who expects urgent exceptions teaches a stronger lesson than a training slide that says everyone follows the process.
Evaluate whether the organisation responds better
Review report quality, time to appropriate triage and the practical problems staff raise. Interpret trends carefully. More reports may reflect increased willingness to ask for help rather than more malicious activity. Fewer reports are not automatically evidence of safer behaviour.
Use anonymised themes to guide the next training topics and process improvements. If staff repeatedly misunderstand one approval step, simplify it or demonstrate it differently. If reports stall at a supplier boundary, repair the response arrangement described in preparing for a cyber incident before anyone is on call.
The aim is a workplace where someone can pause an unsafe request and receive useful help without being made to feel foolish. Training contributes to that, but leadership and everyday support determine whether the lesson survives a busy afternoon.
Working on something similar?
If this connects with something you’re working through, I’m happy to talk about where you’re stuck and whether I can help.
See how I work