Security

Security Awareness Training That Doesn't Suck

September 13, 2024 Steven Singer 11 min read

Most security awareness training is terrible. Employees click through slides about password hygiene while mentally composing their grocery list. They pass the quiz at the end by guessing the most paranoid-sounding answer. They learn nothing. They change nothing. And IT can check the compliance box.

Security Awareness Training That Doesn't Suck

We rebuilt our security awareness program from scratch last year. Click rates on phishing simulations dropped from 18% to 4%. More importantly, employees actually report suspicious emails now instead of just ignoring them. Here's how we did it.

The Problem with Traditional Training

Traditional security awareness training fails for predictable reasons:

It's boring. Thirty-minute videos about threat landscapes don't engage people. They endure it, they don't absorb it.

It's abstract. Generic examples about "hackers" attacking "your organization" don't feel real. Employees don't see themselves in the scenarios.

It's annual. Once-a-year training creates a spike of awareness that fades within weeks. Security threats don't take 11 months off.

It's punitive. Failed phishing tests lead to "gotcha" moments and mandatory remedial training. This creates resentment, not learning.

It measures the wrong things. Completion rates and quiz scores don't indicate actual behavior change. They measure compliance theater.

Our Redesigned Approach

Make It Relevant

We customized training content to our actual environment. Instead of generic "phishing email from unknown sender," we showed employees what a real attack against Julius Silvert might look like:

When employees see their own environment being targeted, the threat becomes real. "That looks exactly like an email I'd get" is a powerful learning moment.

Make It Continuous

Instead of annual training, we implemented monthly micro-learning:

Weekly security tips: Short (2-3 sentence) tips delivered via email every Monday. Readable in 30 seconds. Practical. Specific. "This week, verify any wire transfer request by calling the requester directly. Use a phone number you look up yourself, not one from the email."

Monthly simulations: Phishing tests with varying difficulty levels. Not to catch people, but to train them. Failed simulations lead to immediate education, not punishment.

Quarterly deep dives: Longer sessions (15-20 minutes) on specific topics. These are interactive, not videos. Employees practice identifying threats rather than passively watching.

Make It Safe

We explicitly removed punishment from the program. If you click a phishing simulation, you get training, not a write-up. If you report a suspicious email that turns out to be legitimate, you get thanked, not mocked.

This changes the psychology entirely. Employees aren't trying to avoid getting caught; they're genuinely trying to protect the company. They ask questions. They report concerns. They become partners in security rather than targets of security theater.

The Reporting Effect

Before our program redesign, we received maybe 2-3 suspicious email reports per month. Now we receive 40-50. Most are legitimate emails that employees are rightfully cautious about. That's exactly what we want - a culture where people pause and verify rather than click and hope.

Make It Personal

Security training that only protects the company misses an opportunity. We extended training to include personal security:

Employees pay attention when the training helps them personally. And skills learned for personal protection transfer directly to workplace security.

The Phishing Simulation Program

Phishing simulations are the core of our program. Here's how we structure them:

Difficulty progression: We start with obvious phishing (bad grammar, suspicious sender, urgent demands) and gradually increase sophistication. By month 6, we're sending convincing spear-phishing attempts that would fool many security professionals.

Varied attack vectors: Not just email. We test:

Immediate feedback: If someone clicks a simulated phishing link, they immediately see an educational page explaining what they missed. No delay. No waiting for IT to reach out. The learning happens in the moment while the experience is fresh.

Department-specific scenarios: Finance gets fake wire transfer requests. Operations gets fake delivery notifications. HR gets fake resume attachments. Relevant threats for each group.

Metrics That Matter

We stopped measuring completion rates and started measuring behavior:

Click rate: Percentage of employees who click simulated phishing links. Our target is under 5%.

Report rate: Percentage of employees who report simulated (and real) suspicious emails. Our target is over 50%.

Response time: How quickly employees report suspicious emails after receiving them. Faster is better.

Repeat offenders: How many employees click multiple simulations. This identifies who needs additional help.

Real incident correlation: Do our simulation results predict real-world behavior? When we've had actual phishing attempts, how did employees respond?

Tools We Use

KnowBe4: Our primary security awareness platform. Handles training content, phishing simulations, and reporting. The integration with our email system makes simulation deployment seamless.

Phish Alert Button: One-click reporting for suspicious emails directly from Outlook. Removes friction from doing the right thing.

Power BI dashboards: Custom reporting showing trends over time, departmental comparisons, and individual risk scores. Leadership sees these monthly.

Leadership Buy-In

Security awareness only works if leadership participates. Our CEO takes every training and every simulation. When he gets phished (it's happened), he shares the experience with the company. This normalizes failure as part of learning.

Leadership messages reinforce the program:

When employees see that security matters to leadership, they treat it seriously.

Handling Repeat Offenders

Some employees consistently fail simulations. Our approach:

First, investigate: Is there a reason? Some employees have legitimate conditions (visual impairments, cognitive processing differences) that make certain cues harder to spot. Accommodate these cases.

Second, personalize: One-on-one coaching is more effective than generic remedial training. Sit with the employee, walk through what they missed, and practice together.

Third, restrict (if necessary): For employees who remain high-risk after coaching, we implement additional controls - more aggressive email filtering, reduced system access, additional approval requirements. This isn't punishment; it's risk management.

Fourth, document: Persistent security negligence after training and coaching becomes a performance issue. This is rare - most people improve with proper support - but it's an available tool.

The Results

After 18 months of the new program:

More importantly, we've prevented real incidents. Employees have caught and reported actual phishing attempts that made it through our email filters. The human layer is now a genuine defense, not just a vulnerability.

What We'd Do Differently

Start with leadership alignment. We launched the program and then got leadership buy-in. Should have been the other way around. Leadership participation from day one would have accelerated culture change.

Communicate the "why" earlier. Some employees initially saw the program as Big Brother surveillance. Better upfront communication about protecting both the company and employees would have reduced this resistance.

Include contractors and vendors. Our initial program focused on employees. We've since extended it to contractors and are working on vendor security requirements. Should have been included from the start.

Recommendations

If you're building or rebuilding a security awareness program:

  1. Kill annual checkbox training. It doesn't work.
  2. Make it continuous, relevant, and safe.
  3. Measure behavior, not completion.
  4. Get leadership visibly participating.
  5. Treat failures as learning opportunities, not gotcha moments.
  6. Extend protection to employees' personal lives.
  7. Invest in the tools and time needed to do it right.

Security awareness isn't about preventing all clicks - that's impossible. It's about building a culture where security is everyone's responsibility and reporting suspicious activity is natural and encouraged. That cultural shift is the real goal.

#Security #SecurityAwareness #Phishing #Training #CIO
← Previous Post Next Post →

Planning an ERP modernization?

6 SAP-to-Dynamics conversions with zero business disruption. Let's discuss your project.

ERP Services Book a Call