Organisational Transformation

Cybersecurity: 4 Ideas to Raise Awareness Among Your Employees

ARTICLE WRITTEN BY
Emmanuelle Abensur
READING TIME
7
minutes
Summarize the article
  • Four ways for a CIO to raise cybersecurity awareness: build it into onboarding, invest in ongoing and role-specific training, show the team what a real breach costs, and run drills.
  • Eight ready-to-run activities are laid out in a table: simulated phishing, spot the phish quiz, invoice fraud role play, password clinic, tabletop exercise, cyber escape game, breach post-mortem talk, clean desk walk.
  • Each activity takes between 15 minutes and 2 hours, and each measures something different: report rate, reused passwords, time to escalate an alert.
  • Rhythm beats format: two or three sessions a year, anchored on European Cybersecurity Month in October, beat one long annual briefing.
  • Run drills unannounced, so you measure everyday reflexes rather than exam preparation.
  • For companies in scope of NIS2, awareness sits among the risk management measures the management body has to see through.

As one of the leaders of the company, CIOs have a variety of responsibilities. But one of the most important? Protecting the company from cyberattacks. And in order to do that, they need to not only put the right cybersecurity protocols in place, but ensure that their teams understand what those protocols are, and how to follow them.

But not every employee has cybersecurity on their radar. So the question is, as CIO, how can you raise cybersecurity awareness among your employees, and protect your data and sensitive information in the process?

Include cybersecurity in your onboarding process

If you want to raise cybersecurity awareness with your employees, why not start on day one?

Working cybersecurity training into your onboarding process is a great way to ensure that every employee that walks through your doors is aware of your cybersecurity protocols. And not only will including cybersecurity in your onboarding process get security on your employees’ radar from the beginning, but it will also show them that you’re a company that takes cybersecurity seriously, which can inspire them to take it seriously as well.

During the onboarding process, walk your new employee through your company’s stance on cybersecurity, key threats they need to be aware of (for example, malware or phishing scams), and general best practices for how to work safely. The earlier you introduce cybersecurity to your employees, the higher their awareness will be, and the less likely they’ll be to have security-related issues.

Invest in ongoing training

Introducing cybersecurity during the onboarding process is great. But the conversation around cybersecurity can’t end there. As CIO, if you want to keep your network safe, you need to invest in regular and comprehensive cybersecurity training for your team.

Ideally, you’ll want to offer basic cybersecurity training to your entire team, whether or not they sit in IT. That training should cover:

  • securing a home network and a home router,
  • reaching company files, tools and data safely from anywhere,
  • setting strong, unique passwords and switching on multi-factor authentication,
  • recognising a suspicious message, and reporting it without fear of looking silly.

In addition, you may want to consider offering more targeted training based on role, department, and/or common threats employees may encounter while performing their job duties. For example, you might consider training your accounting team on how to spot financial scams, and what to do if they suspect company financial information has been exposed in a security breach. 

The better you train your team, the more securely they’ll be able to navigate their jobs, and the less likely you’ll be to deal with any serious cybersecurity issues.

Also read: [Expert Opinion] 4 Security Commandments for the CIO in the Era of Hybrid Work

Show your team what can go wrong

Sometimes, telling your team that cybersecurity is important isn’t enough; sometimes, you have to show them what’s actually at risk if they don’t take cybersecurity seriously.

Showing your team what happens when there’s a security breach, by sharing real, concrete examples, will help your team understand why cybersecurity needs to be a priority. And when they understand the why behind your company’s security protocols, they’re more likely to take them seriously, and your business will be more secure as a result.

If there have been any past security breaches within your company, walk your team through how they happened, how they negatively impacted your business, and the amount of time, energy, and resources it took to recover. And if your company has never had a major security breach, look for examples within your industry to speak to.

Giving real-world examples with your team of what happens when cybersecurity goes wrong takes security issues from conceptual to concrete, and the more real cybersecurity threats feel to your team, the more vigilant they’ll be about preventing them.

Run cybersecurity drills

You can train your team on cybersecurity. You can show them what can go wrong if there’s a security breach. But sometimes, in order to really understand cybersecurity threats (and, more importantly, how to avoid them)? Your team has to experience those threats for themselves

Running cybersecurity drills with your team can help you get a better sense of your team’s level of awareness around cybersecurity. For example, let’s say you simulate a phishing scam and send the phishing email out to your entire team, and find that 25 percent of your employees opened the file attached to that email. This shows you that your team needs further training around that particular cybersecurity threat, and how to prevent falling prey to a similar (but real) scam. Or let’s say you want to gauge how well your IT team would handle a security threat. You might simulate common threats (for example, adding an unregistered device to your network) and see how they respond.

The point is, sometimes the best way to learn is through experience, so if you want your team to better understand cybersecurity threats (and if you want to better understand their awareness around those threats), try giving them that experience first-hand.

Also read: [Expert Opinion] 3 Ways to Secure Your Workstations

Cyber security awareness activities for employees: 8 formats that work

The four ideas above set the direction. What follows is the toolbox: activities you can actually put in the calendar, each one short enough to survive a busy quarter. Two or three well-run sessions a year, rotated so nobody sees the same exercise twice, beat one long annual briefing that everyone forgets by November.

Eight cyber security awareness activities, and what each one reveals
ActivityFormatTime neededWhat it tells you
ActivitySimulated phishing campaignFormatAn email sent to the whole company, trackedTime needed15 min to set up, 2 weeks to runWhat it tells youClick rate and, more useful, report rate, team by team
ActivitySpot the phish quizFormatReal and fake emails side by side, answered liveTime needed20 minWhat it tells youWhich warning signs people actually read
ActivityInvoice fraud role playFormatSmall group, a fake supplier changing its bank detailsTime needed30 minWhat it tells youWhether the payment process holds when someone is in a hurry
ActivityPassword clinicFormatHands-on, password manager installed on the spotTime needed45 minWhat it tells youHow many reused passwords disappear that day
ActivityTabletop incident exerciseFormatIT and management around one scenario, no keyboardTime needed1 to 2 hoursWhat it tells youWho calls whom, in what order, and how fast
ActivityCyber escape gameFormatTeam activity, external kit or built in-houseTime needed1 hourWhat it tells youAwareness gaps, without the classroom feel
ActivityBreach post-mortem talkFormatLunch and learn on a real incident in your industryTime needed30 minWhat it tells youWhether the risk finally feels concrete
ActivityClean desk and screen lock walkFormatUnannounced walk through the office or a video call checkTime needed15 minWhat it tells youThe physical habits no training ever covers

The rhythm matters more than any single activity. October is European Cybersecurity Month, a ready-made anchor for the heaviest session of the year, and national agencies publish free material you can reuse as is, such as the Dutch NCSC for teams in the Benelux. For companies in scope of the NIS2 directive, awareness is no longer only good practice: cyber hygiene and training sit among the risk management measures the management body has to see through.

Whatever you run, keep the numbers. A click rate on a phishing simulation means nothing on its own; it means something next to the one from last quarter, and so does the count of reused passwords or the time it takes IT to escalate an alert. Tracking those figures in a secure digital workplace the whole team can see does more for vigilance than any slide deck, especially when the platform itself runs on a sovereign, qualified cloud.

Use these tips to raise cybersecurity awareness among your employees

If you want to keep your business safe, your team needs to have a clear understanding of cybersecurity. And with these tips, you have everything you need to raise awareness about cybersecurity best practices and how to avoid security risks with your team, and protect your company in the process.

Are you looking for more ways to raise cybersecurity awareness among your employees? Read this white paper to find concrete tips from CIOs and CTOs:

Access White Paper

In our white paper “CIOs: Navigating the New Challenges of Hybrid Work”, you’ll discover: the 3 major challenges for CIOs in the era of hybrid work, concrete advice on how to accelerate your digital transformation, secure your workstations and improve the employee experience, as well as testimonials from 10 CIOs working in companies, administrations and associations.

Download

Author: Deanna deBara

Best practices
Cybersecurity
Training
ARTICLE WRITTEN BY
Emmanuelle Abensur
Share article

Explore similar articles

Clarity drives progress

Frequently asked questions.

Protecting the company from cyberattacks takes more than technical measures. CIOs need to not only put the right cybersecurity protocols in place, but also ensure their teams understand what those protocols are and how to follow them.

Because working cybersecurity training into onboarding ensures every employee is aware of the protocols from day one, and shows them the company takes cybersecurity seriously. The earlier you introduce it, the higher their awareness will be and the less likely they are to have security-related issues.

The ones that fit in a busy calendar and measure something: a simulated phishing campaign, a spot the phish quiz, an invoice fraud role play, a hands-on password clinic, a tabletop incident exercise, a cyber escape game, a talk on a real breach in your industry, and an unannounced clean desk walk. Each takes between 15 minutes and 2 hours, and two or three a year work better than one long annual briefing.

Basic training for the whole team, whether or not they sit in IT: securing a home network and a home router, reaching company files, tools and data safely from anywhere, setting strong, unique passwords and switching on multi-factor authentication, and recognising a suspicious message and reporting it without fear of looking silly. More targeted training can then be added by role, department or common threat, such as teaching the accounting team to spot financial scams.

Because showing what happens when there is a security breach, through real and concrete examples, helps the team understand why security has to be a priority. Walk them through past breaches within the company, how they hurt the business and what recovery cost; if there have been none, use examples from your industry.

In the article's example, simulating a phishing scam sent to the entire team revealed that 25 percent of employees opened the file attached to that email, showing the team needed further training on that particular threat. The same approach can gauge how the IT team handles a simulated threat, such as an unregistered device added to the network.