Build cyber habits that last
Cyber awareness only creates value when it turns into action. In this webinar, Markus Berg-Urhammer shares practical ways to build secure habits, use nano learning effectively and anchor security ownership across the organisation, so teams can reduce human risk in a measurable and lasting way.
Why awareness often falls short
Many organisations already invest in awareness training, but long and infrequent sessions rarely change behaviour. Employees forget the content quickly, and generic messages often feel disconnected from their daily work. Real impact comes from training that is relevant, simple and easy to act on.
How nano learning creates change
Nano learning uses short, focused sessions delivered continuously across the year. This keeps attention high and makes security part of everyday routines instead of a one off activity. Combined with strong visuals, real human scenarios and repetition, it helps employees turn knowledge into consistent secure behaviour.
How to build a stronger security culture
A lasting security culture requires shared ownership across leadership, HR, IT and compliance. Risk based training, automated reporting and human risk assessments make it easier to target the right people with the right content. This reduces human error, supports compliance and strengthens trust with customers and stakeholders.
Build cyber habits that last
Cyber awareness only creates value when it turns into action. In this webinar, Markus Berg-Urhammer shares practical ways to build secure habits, use nano learning effectively and anchor security ownership across the organisation, so teams can reduce human risk in a measurable and lasting way.
Why awareness often falls short
Many organisations already invest in awareness training, but long and infrequent sessions rarely change behaviour. Employees forget the content quickly, and generic messages often feel disconnected from their daily work. Real impact comes from training that is relevant, simple and easy to act on.
How nano learning creates change
Nano learning uses short, focused sessions delivered continuously across the year. This keeps attention high and makes security part of everyday routines instead of a one off activity. Combined with strong visuals, real human scenarios and repetition, it helps employees turn knowledge into consistent secure behaviour.
How to build a stronger security culture
A lasting security culture requires shared ownership across leadership, HR, IT and compliance. Risk based training, automated reporting and human risk assessments make it easier to target the right people with the right content. This reduces human error, supports compliance and strengthens trust with customers and stakeholders.
View transcript
So, all good. Welcome everyone and thanks for spending this 30 minutes, 25-30 minutes with me this morning. I'll try to keep it sharp and actionable. Today's topic is simple but a critical one. How do we move from cyber awareness to actual secure behavior in our organizations? Because let's be honest, most organizations already have some kind of awareness solution. The real problem is it doesn't consistently translate into actions. Cyber threats are evolving constantly and while we are invested quite heavily in technology, technology alone is not enough. The reality is the people are our most exposed attack surface, but at the same time they are also our biggest untapped defense layer. So the question we'll explore today is how do we actually train and enable employees to act securely in our organization and also so they do it consistently at a scale. I'll walk you through a few practical perspectives and approaches you can take directly back and use in your organization after today's webinar. Feel free to use the chat that we have here. I will try to sum up the questions in the end. And also feel free to reach out afterwards if you have any further questions. All right. Before doing a short presentation of myself, I just want to run you quickly through the agenda here. As I said before, I hope that you leave today with some concrete tools and inspiration that you can start using immediately. Not theory, not more awareness, but things that you can actually apply in your organization from tomorrow. I don't want to read the agenda loud. You can see that here on the slide. Good. So who am I? My name is Markus Berg-Urhammer and I work in the Tech Collective, which is a part of Implement Consulting Group. I'm the leader of our CTP department, which stands for Cyber Tech Products. I'm not going to go too deep into that now. I just want to give you a short brief of my background. Before I moved into cyber awareness and security, I was an athlete in cycling. And that background gave me a strong interest in how to optimize performance across all aspects of life, both the physical part, but also the mental part. In elite sport, it's not just about training. It's about building the right habits, staying motivated, and working quite deliberately with behavioral change. And that's exactly where I see the parallels to cyber awareness that we're going to talk about today. Because if you go to its core, awareness training is not about the knowledge that we give people. It's about motivating the people, helping them build new, secure habits. So that's what we will be trying to be exploring today. And we're going to try to explore how to approach it, nudging the security culture to see and change the security culture in the company. Let's get started. What we've seen across many organizations is that they make quite significant investments in strong awareness solution, but we see that the effect fades quite quickly. And there are a few clear reasons for that. First, the training is often too long and too theoretical. It doesn't connect to employees' everyday reality. Second, it's simply too infrequent. People might get one long session a year or maybe once every quarter, and then forget most of it shortly after the session. So while the attention of doing awareness training is good, the behavioral impact is often limited. And if we want to change that, we need to understand why this happens. Because it isn't about just doing more training. It's about doing, you know, the training better. Training that's relevant, engaging and easy to translate into your everyday behaviors. So, if we look at the difference here, we have two curves. There's one on the left, that's the old traditional training method, and there's one on the right, that's the nano learning concept. So if we look at the difference between the traditional training and the nano learning, traditional training often or typically consists of long session, 15 to 30 minute session, often delivered once a year or once every quarter. And the challenge here is quite obvious. It's hard to maintain attention and it's even harder to retain the content afterwards. Nano learning takes a different approach. In nano learning we do short focus sessions, typically two to four minutes or less, distributed across the year, every month we deliver these. This makes it quite easier to keep people engaged and continuously aligned with the content. continuously aligned training with the current threats that are in the real world risks, that are the real world risks. And that's where the real value comes in. Instead of a one time effort, employees receive ongoing small nudges, and that's what really changes and drives the behavior, keeping the awareness high consistently throughout the year. And that's also what we've been trying to visualizing here, that we don't want these high risk periods where we are not aware. We want that consistent new training, so we always keep the awareness level high. The threat is ongoing and every day, so we need that awareness level. Good. So what do we actually mean when we say nano learning? So it's a short, precise session, typically two to four minutes, as I mentioned before, focused on a single idea or a skill at a time. The content is available on demand, so employees can engage with it whenever it feels natural into their everyday work life. And then we use a mix of formats, video, quizzes, infographics, micro learning modules, etc. Both interactives and passive elements. Now, why is it that this works? It is because short sessions maintain the attention and motivation in a much higher grade. We avoid losing people after the first 60 to 90 seconds where they are most motivated, as you can see on the curve here. And then we focus on the three most important elements when we learn in front of a screen. There's time. We already talked about that. The visuals, super, super important. If we look at an animated figure that's doing something, it's fine, but it doesn't really wake any feeling in us as humans. So we need to have some kind of material. We need real humans, real feelings in the videos for us as humans to learn the best. And in the end, it's the audio. We all try to see in a movie without audio. It's not super interesting. And ultimately, you know, it's all about optimizing the learning. Good. So the real challenge here, and I think I mentioned that in the beginning as well, it's not giving people the knowledge. It's to change the behavior and, you know, getting people to use the knowledge that they have in a good way. Because knowing what to do is certainly one thing, but actually doing so in a busy work day with a full calendar is something totally different. So the key question becomes here, how do we ensure that learning translates into action? And this is where we need to shift our focus. It's about motivation, making people want to act securely. It's about repetition, sending out these contents once a month, reinforcing behavior over time. And then it's about simplicity, making it easier to turn learning into concrete actions. Because it's not easy to get an organization to see and watch this, but we need to be as good as possible. Yeah. Awareness training needs to reflect the reality of the organization. You know, different cultures, roles, languages. If people don't recognize themselves in the content, they simply won't engage. Back to the thing I mentioned before with the visuals that are important. At the same time, accessibility is key. Training shouldn't be limited to a laptop. It needs to work seamlessly across, you know, different devices that they have in their pockets and on the go as well. Because the easier it is to access, the more likely people are to actually use it. And ultimately, this is what ensures the awareness becomes something that reaches everyone, not just a subset of the organization. We often default to technical solutions when addressing cyber risk. But in doing so, we tend to overlook the human factor, or at least we did. I see the last year that organizations have really become better and better about the human firewall strengthening that. But yeah, employees are not, you know, on the front line. They are on the front line, sorry, dealing with phishing mail, soldier engineering and everyday threats. And if we only invest in our technology, we don't actually change how the people behave. Obviously, there need to be technology behind the awareness solution. But, you know, we don't want that IT ends up taking on more responsibility and often task that they are more about behavior and culture in the technology. Good. So, human risk assessment. To create real impact, we need to move towards risk-based training. That means adapting content to the individual employee and to its risk profile based on their role, behavior and exposure. At the same time, it needs to be delivered in a smart, automated way. So, we maximize impact without adding unnecessary complexity or workload to our organization. But just as important is where the responsibility sits. If awareness, as I said before, stays centralized in IT or HR or even our compliance department, it becomes disconnected from the daily operations. Instead, we need to push ownership out into the organization, into teams and departments where the actual risk does exist. Because it's much easier for a team lead to follow up directly than relying on central email from IT or HR or compliance department. These are also often ignored. And that's how awareness becomes a part of the culture, not just a central initiative. So, diving in a little more into the training method. What we see from well-documented and effective training approaches is that they are built around flexibility and adaption. One size fits all, simply doesn't work when it comes to behavior. It's fine having some kind of onboarding for new employees, but the training needs to be relevant for the individual. Otherwise, engagement will just drop immediately. So, it needs to be engaging so people actually can pay attention. And just as importantly, it needs to be easy to implement and act on. Because if it feels too complex or disconnected from their daily work, it won't translate into actual behavioral change. So, when building your awareness setup, start with a platform that has a strong and proven foundation. Our recommendation is nano learning for sure. That's how we learn best in front of a screen. But, yeah, start with something strong that has a strong and proven platform. Because the structure will matter. But there are a few key points. Like generic content rarely works on its own. And if it doesn't reflect, how to say, your organization, your culture and your risks, it simply won't stick with the employees. And that's why it's quite important to work with a partner who can also translate your reality into relevant content. And that includes videos, live acting, maybe in some certain animations and learning modules. All aligned, you know, with your branding, your tone of voice, your internal language. Maybe even one of your C-level speaking in front of the screen to talk about security in our organization. All these parts are important parts of creating this great culture. So, find a partner that can develop content on specific topics, write scripts and produce the voiceovers in all these multiple languages that meet your culture. And obviously, everything needs to be delivered in a format so it fits your current learning management system, your LMS. And then, let's just touch this quickly. So, we know that up to 95% of cybersecurity incidents involve human error. And that's why awareness training is not nice to have, it's quite business critical. We already touched on this, but it's behavioral driven and embedded into your everyday workflows. This is where we really see the change. And that's where nano learning makes a big difference. Repetition and nudging are key. Small continuous inputs over time. Security, top of mind. The format of the modules also matters a lot. Short models can be accessed on mobiles or desktops without disrupting the everyday workday. And we're seeing clear results when organizations do this. Organizations actually using this approach achieve quite consistently higher awareness levels and up to 50% fewer errors in our human risk assessment. And if we sometimes do phishing simulations. We don't do phishing simulations a lot because they only tell us a number on how many clicked and how many gave up their credentials. We'd rather use the human risk assessment approach, which is more modern, that can give us actionable training and specific training for specific employees afterwards. So, it's simply an investment, investing into the awareness, but it's a measurable return on investment when we see the fewer incidents, when we see the less operational disruptions. And ultimately, we also build stronger trust from our customer and stakeholders when doing so. Good. What's the time? See. So, the goal is to build a strong security culture. We want a place where security becomes a natural part of our everyday work. And that requires more than policies and rules. It's about changing habits and behavior. We need to engage the employees, recognize good behavior, and make it easy to do the right thing. Yeah. So, to build a strong security culture, we already talked a little bit about this, but it's quite an important topic. So, I'll just try to walk you through this slide. IT cannot stand alone anymore. It requires collaboration between HR, IT, and compliance, each bringing their own strengths. We need shared goals, including KPIs that measure security behavior, not just the technical metrics. This also requires ongoing communication in the organization, regular dialogue across departments, and most importantly, as I also mentioned before, visible leadership support. Leadership needs to clearly signal the security as a shared responsibility. Finally, awareness, it must be embedded into the onboarding and the employee development. So, it becomes a natural part of the culture. And just touching upon that leadership part, it can be as simple as a leader going out on the screen saying, we did this for our organization, we want to heighten our security culture, etc., etc. That heightens the security culture a lot. But also, you should see this triangle as the top of the Christmas tree. So, HR, IT, and compliance sit on top of the Christmas tree, having the shared ownership of the awareness solution that you have. And then, the Christmas trees go down, but all the team leaders in the Christmas tree are branches down, and they have the responsibility for their own employees. Back to the talk that we had before about sharing the ownership or pushing it into the organization where the actual risk lies. All right. Good. So, one of the key challenges in awareness is placing the ownership in the right place. And one way of doing so is with automated reporting. So, you can send risk-related insights directly to the relevant stakeholders across the organization. That means that the ownership is no longer, as I mentioned before, in IT, HR compliance. It's place where the risk actually exists. And that's a big shift because instead of IT chasing people, the organization becomes self-aware and actionable. Even the team lead can have some kind of KPIs on this. But at the same time, it significantly reduces the workload for both IT and others involved in running the awareness program. So, it enables, when doing so, a much more scalable and sustainable approach to awareness. And not just awareness, awareness that actually works in the organization. Yeah. We need to move a little bit from rules to culture, where security becomes a part of our behavior, not just something we comply with. And that requires us to recognize and reward good behavior through things like gamification, badges, storytelling, certificates when actually completing the training. But at the same time, we should use the data from our LMS to measure impact and document actual behavioral change. And we can, yeah, find a partner that can do that. That's quite important. Nudging and microlearning play a key role here. We talked about that. But that's keeping the awareness level high and reinforcing the knowledge over time. And finally, engagement matters by using realistic cases, simulations and shareable achievements. As an organization, we create motivation and we make security something that people can actually participate in and actually do watch instead of just, going, grabbing a cup of coffee when watching that one long session that's coming out every quarter. So, to wrap up, nano learning is simply more effective than traditional awareness. It's short, it's targeted and it's continuous. And it's not something I'm just saying. It's short from many studies that I would love to share with you afterwards if you're interested. So, when integrated with your existing system, it should run automatically with minimal operational effort from where the solution is centralized. At the same time, we need to build a culture of shared responsibility, not just one person, but out in the whole organization. Where we measure behavior, we identify the risk, and we continuously strengthen the organization by placing ownership where the risk lies. Human risk assessment, the new phishing, if I can say so, helps us move from generic awareness to risk-based learning and removing the gut feeling training into database training. It allows training to be tailored into the, how do you say, the employee's risk profile and their behavior and the exposure throughout the organization. That means we focus effort where the need is greatest. And it simply makes awareness more relevant, more targeted and more effective in practice. And ultimately, like this whole approach helps you save both time and cost while you significantly increases the effectiveness of your awareness efforts and awareness culture. All right. So, on purpose, we left a little bit of time for some questions. So, I'll just have a look in the chat here. So, where are our biggest risks in the organization? That's hard to tell, really. That's from organization to organization. But it's a very strong starting point is to take the pools of the organization through a human risk assessment. So, we do help a lot of people with these awareness solutions. Some tend to just say, we want this in our on-burning schedule. But the more measurable way is doing an actual human risk assessment. So, you know that you have a clear data-driven view of where the vulnerabilities actually exist across departments, across roles and employees. And then it also moves the conversation from assumptions to real insights. So, you can prioritize your efforts where it matters the most. Let's see. Anita, you have asked, how do I make the argument for this kind of investment time from the organization and money? We don't have operational disruptions to human error, dot, dot, dot, yet. Well, that's a great question. Thank you. But the question I just answered actually answers that a little bit as well. So, training have historically tend to be a gut feeling, right? We feel that we should do some kind of phishing training. Oh, our password is not good enough. Let's do some training about that, et cetera. So, if you can argument that you have an actual data-driven approach towards training, you can also argument that you will get a, how to say it, like a year-on-year assessment that proves that your security culture gets better and better. So, that's how I would approach it, starting out by making an assessment, see where is our organization. We score 40 out of 100. We want to lift it towards 70. And there you have a business case. And we have one more question here. How do we ensure training feels relevant for all employees and not just the IT department? Well, the relevance comes from tailoring the training. Typically, we would structure it around an annual cycle that allows us to define the training based on the risk assessment. And then different parts of the organization receive different targeted content. That's how we would do it. And then, obviously, around Christmas and during the summer holidays and stuff, we would have more focus on certain matters there than we would at the rest of the year. Because we see a lot of fishing, especially during the Christmas time where we get all these notifications from our delivery, GLS, and POSNO and DAO, etc. So, we would have a big focus on that in these periods. But we will make an annual cycle based off a human risk assessment. Okay. I think we have time for one last question here. What role do leadership and culture play? I think that was one of the first ones, actually. I think we answered that a little bit already. But the leadership simply just plays a critical role in this. Awareness does only work when the message is clearly anchored from the top and reinforced in collaboration with the IT, the HR, the compliance department, and then also wider in the organization. The best practice here is simply that the leadership leads by example and actively support a structural awareness roadmap. And it doesn't have to be that complex. As I said before, a few minutes on a video can change a lot. And you just integrate that into the platform and send that out as the first thing that we want to do this and we want to strengthen our culture. And that's why, etc. etc. By doing so, you come very, very far and then it's anchored from the top. Good. I don't see any more questions. So, I think from here on, I hope that you have some great insights from us, at least on how we approach the awareness agenda. My contact information is here. I'm sure looking at you, Dimas, we will also share the slides afterwards. Yeah, we will. So, you will have them. And in there you can also find my contact information if you want a further talk around this topic. We didn't have the time to talk around frameworks, but awareness training is becoming a quite key part in living up to different standards around EU. So, if you also like a talk around that, NIST 2, etc. We can also do that. But thank you so much from here and I hope that you all have a great day. Bye-bye.