From Cyber Awareness to Secure Behavior
Cyber awareness only creates value when it changes what people do. This session explores practical ways to turn knowledge into secure everyday behavior through nano learning, targeted training, shared ownership and continuous reinforcement, helping organizations build a stronger and more resilient security culture.
From awareness to behavior
Traditional annual training often struggles to create lasting change. Short, relevant and continuous nano learning keeps security top of mind while fitting naturally into the workday. By combining repetition, motivation and simplicity, organizations can make secure behavior easier to understand, remember and apply in real situations.
Make training relevant and measurable
Effective awareness programs reflect different roles, cultures, languages and risk profiles. Human risk assessment can help identify where training is needed most and tailor content accordingly. Automated delivery and reporting also reduce administrative effort, while giving relevant stakeholders the insights they need to take ownership of security behavior.
Build a shared security culture
Security is not an IT responsibility alone. HR, IT, compliance and leadership all have important roles in embedding security into everyday work. Shared KPIs, visible leadership support, realistic simulations, recognition and continuous nudging can turn security from a set of rules into a collective habit, making the organization more resilient.
From Cyber Awareness to Secure Behavior
Cyber awareness only creates value when it changes what people do. This session explores practical ways to turn knowledge into secure everyday behavior through nano learning, targeted training, shared ownership and continuous reinforcement, helping organizations build a stronger and more resilient security culture.
From awareness to behavior
Traditional annual training often struggles to create lasting change. Short, relevant and continuous nano learning keeps security top of mind while fitting naturally into the workday. By combining repetition, motivation and simplicity, organizations can make secure behavior easier to understand, remember and apply in real situations.
Make training relevant and measurable
Effective awareness programs reflect different roles, cultures, languages and risk profiles. Human risk assessment can help identify where training is needed most and tailor content accordingly. Automated delivery and reporting also reduce administrative effort, while giving relevant stakeholders the insights they need to take ownership of security behavior.
Build a shared security culture
Security is not an IT responsibility alone. HR, IT, compliance and leadership all have important roles in embedding security into everyday work. Shared KPIs, visible leadership support, realistic simulations, recognition and continuous nudging can turn security from a set of rules into a collective habit, making the organization more resilient.
View transcript
Good morning everyone and also I see that we have people from Paris this morning. Very nice. Good morning to you as well. And thank you for spending this 20-30 minutes with me this morning. I promise to keep it short and actionable. Today's topic is simple but it's a critical one. How do we move from cyber awareness to actual secure behavior? Because let's be honest, most organizations already have awareness. The real problem is that it doesn't really translate into actions. Threats evolve every single day. We invest quite heavily in technology. But technology alone is no longer enough. People are still the most exposed attack surface and at the same time they are our biggest untapped defense layer. So the question for today is how do we enable employees to act securely, consistently and at scale? I'll work you through practical approaches you can take straight back into your organization and please use the chat throughout. I'll pick up questions at the end but share your thoughts along the way. My goal today is quite simple. It's that you leave this session with concrete tools that you can start using immediately. Not just theory, not just more awareness. Things that you can apply from tomorrow. So here's the journey that we're going to follow today. Why traditional awareness training doesn't work. How we turn learning into behavioral change. And how we build a strong security culture. And then we close up with a short Q&A. So who am I? Before I moved into cyber awareness and security many years ago, I was an elite cyclist for the national team. The background taught me one thing above all. Performance is not just about training harder. It's about habits, motivation and working deliberately with behavioral change. And that's exactly the parallel to cyber awareness. As its core, awareness training is not about knowledge. It's about motivating people to build new secure habits. Approach it that way. Keep nudging the culture and that's when you'll see the real lasting change in your organization. Across many organizations, we see the same pattern. Significant investments in strong awareness solution. But the effect fades quickly. There are two clear reasons for that. First, the training is too long and too theoretical. It doesn't connect to employees everyday reality. And second, it's too infrequent. One long session a year, maybe one per quarter, and most of it is forgotten shortly after. So while the intention is good, but the behavioral impact is limited. This is not about more training. It's about better trailing, relevant, engaging and easy to turn into daily behavior. So let's just start with the reality. Up to 95% of cybersecurity breaches involve human error. That makes awareness training business critical. Not a nice to have. But it only works when it's behavioral driven and embedded into daily workflows. That's exactly where nano learning makes the difference. Repetition and nudging small continuous inputs that keep security top of mind. The format matters too. Short modules on mobile or desktop without disrupting the workday. And the results are clear. Consistency, consistently higher awareness level and up to 50% fewer errors in phishing simulations. That's a measurable return on investment. Fewer incidents, less downtime and stronger trust from customers and stakeholders. So let's dive into it. Look at the difference on this slide. So we have the traditional training sessions. They are 15 to 30 minutes, once a year or once a quarter, hard to hold attention and even harder to retain afterwards. Nano learning flips that. One or two minutes, one or two videos per month spread across the whole year. Employees get ongoing small nudges always aligned with the current threats and real world risks. And that is what drives behavior. Awareness that stays consistently high all year round. So what do we actually mean by nano learning? It's short and precise. One or two minutes, one idea, one subject, one skill position. It's on demand, so it fits naturally into the workday. And it uses a mix of formats, video, quizzes, infographics, interactives and the workday. And why does this work? Because motivation drops fast often after just 90 seconds when sitting in front of a screen. And when the content sits outside our area of interest, which awareness training does for most. Visuals improve the retention and make real incidents easier to recognize when they happen. Audio adds the emotion and emotion is what drives the learning. In short, this is learning that is designed around how we learn best as humans or how we actually learn. So the real challenge is not giving people knowledge. It's changing behavior. Knowing what to do is one thing. Actually doing it in a busy workday is something completely different. Three things that makes a huge difference. The motivation. People must want to act securely. The repetition. Reinforce the behavior over time. And simplicity. Make the secure choice the easy choice. If it isn't easy and relevant, it simply won't happen in practice. So, awareness training has to reflect the reality of your organization. Different cultures, different roles, different languages. If people don't recognize themselves in the content, they simply won't engage. At the same time, accessibility is key. Not just the work laptop, but any device. The easier it is to access, the more people actually use it. That's how awareness reaches everyone, not just a subset of the organization. When we address cyber risk, we tend to default to technical solutions. And in doing so, we overlook the human factor. But our employees are on the front line. Phishing emails, social engineering, and everyday threats coming up. If we only invest in technology, we don't change how people behave. What happens instead? IT inherits the task. More workload tasks that are really about behavior and culture. And no increase in actual awareness. The fix needs to sit where the risk sits. Technology doesn't solve the human problem and the human factor. So to create the real impact, we need to move towards risk-based training. That measures, that means tailoring content to each employee's risk profile. The role, behavior, and their exposure. And delivering in a smart, automated way. So impact scales without extra complexity or workload. Just as important, where the responsibility sits. If awareness stays centralized in IT or HR, it becomes disconnected from the daily operation. Push ownership out into the teams where the risk actually exists. A team need following up directly beats a central email every time from IT, for example. That's how awareness becomes a part of the culture, not just a central initiative. The best documented, most effective training approaches we see all share one thing. They are flexible and adaptable. One size fits all simply doesn't work when it comes to behavior. The training must feel relevant to the individual or engagement drops immediately. It must be engaging so people actually pay attention and it must be easy to implement and act on. If we feel complex or disconnected from daily work, it won't become a behavior. When building your awareness setup, start with a platform that has a strong proven foundation. Structure and scalability matters here. But here's the key point. Generic content rarely works on its own. If it doesn't reflect your organization, your culture, and your real risk, it won't stick. So work with a partner who can translate your reality into relevant content. Videos, animation, and learning modules aligned with your branding, tone of voice, and internal language. A partner who can develop content on specific topics, write scripts, produce voiceovers in multiple languages. And everything delivered in a format that plugs straight into your LMS. So everything we covered up here points to one goal. A strong security culture. Where security is a natural part of our everyday work. That takes more than policies and rules. It takes new habits and new behavior. Engage employees, recognize good behavior, make it easy to do the right thing. Get that right and you create a culture that makes the whole organization more resilient to threats. Okay, so a strong security culture is never built by IT alone. Surprise. It takes HR, IT, and compliance working together, each bringing their own strengths. HR embeds awareness into the onboarding and employee development. IT provides the technical framework and risk data. Compliance keeps you audit ready. And how do we make that ownership truly shared? Shared KPIs that measure security behavior, not just the technical metrics. Regular dialogue across all three functions. And above all, visible leadership support. When the leadership clearly signals that security is a shared responsibility, the organization follows. And I will say that again. When leadership clearly signals the security is a shared responsibility, the organization follows. Super important here. One of the biggest levers in awareness is placing ownership in the right place. Find a partner that can use automated reporting. With automated reporting, risk insights go directly to the relevant stakeholders across the organization. Ownership is no longer locked in in AT, IT, or compliance. It sits where the risk actually exists in the organization. And that's a big shift. Instead of IT chasing people around, the organization becomes self-aware and accountable. It significantly reduces the workload for everyone running the program. And it enables a far more scalable and sustainable approach. Not just more awareness. Awareness that actually works in the organization. So the journey is from rules to culture. Security as everyday behavior. Not just something we comply with. Recognize and reward the right behavior. Gamification, badges, points, team competition, competitions, manager shoutouts, whatever you have of great ideas here. It's great to use. And use the data from your LMS to measure impact and document the actual behavioral change. Keep knowledge alive with nudging and microlearning. Reinforcing over time. And build engagement through realistic cases and simulations. That's what turns security into something people actively take part in. So, let's wrap up the five key takeaways for today. Nano learning beats traditional training. Short, targeted and continuous. Integrate and automate everything you can. When it runs with your existing systems, you get maximum impact with minimal operational effort. So, build a culture of shared responsibility. Measure behavior. Identify risk. And place the ownership where the risk lies. An important one here. It's really important that you push it out in the organization. So, the responsibility is not lies within IT, HR compliance. Put it, you know, push the responsibility out towards the leaders in the organization. Use human risk assessment to move from your gut feeling. Move the training from your gut feeling to data based training. Tailored to each employee's risk profile, behavior and exposure in the market. Focus the effort where the real need is greatest. And the business case is real here. Save time and money with the targeted awareness that actually works in practice by using the human risk assessment. Good. So, that was actually it for today's webinar. A quick run over of the awareness agenda. If you have any questions, feel free to write them in the chat right now. I'll take a few minutes waiting. Maybe one minute. And yeah, feel free to write whatever questions you have. I can see that one came in during the webinar. How do we make training relevant beyond IT? I think we already touched a little bit upon it, but tailor it really. Structure the year around an annual cycle based on the risk assessment that you do in the organization. Maybe give different parts of the organization different targeted content. Actually, not maybe. That's quite important. And place the local ownership with the department leaders. So, training is completed and embedded into the organization instead of just lying in IT. Yeah. Okay. We have another one here. What role do leadership and culture play? As I repeated myself before, quite a critical one. Awareness only works when the message is anchored from the top and reinforced together with IT, HR compliance and the wider organization. The best practice is that leadership leads by example. When leadership signals that this matters, the organization will often, most often follows as we see it. And if anything comes up after this webinar, feel free to reach out to me. But really, what we see also when introducing awareness, it's a good idea that we have one of the top leaders going in front of the camera and maybe speaking to the rest of the organization about why we took an initiative to actually start doing a little more awareness training or why we're switching to nano learning and so on. Okay. Okay. I don't see any more questions. So, I will just leave it here and wish you all a great day. See you. Thank you.