Security awareness training
Revamping security awareness training with the GLB-90 Method
A practical video and guide for security leaders, HR teams, founders and operators who need awareness training to move beyond annual compliance and become role-based, continuous and behaviour-led.
Watch the video
Revamping Security Awareness Training | The GLB-90 Method for Building a Cyber-Aware Workforce
What this video covers
This video introduces the GLB-90 Method as a way to turn awareness training from a one-off compliance exercise into a practical operating rhythm that improves engagement, confidence and everyday security behaviour.
- Why traditional compliance-led awareness training often fails to change behaviour.
- How to make cyber security feel relevant to the decisions employees make every day.
- How to build a continuous programme across campaigns, role-based training and reinforcement.
- How to track improvement using signals beyond module completion.
Before choosing topics, define the behaviours you need to improve. Awareness training should help people recognise risky moments, know what to do next and feel safe reporting concerns quickly.
The problem
Why traditional security awareness training fails
Many awareness programmes are designed around completion, not capability. People are asked to click through a module, pass a short quiz and move on. That may satisfy a reporting requirement, but it rarely creates the judgement, confidence or habits needed in real situations.
It is too generic
The same message is sent to everyone, even though finance, HR, engineering, customer support and senior leaders face different security decisions.
It is too infrequent
Annual training leaves long gaps between learning and real-world application. People forget what they do not repeatedly use.
It feels separate from work
Security is often presented as a rulebook rather than a useful part of how people buy tools, share data, manage access, approve payments or handle client information.
Framework
How the GLB-90 Method changes the awareness conversation
The GLB-90 Method is useful because it treats awareness as an operating rhythm. Instead of relying on a single training event, it uses a structured 90-day cycle to build understanding, reinforce behaviour and show practical progress.
Start with behaviour
Choose the behaviours that matter most: reporting suspicious emails, protecting credentials, checking payment changes, handling sensitive data or challenging unusual requests.
Make it role-based
Adapt examples, scenarios and responsibilities by team so the training feels connected to people’s real decisions rather than generic security advice.
Reinforce for 90 days
Use reminders, manager prompts, phishing simulations, team briefings, micro-learning and practical nudges to keep awareness alive after launch.
Practical shift
From compliance training to security culture
Compliance-only awareness
- Annual module with limited follow-up.
- Same content for every role.
- Success measured mainly by completion rate.
- Employees remember the policy, but not always the action.
- Security feels like something done to satisfy audit.
Behaviour-led awareness
- Ongoing rhythm of reminders, examples and team conversations.
- Role-based security awareness training linked to daily work.
- Success measured by reporting quality, behaviour signals and reduced repeat mistakes.
- Employees know what to do in risky moments.
- Security becomes part of how the organisation operates.
Role-based design
Role-based security awareness training examples
A strong programme translates security into the risks each team is most likely to face. The message should be consistent, but the scenarios should feel familiar to the audience.
| Audience | Training focus | Practical scenario | Behaviour to reinforce |
|---|---|---|---|
| Finance | Payment fraud, invoice redirection, approval discipline and suspicious requests. | A supplier emails new bank details shortly before a payment deadline. | Verify changes through an approved channel before processing payment. |
| HR and People teams | Employee data, onboarding, offboarding, sensitive documents and impersonation. | A message asks for payroll information or a change to employee details. | Check identity, protect personal data and follow approved update procedures. |
| Engineering and Product | Secure design decisions, secrets, code repositories, access and production changes. | A deadline creates pressure to bypass review or share credentials informally. | Use secure workflows even when delivery pressure increases. |
| Sales and Customer Success | Client data, due diligence, contract promises, demos and information sharing. | A prospect asks for security evidence or sensitive customer examples. | Use approved evidence, avoid over-sharing and route questions correctly. |
| Senior leaders | Business email compromise, decision pressure, governance and visible sponsorship. | An urgent request appears to come from a senior executive or external partner. | Model calm verification, support reporting and avoid normalising shortcuts. |
Compliance
How to make compliance security awareness training more useful
Compliance awareness training should still produce evidence, but it should also improve how people handle risk. The best programmes satisfy governance needs while making the content more practical for the workforce.
| Requirement | Weak approach | Stronger approach |
|---|---|---|
| Training records | Track completion only. | Track completion, follow-up reminders, role coverage and repeat non-completion. |
| Policy understanding | Ask employees to acknowledge a policy once a year. | Connect policies to practical scenarios, decisions and reporting routes. |
| Phishing awareness | Run a simulation and name click rates as the main result. | Measure reporting rates, repeat patterns, quality of follow-up and team-specific improvement. |
| Audit evidence | Store a spreadsheet of names and dates. | Keep evidence of content, audience, role coverage, communications, results and improvement actions. |
| Leadership oversight | Report that training was completed. | Report changes in behaviour, risk themes, engagement gaps and actions needed from leadership. |
Rollout
A practical 90-day awareness training rollout
A 90-day cycle gives the programme enough structure to launch, reinforce and review without overwhelming the business. It also creates a natural rhythm for reporting progress.
Baseline and focus
Review recent incidents, phishing results, audit findings, policy gaps and business changes. Choose the behaviours and audiences that need attention first.
- Define priority behaviours.
- Segment audiences by role.
- Agree reporting and ownership.
Launch and reinforce
Run the main campaign, but support it with manager prompts, practical examples, micro-messages and clear reporting routes.
- Deliver training and communications.
- Run role-specific scenarios.
- Make reporting simple and visible.
Measure and improve
Review engagement, reporting behaviour, repeat mistakes, questions raised and leadership feedback. Turn the findings into the next improvement cycle.
- Compare signals by audience.
- Identify friction and confusion.
- Update the next campaign plan.
Measurement
What to measure beyond completion rates
Completion rates tell you whether people finished the task. They do not tell you whether the workforce is becoming more cyber-aware. Use a wider set of signals to understand whether the programme is changing behaviour.
| Signal | What it can show | How to use it |
|---|---|---|
| Reporting rate | Whether employees are spotting and escalating suspicious activity. | Track reported phishing, suspicious requests and security questions over time. |
| Repeat themes | Where the same risky behaviour or confusion keeps appearing. | Use themes to choose future micro-learning and manager briefings. |
| Role coverage | Whether higher-risk teams have received relevant training. | Map training to departments, systems, data access and business processes. |
| Response quality | Whether people know the correct next step in risky situations. | Review how quickly incidents, suspicious emails and access concerns are escalated. |
| Leadership engagement | Whether managers and executives are reinforcing secure behaviour. | Include awareness messages in team meetings, onboarding and operational reviews. |
Programme design
What a stronger security awareness programme should include
Core annual training
Keep the required baseline, but make it easier to understand and connect it to real decisions: passwords, MFA, phishing, data handling, incident reporting, device security and acceptable use.
Role-based campaigns
Create focused training for teams exposed to specific risks, such as finance fraud, HR data protection, engineering secrets, customer data or executive impersonation.
Manager reinforcement
Give managers short prompts they can use in team meetings so cyber awareness does not depend only on the security team sending emails.
Reporting confidence
Make it normal to report early. Employees should know that reporting a mistake quickly is better than hiding uncertainty until the risk grows.
Related resources
Continue building a more cyber-aware workforce
FAQs
Security awareness training FAQs
How do you revamp security awareness training?
Start by identifying the behaviours you need to improve, then segment training by audience, use practical scenarios, reinforce messages over time and measure signals such as reporting quality, repeat mistakes and role coverage rather than relying only on completion rates.
What is role-based security awareness training?
Role-based security awareness training adapts cyber security guidance to the risks different teams face. For example, finance may need payment fraud scenarios, HR may need employee data scenarios and engineering may need training on secrets, access and secure development workflows.
How is compliance security awareness training different from security culture?
Compliance security awareness training often focuses on proving that training happened. Security culture goes further by making secure behaviour part of everyday work, decision-making, reporting and leadership expectations.
How often should security awareness training happen?
Most organisations benefit from a baseline annual training requirement plus more frequent reinforcement. Short monthly or quarterly campaigns, phishing simulations, manager prompts and role-specific reminders usually keep awareness more active than a once-a-year module alone.
What should be included in a cyber awareness programme?
A cyber awareness programme should usually include phishing awareness, password and MFA guidance, data handling, incident reporting, device security, social engineering, role-based scenarios, policy reminders, leadership messaging and measurement of behaviour signals.
How do you measure whether awareness training is working?
Measure completion rates, but also track reporting rates, repeat risk themes, quality of escalations, role coverage, questions raised, incident trends, phishing simulation outcomes and whether managers are reinforcing the expected behaviours.
Who should own security awareness training?
Security often owns the programme, but HR, learning and development, communications, managers and senior leaders all play important roles. The most effective programmes make awareness a shared business responsibility rather than a security-only broadcast.
Next step
Need a security awareness programme people actually remember?
Use a structured approach to design role-based training, practical campaigns, reporting routines and leadership updates that turn cyber awareness into a repeatable business habit.