Security awareness training

Revamping security awareness training with the GLB-90 Method

A practical video and guide for security leaders, HR teams, founders and operators who need awareness training to move beyond annual compliance and become role-based, continuous and behaviour-led.

Watch the video

Revamping Security Awareness Training | The GLB-90 Method for Building a Cyber-Aware Workforce

What this video covers

This video introduces the GLB-90 Method as a way to turn awareness training from a one-off compliance exercise into a practical operating rhythm that improves engagement, confidence and everyday security behaviour.

  • Why traditional compliance-led awareness training often fails to change behaviour.
  • How to make cyber security feel relevant to the decisions employees make every day.
  • How to build a continuous programme across campaigns, role-based training and reinforcement.
  • How to track improvement using signals beyond module completion.
Useful starting point:

Before choosing topics, define the behaviours you need to improve. Awareness training should help people recognise risky moments, know what to do next and feel safe reporting concerns quickly.

Phishing Role-based training Compliance awareness Incident reporting Security culture

The problem

Why traditional security awareness training fails

Many awareness programmes are designed around completion, not capability. People are asked to click through a module, pass a short quiz and move on. That may satisfy a reporting requirement, but it rarely creates the judgement, confidence or habits needed in real situations.

It is too generic

The same message is sent to everyone, even though finance, HR, engineering, customer support and senior leaders face different security decisions.

It is too infrequent

Annual training leaves long gaps between learning and real-world application. People forget what they do not repeatedly use.

It feels separate from work

Security is often presented as a rulebook rather than a useful part of how people buy tools, share data, manage access, approve payments or handle client information.

Framework

How the GLB-90 Method changes the awareness conversation

The GLB-90 Method is useful because it treats awareness as an operating rhythm. Instead of relying on a single training event, it uses a structured 90-day cycle to build understanding, reinforce behaviour and show practical progress.

1

Start with behaviour

Choose the behaviours that matter most: reporting suspicious emails, protecting credentials, checking payment changes, handling sensitive data or challenging unusual requests.

2

Make it role-based

Adapt examples, scenarios and responsibilities by team so the training feels connected to people’s real decisions rather than generic security advice.

3

Reinforce for 90 days

Use reminders, manager prompts, phishing simulations, team briefings, micro-learning and practical nudges to keep awareness alive after launch.

Practical shift

From compliance training to security culture

Compliance-only awareness

  • Annual module with limited follow-up.
  • Same content for every role.
  • Success measured mainly by completion rate.
  • Employees remember the policy, but not always the action.
  • Security feels like something done to satisfy audit.

Behaviour-led awareness

  • Ongoing rhythm of reminders, examples and team conversations.
  • Role-based security awareness training linked to daily work.
  • Success measured by reporting quality, behaviour signals and reduced repeat mistakes.
  • Employees know what to do in risky moments.
  • Security becomes part of how the organisation operates.

Role-based design

Role-based security awareness training examples

A strong programme translates security into the risks each team is most likely to face. The message should be consistent, but the scenarios should feel familiar to the audience.

Audience Training focus Practical scenario Behaviour to reinforce
Finance Payment fraud, invoice redirection, approval discipline and suspicious requests. A supplier emails new bank details shortly before a payment deadline. Verify changes through an approved channel before processing payment.
HR and People teams Employee data, onboarding, offboarding, sensitive documents and impersonation. A message asks for payroll information or a change to employee details. Check identity, protect personal data and follow approved update procedures.
Engineering and Product Secure design decisions, secrets, code repositories, access and production changes. A deadline creates pressure to bypass review or share credentials informally. Use secure workflows even when delivery pressure increases.
Sales and Customer Success Client data, due diligence, contract promises, demos and information sharing. A prospect asks for security evidence or sensitive customer examples. Use approved evidence, avoid over-sharing and route questions correctly.
Senior leaders Business email compromise, decision pressure, governance and visible sponsorship. An urgent request appears to come from a senior executive or external partner. Model calm verification, support reporting and avoid normalising shortcuts.

Compliance

How to make compliance security awareness training more useful

Compliance awareness training should still produce evidence, but it should also improve how people handle risk. The best programmes satisfy governance needs while making the content more practical for the workforce.

Requirement Weak approach Stronger approach
Training records Track completion only. Track completion, follow-up reminders, role coverage and repeat non-completion.
Policy understanding Ask employees to acknowledge a policy once a year. Connect policies to practical scenarios, decisions and reporting routes.
Phishing awareness Run a simulation and name click rates as the main result. Measure reporting rates, repeat patterns, quality of follow-up and team-specific improvement.
Audit evidence Store a spreadsheet of names and dates. Keep evidence of content, audience, role coverage, communications, results and improvement actions.
Leadership oversight Report that training was completed. Report changes in behaviour, risk themes, engagement gaps and actions needed from leadership.

Rollout

A practical 90-day awareness training rollout

A 90-day cycle gives the programme enough structure to launch, reinforce and review without overwhelming the business. It also creates a natural rhythm for reporting progress.

Days 1–30

Baseline and focus

Review recent incidents, phishing results, audit findings, policy gaps and business changes. Choose the behaviours and audiences that need attention first.

  • Define priority behaviours.
  • Segment audiences by role.
  • Agree reporting and ownership.
Days 31–60

Launch and reinforce

Run the main campaign, but support it with manager prompts, practical examples, micro-messages and clear reporting routes.

  • Deliver training and communications.
  • Run role-specific scenarios.
  • Make reporting simple and visible.
Days 61–90

Measure and improve

Review engagement, reporting behaviour, repeat mistakes, questions raised and leadership feedback. Turn the findings into the next improvement cycle.

  • Compare signals by audience.
  • Identify friction and confusion.
  • Update the next campaign plan.

Measurement

What to measure beyond completion rates

Completion rates tell you whether people finished the task. They do not tell you whether the workforce is becoming more cyber-aware. Use a wider set of signals to understand whether the programme is changing behaviour.

Signal What it can show How to use it
Reporting rate Whether employees are spotting and escalating suspicious activity. Track reported phishing, suspicious requests and security questions over time.
Repeat themes Where the same risky behaviour or confusion keeps appearing. Use themes to choose future micro-learning and manager briefings.
Role coverage Whether higher-risk teams have received relevant training. Map training to departments, systems, data access and business processes.
Response quality Whether people know the correct next step in risky situations. Review how quickly incidents, suspicious emails and access concerns are escalated.
Leadership engagement Whether managers and executives are reinforcing secure behaviour. Include awareness messages in team meetings, onboarding and operational reviews.

Programme design

What a stronger security awareness programme should include

Core annual training

Keep the required baseline, but make it easier to understand and connect it to real decisions: passwords, MFA, phishing, data handling, incident reporting, device security and acceptable use.

Role-based campaigns

Create focused training for teams exposed to specific risks, such as finance fraud, HR data protection, engineering secrets, customer data or executive impersonation.

Manager reinforcement

Give managers short prompts they can use in team meetings so cyber awareness does not depend only on the security team sending emails.

Reporting confidence

Make it normal to report early. Employees should know that reporting a mistake quickly is better than hiding uncertainty until the risk grows.

Related resources

FAQs

Security awareness training FAQs

How do you revamp security awareness training?

Start by identifying the behaviours you need to improve, then segment training by audience, use practical scenarios, reinforce messages over time and measure signals such as reporting quality, repeat mistakes and role coverage rather than relying only on completion rates.

What is role-based security awareness training?

Role-based security awareness training adapts cyber security guidance to the risks different teams face. For example, finance may need payment fraud scenarios, HR may need employee data scenarios and engineering may need training on secrets, access and secure development workflows.

How is compliance security awareness training different from security culture?

Compliance security awareness training often focuses on proving that training happened. Security culture goes further by making secure behaviour part of everyday work, decision-making, reporting and leadership expectations.

How often should security awareness training happen?

Most organisations benefit from a baseline annual training requirement plus more frequent reinforcement. Short monthly or quarterly campaigns, phishing simulations, manager prompts and role-specific reminders usually keep awareness more active than a once-a-year module alone.

What should be included in a cyber awareness programme?

A cyber awareness programme should usually include phishing awareness, password and MFA guidance, data handling, incident reporting, device security, social engineering, role-based scenarios, policy reminders, leadership messaging and measurement of behaviour signals.

How do you measure whether awareness training is working?

Measure completion rates, but also track reporting rates, repeat risk themes, quality of escalations, role coverage, questions raised, incident trends, phishing simulation outcomes and whether managers are reinforcing the expected behaviours.

Who should own security awareness training?

Security often owns the programme, but HR, learning and development, communications, managers and senior leaders all play important roles. The most effective programmes make awareness a shared business responsibility rather than a security-only broadcast.

Next step

Need a security awareness programme people actually remember?

Use a structured approach to design role-based training, practical campaigns, reporting routines and leadership updates that turn cyber awareness into a repeatable business habit.

Last updated . Written for organisations improving security awareness training, workforce engagement and cyber culture.