MY WORK / CYBER AWARENESS

Revamping Security Awareness Training | The GLB-90 Method for Building a Cyber-Aware Workforce

Traditional security awareness training fails because it’s built around compliance — not culture. Employees click through modules, pass the quiz, and forget what they’ve learned. Real awareness means engagement, empowerment, and consistency.

Quick answer: The GLB-90 Method transforms security awareness training from a one-off compliance task into a continuous learning approach that builds stronger habits, deeper engagement, and a more cyber-aware workforce over time.

Oct 27
Written By Karimah A

In this video, I introduce The GLB-90 Method — my signature framework for transforming security awareness training into a continuous learning experience that actually changes behaviour and builds a cyber-aware workforce. The goal is not just to reduce risk on paper, but to create a stronger security culture in practice.

Key takeaway: When you use The GLB-90 Method, security awareness becomes a culture — not a checkbox. You don’t just reduce risk; you build a workforce that thinks and acts securely every day.

Watch the video

This video is for organisations that want security awareness to be remembered, repeated, and embedded into the way people work. It is especially useful for leaders trying to move from annual awareness exercises to something more meaningful and sustainable.

What you’ll learn

Why traditional awareness training fails

Why one-off compliance-led training often produces weak retention and little real behaviour change.

How to make security part of daily routines

How to move awareness closer to real work so secure habits become more natural and repeatable.

How to make awareness continuous

How to turn awareness from an isolated event into an ongoing conversation that builds culture over time.

How to track real improvement

How to measure awareness maturity, sustain leadership buy-in, and keep momentum going.

Why traditional training fails

Traditional awareness training often fails because it is built around completion, not culture. Employees are asked to finish modules, pass quizzes, and move on, but the training rarely connects strongly enough to the real decisions they make every day.

When awareness is treated as a once-a-year task, it becomes something people tolerate rather than something they internalise. That creates a gap between formal training and actual secure behaviour. The GLB-90 Method is designed to close that gap by creating more consistent engagement, reinforcement, and ownership.

Why security awareness programmes fail

Below are common, practical reasons programmes do not deliver sustained behaviour change. These reflect problems I discuss in the video and in client work.

1. Generic training that doesn’t fit roles

When learning is generic, people cannot relate it to the decisions they make. Training that doesn’t map to role-specific risks is forgotten.

2. Weak relevance to day-to-day work

If the content sits apart from real processes and tools, people don’t practise secure choices in the flow of their work.

3. Poor behavioural integration and reinforcement

Without repeated prompts, leadership reinforcement and practical scenarios, knowledge decays and secure behaviours don’t become habits.

4. Lack of ownership and simple evidence

Programmes without clear owners, measurable outcomes and easy evidence capture struggle to keep leadership buy-in and to iterate improvements.

Practical improvement considerations

  • Map training to role decisions: Start with a small set of role-specific scenarios and test them in live or simulated tasks.
  • Embed micro-practice: Use short, frequent prompts and scenarios that fit into daily tools and meetings.
  • Make ownership visible: Assign owners for awareness outcomes and simple evidence with review dates.
  • Reinforce with leadership: Ask leaders to reference awareness in regular meetings and to model secure decisions.
  • Measure meaningful signals: Track behaviour signals, not only course completion.

Short checklist for an improvement sprint

  1. Identify 3 role-specific scenarios to test in the next 30 days.
  2. Assign an owner and one piece of evidence to collect.
  3. Run a short prompt or scenario in a team meeting and collect feedback.
  4. Share results with leadership and set the next review date.

Who this video is for

  • CISOs and Security Managers
  • HR and People Leaders
  • Training and Development Professionals
  • Anyone tasked with improving their organisation’s cyber security culture

Subscribe to my channel

Subscribe for more videos on cyber strategy, workforce engagement, and practical frameworks for building lasting security cultures.

Need help building a more cyber-aware workforce?

Explore more of my work on cyber awareness, workforce engagement, security culture, and practical frameworks for sustainable change.