Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› How should organisations run a cybersecurity awareness program…
Governance, Ownership & Risk

How should organisations run a cybersecurity awareness program that people will actually participate in?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 27, 2026 Domain: Governance, Ownership & Risk

Start with short, relevant content and make the experience easy to complete. Use brief videos, practical topics such as phishing, ransomware and identity protection, and positive leadership support to increase engagement. Add lightweight events or contests, and keep the messaging focused on helping people stay safe at work and at home. Programs work best when they feel useful, not intrusive.

What makes a cybersecurity awareness program actually get used?

Participation starts with relevance and effort. People are more likely to engage when the content is short, clearly useful, and easy to complete in the flow of work. The most effective programs also avoid guilt-heavy messaging and instead show employees how the material helps them protect themselves, their teams, and the organisation.

That means the program has to solve a real attention problem, not just a compliance problem. If the format feels long, generic, or disconnected from daily work, completion rates and retention both drop. If it feels practical, lightweight, and respectful of time, participation is much easier to sustain.

A good benchmark is whether someone can complete the activity without having to stop real work for long. Microlearning, short videos, and simple check-ins usually outperform dense slides or annual training events because they reduce friction and make the first click less intimidating.

Which topics and formats tend to drive engagement?

The best topics are familiar and immediately applicable: phishing, ransomware, identity protection, safe password handling, device security, and how to spot suspicious requests. These topics work because people can connect them to situations they have already seen at work or in their personal lives.

Format matters as much as subject matter. Brief videos, scenario-based examples, quick quizzes, and lightweight contests can create enough variety to keep attention without turning the program into entertainment. The aim is not novelty for its own sake, but a rhythm that makes participation feel manageable and predictable.

Programs also improve when they are tailored to the audience. A finance team, a help desk, and a developer group do not need the same examples or delivery style. Relevance rises when the message reflects the actual tools, workflows, and threats people encounter most often.

How should organisations build participation without making the program feel intrusive?

Participation improves when leadership treats awareness as a shared safety habit rather than a policing exercise. Visible support from managers, simple reminders, and recognition for completion all help, but the messaging should stay practical and non-judgmental so people do not feel they are being tested or shamed.

Timing also matters. A program that interrupts busy periods, demands long sessions, or pushes too many reminders will quickly lose goodwill. The better approach is to make training easy to start, easy to finish, and easy to return to later, especially when it can be broken into small pieces.

Successful programs usually keep the promise very clear: the training helps people stay safe at work and at home. When employees see direct personal value, participation is more likely to become routine rather than something they do only because compliance requires it.

Risk and Threat Considerations

Low participation creates a false sense of coverage. An awareness program can look complete on paper while the workforce ignores it, forgets it, or treats it as background noise, which leaves phishing, credential theft, ransomware, and social engineering conditions unchanged.

Failure mechanism: The program becomes high-friction, low-relevance, or overly punitive, so users stop engaging, skim content, or mechanically complete it without retention. That weakens the human control layer exactly when attackers rely on routine mistakes and trust-based shortcuts.

Impact: The organisation loses the behavioural benefit it expected from the program, and the same weaknesses continue to drive real incident exposure. In practice, the risk is not just poor attendance, but repeated susceptibility to the attacks the program was meant to reduce.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-14 — Security Awareness and Skills TrainingDirectly addresses user participation and role-tailored awareness training.
Recommendation — Use engaging, role-based awareness content and track completion and behaviour change.
NIST CSF 2.0PR.AT-01 — Personnel are provided awareness and training that is relevant to their roles and risksFits role-relevant awareness content that drives participation and retention.
Recommendation — Deliver role-specific awareness that maps to the risks people actually face.
ISO/IEC 27001:2022A.6.3 — Information security awareness, education and trainingSupports a formal awareness programme that keeps messaging practical and relevant.
Recommendation — Run awareness training that is understandable, relevant, and repeated at suitable intervals.

Practitioner Guidance

What to prioritise: Start with the shortest content that addresses the most common real-world mistakes your workforce actually faces. If the program does not reduce friction for the learner, it will not improve participation no matter how strong the material is.

What to verify: Check whether completion is driven by genuine engagement or by deadline pressure and checkbox behaviour. Look for evidence that people can explain the message back in plain language, not just that they clicked through it.

What good looks like: The program feels like a normal part of work, managers reinforce it without overloading people, and employees can quickly connect the training to decisions they make every day.

Practitioner takeaway: Treat awareness as an adoption problem first and a content problem second, because participation depends less on how much you publish and more on whether the audience sees immediate, practical value in finishing it.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 27, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org