The short answer
A security awareness program that changes behaviour has five parts:
- Clear goals tied to real risks: recognizing phishing, protecting accounts, handling data correctly, reporting incidents quickly.
- Short, regular content instead of one long annual session.
- Role-based depth for people with higher risk: finance, executives, IT administrators, anyone who handles sensitive records.
- Practice and feedback, including fair phishing simulations.
- A no-blame reporting culture, with a one-click way to report suspicious messages and a quick, friendly response.
The Canadian Centre for Cyber Security includes employee awareness training among its baseline controls for small and medium organizations, covering practical topics such as password practices, identifying malicious email, using approved software and appropriate internet use (Cyber Centre). NIST's updated guide, Building a Cybersecurity and Privacy Learning Program (SP 800-50 Rev. 1, September 2024), frames training as a life cycle aimed at behaviour change, with metrics to evaluate and improve it (NIST).
Start with the behaviours you want
Write the program's goals as behaviours, not topics:
| Instead of | Aim for |
|---|---|
| "Understand phishing" | Staff report suspicious emails within minutes, and verify payment changes by phone |
| "Password training" | Everyone uses MFA and a password manager; nobody reuses work passwords |
| "Data protection awareness" | Staff send sensitive files through approved tools, never personal email |
| "Incident awareness" | People report lost devices and mistakes immediately, knowing they will not be punished |
These goals also tell you what to measure.
Make it relevant to Canadian staff
Generic content from another country can feel irrelevant. Use examples people will recognize:
- Messages impersonating the Canada Revenue Agency, Canada Post, banks or courier services.
- Fraudulent Interac e-Transfer notifications and requests.
- Supplier invoice fraud: an email, apparently from a known vendor, announcing new banking details.
- Executive impersonation asking for gift cards or an urgent wire transfer.
- Fake Microsoft 365 or Google sign-in pages.
The Government of Canada's Get Cyber Safe campaign publishes free awareness material that can supplement your program (Get Cyber Safe). Offer content in English and French where your workforce needs it, and make it accessible (captions, screen reader support, plain language).
Role-based depth
Everyone needs the basics. Some roles need more:
- Finance and payroll: payment verification procedures, supplier banking changes, invoice fraud.
- Executives and their assistants: impersonation, targeted phishing, travel and device security.
- IT and administrators: privileged account protection, social engineering of help desks, secure remote access.
- HR and client-facing staff: handling personal information, resumes and attachments from unknown senders.
- New staff: security basics in the first week, before they build habits.
Phishing simulations, done fairly
Simulated phishing gives people safe practice and gives you data. Run it in a way that builds trust:
- Tell staff that simulations happen, without saying when.
- Treat a click as a learning moment: show a short explanation straight away.
- Do not name or shame individuals, and do not tie simulation results to discipline.
- Avoid lures that exploit real distress or promise benefits the organization would never give, such as fake bonuses; they damage trust more than they teach.
- Vary difficulty and themes, and include lures that match real attacks your organization has seen.
- Measure reporting, not just clicking.
Make reporting easy
The most valuable behaviour is fast reporting. A single suspicious email reported early can protect everyone else. Provide:
- A report button in the email client.
- A clear contact for lost devices, mistaken emails and anything that "feels off", reachable after hours if you have that coverage.
- A quick thank-you and, where possible, feedback on what the message was.
People who fear blame hide mistakes. Say plainly, and repeatedly, that reporting a mistake quickly is the right thing to do.
Back training with technical controls
Training reduces risk but never removes it; someone will eventually click. Pair the program with controls that limit the damage: MFA, email filtering, endpoint protection, least-privilege access and tested backups. See the Microsoft 365 security baseline for common settings.
A 12-month plan
| When | Activity |
|---|---|
| Month 1 | Baseline phishing simulation; launch the report button; leadership message on no-blame reporting |
| Months 1 to 12 | A short module each month (5 to 10 minutes) on one topic |
| Quarterly | Phishing simulation with a new theme; role-based sessions for finance, executives and IT |
| On hire | Onboarding module in the first week |
| After incidents | Short, anonymized lessons learned shared with staff |
| Month 12 | Review metrics, update topics, report to leadership |
Measure what matters
Useful measures, tracked over time:
- Report rate: share of simulated and real phishing messages reported.
- Time to report: how quickly the first report arrives after a campaign or real attack.
- Click rate by theme, to target the next module (not to rank people).
- Repeat clicks, to offer extra support.
- Real incidents involving human error, and how quickly they were reported.
- Completion rates, as a hygiene measure only.
Handle training and simulation data as employee personal information: restrict access and set retention periods.
Program checklist
Design
- Program goals written as behaviours
- Higher-risk roles identified with extra content planned
- Canadian examples and bilingual needs addressed
Delivery
- Monthly short modules scheduled
- Onboarding module for new staff
- Quarterly phishing simulations with fair rules published
Reporting culture
- One-click reporting in email
- Clear contact for mistakes and lost devices
- Leadership statement on no-blame reporting
Measurement
- Report rate and time to report tracked
- Annual review with leadership
- Training data access and retention defined
Limitations
Awareness training is one control among many and works best when leaders take part visibly. Results take months, not weeks. If you would like help designing or running a program, see our cybersecurity awareness training service.
Sources and further reading
Product capabilities and guidance change. These are the primary sources this article relies on, checked on the review date above.
- Building a Cybersecurity and Privacy Learning Program (NIST SP 800-50 Rev. 1), National Institute of Standards and Technology
- Baseline cyber security controls for small and medium organizations, Canadian Centre for Cyber Security
- Get Cyber Safe, Government of Canada
This article is general information, not legal, accounting or security advice for your specific situation. Examples are hypothetical unless stated otherwise.