Buyer guide

Building a security awareness training program that changes behaviour

Awareness training changes behaviour when it is short, frequent, relevant to each person's job and backed by an easy way to report problems without blame. An annual slideshow and a completion certificate rarely do.

The short answer

A security awareness program that changes behaviour has five parts:

  1. Clear goals tied to real risks: recognizing phishing, protecting accounts, handling data correctly, reporting incidents quickly.
  2. Short, regular content instead of one long annual session.
  3. Role-based depth for people with higher risk: finance, executives, IT administrators, anyone who handles sensitive records.
  4. Practice and feedback, including fair phishing simulations.
  5. A no-blame reporting culture, with a one-click way to report suspicious messages and a quick, friendly response.

The Canadian Centre for Cyber Security includes employee awareness training among its baseline controls for small and medium organizations, covering practical topics such as password practices, identifying malicious email, using approved software and appropriate internet use (Cyber Centre). NIST's updated guide, Building a Cybersecurity and Privacy Learning Program (SP 800-50 Rev. 1, September 2024), frames training as a life cycle aimed at behaviour change, with metrics to evaluate and improve it (NIST).

Start with the behaviours you want

Write the program's goals as behaviours, not topics:

Instead ofAim for
"Understand phishing"Staff report suspicious emails within minutes, and verify payment changes by phone
"Password training"Everyone uses MFA and a password manager; nobody reuses work passwords
"Data protection awareness"Staff send sensitive files through approved tools, never personal email
"Incident awareness"People report lost devices and mistakes immediately, knowing they will not be punished

These goals also tell you what to measure.

Make it relevant to Canadian staff

Generic content from another country can feel irrelevant. Use examples people will recognize:

  • Messages impersonating the Canada Revenue Agency, Canada Post, banks or courier services.
  • Fraudulent Interac e-Transfer notifications and requests.
  • Supplier invoice fraud: an email, apparently from a known vendor, announcing new banking details.
  • Executive impersonation asking for gift cards or an urgent wire transfer.
  • Fake Microsoft 365 or Google sign-in pages.

The Government of Canada's Get Cyber Safe campaign publishes free awareness material that can supplement your program (Get Cyber Safe). Offer content in English and French where your workforce needs it, and make it accessible (captions, screen reader support, plain language).

Role-based depth

Everyone needs the basics. Some roles need more:

  • Finance and payroll: payment verification procedures, supplier banking changes, invoice fraud.
  • Executives and their assistants: impersonation, targeted phishing, travel and device security.
  • IT and administrators: privileged account protection, social engineering of help desks, secure remote access.
  • HR and client-facing staff: handling personal information, resumes and attachments from unknown senders.
  • New staff: security basics in the first week, before they build habits.

Phishing simulations, done fairly

Simulated phishing gives people safe practice and gives you data. Run it in a way that builds trust:

  • Tell staff that simulations happen, without saying when.
  • Treat a click as a learning moment: show a short explanation straight away.
  • Do not name or shame individuals, and do not tie simulation results to discipline.
  • Avoid lures that exploit real distress or promise benefits the organization would never give, such as fake bonuses; they damage trust more than they teach.
  • Vary difficulty and themes, and include lures that match real attacks your organization has seen.
  • Measure reporting, not just clicking.

Make reporting easy

The most valuable behaviour is fast reporting. A single suspicious email reported early can protect everyone else. Provide:

  • A report button in the email client.
  • A clear contact for lost devices, mistaken emails and anything that "feels off", reachable after hours if you have that coverage.
  • A quick thank-you and, where possible, feedback on what the message was.

People who fear blame hide mistakes. Say plainly, and repeatedly, that reporting a mistake quickly is the right thing to do.

Back training with technical controls

Training reduces risk but never removes it; someone will eventually click. Pair the program with controls that limit the damage: MFA, email filtering, endpoint protection, least-privilege access and tested backups. See the Microsoft 365 security baseline for common settings.

A 12-month plan

WhenActivity
Month 1Baseline phishing simulation; launch the report button; leadership message on no-blame reporting
Months 1 to 12A short module each month (5 to 10 minutes) on one topic
QuarterlyPhishing simulation with a new theme; role-based sessions for finance, executives and IT
On hireOnboarding module in the first week
After incidentsShort, anonymized lessons learned shared with staff
Month 12Review metrics, update topics, report to leadership

Measure what matters

Useful measures, tracked over time:

  • Report rate: share of simulated and real phishing messages reported.
  • Time to report: how quickly the first report arrives after a campaign or real attack.
  • Click rate by theme, to target the next module (not to rank people).
  • Repeat clicks, to offer extra support.
  • Real incidents involving human error, and how quickly they were reported.
  • Completion rates, as a hygiene measure only.

Handle training and simulation data as employee personal information: restrict access and set retention periods.

Program checklist

Design

  • Program goals written as behaviours
  • Higher-risk roles identified with extra content planned
  • Canadian examples and bilingual needs addressed

Delivery

  • Monthly short modules scheduled
  • Onboarding module for new staff
  • Quarterly phishing simulations with fair rules published

Reporting culture

  • One-click reporting in email
  • Clear contact for mistakes and lost devices
  • Leadership statement on no-blame reporting

Measurement

  • Report rate and time to report tracked
  • Annual review with leadership
  • Training data access and retention defined

Limitations

Awareness training is one control among many and works best when leaders take part visibly. Results take months, not weeks. If you would like help designing or running a program, see our cybersecurity awareness training service.

Sources and further reading

Product capabilities and guidance change. These are the primary sources this article relies on, checked on the review date above.

  1. Building a Cybersecurity and Privacy Learning Program (NIST SP 800-50 Rev. 1), National Institute of Standards and Technology
  2. Baseline cyber security controls for small and medium organizations, Canadian Centre for Cyber Security
  3. Get Cyber Safe, Government of Canada

This article is general information, not legal, accounting or security advice for your specific situation. Examples are hypothetical unless stated otherwise.

Talk to Promatics

Get a straight answer for your situation

General advice only goes so far. Tell us about your environment and we will tell you what we would do, what it would cost and what to watch out for.

  • A named specialist who owns the outcome, not a chat window
  • Advice checked against your actual systems, contracts and risks
  • Written scope and costs in CAD before any work starts