Insights
Cybersecurity Awareness That Changes Everyday Decisions
Build a practical awareness programme around the decisions people make at work, supported by verification, usable controls and a responsive reporting process.

Make the safe action practical
A useful cybersecurity awareness programme helps people recognize a risky situation, take a practical next step and get timely support. It connects learning to the decisions employees make in their actual roles, alongside technical controls and clear operating procedures.
Consider a finance colleague who receives a convincing request to change a supplier's bank details before an urgent payment. Knowing that phishing exists is only part of the answer. The colleague also needs an independent verification route, permission to pause the change and a responsive team that can help assess it.
That is the design challenge for leadership: make the safe action clear and workable when ordinary business pressure is high.
Start with the decisions that expose the business
Map a small set of situations where a mistaken decision could affect customers, money, information or access. Ask each process owner what employees are expected to do, how they obtain help and where the process becomes difficult.
Finance may need to verify changes to payment instructions. A service desk may need to confirm identity before resetting access. Operations may receive unfamiliar links from partners. Sales teams may need to decide whether a document can be shared externally.
These situations need different practice. A generic annual course can introduce common principles, but it should not be the only place employees learn how to apply them. The aim is to build a repeatable response around the work each person performs.
NIST's learning-programme guidance emphasizes role-aware learning, behaviour change, evaluation and a continuing improvement cycle. It was developed for federal organizations; the approach can inform an enterprise programme without implying that the publication is a GCC regulatory requirement.
Make independent verification possible
In the supplier example, the employee should verify the requested change through a contact route established independently of the suspicious message. Calling a number supplied in that same request does not provide the same independent check.
The FBI's business email compromise guidance specifically recommends checking payment changes with the person involved and independently finding the contact number. This is a useful control for the example, not a guarantee that every fraudulent request will be detected.
The business must support that behaviour. Maintain an approved supplier-contact record, define who can authorize a bank-detail change and provide an escalation route when the normal contact is unavailable. Urgency should not silently remove the required check.
A senior executive should follow the same verification process when requesting an exception. Employees cannot be expected to challenge pressure consistently if leadership routinely rewards bypassing the procedure.
Turn policies into short role-based practice
Use realistic, non-punitive scenarios that let people practise the next action. Ask what they would verify, which approved channel they would use and when they would pause the task. Avoid relying only on quizzes about terminology.
The following is an illustrative starting set for an enterprise programme. The exact procedures should be agreed with the relevant process and security owners.
| Role or situation | Decision to practise |
|---|---|
| Finance receives new payment details | Pause the change and verify through an established independent contact route. |
| Service desk receives an urgent reset request | Follow the approved identity check before changing access. |
| Operations receives an unexpected partner link | Use the agreed reporting route and confirm the intended business exchange. |
| A colleague approves repeated sign-in prompts | Stop approving unexpected requests and contact support promptly. |
| Sales prepares an external document share | Check the recipient, information classification and permitted sharing method. |
Include the tools and language people use at work. For a multilingual workforce, check that the reporting instructions and examples are understood by the intended audience. A translated policy is less useful if the reporting channel cannot support the person using it.
Keep practice short enough to fit the role, but make time for questions. Questions often expose unclear ownership, impractical instructions or a gap between policy and the available software.
Pair awareness with technical and process controls
People should not carry the whole burden of recognizing deceptive requests. Email protection, appropriate access permissions, controlled supplier changes and usable authentication reduce dependence on a perfect decision every time.
CISA recommends phishing-resistant multifactor authentication and describes number matching as an interim improvement for organizations using push-based MFA that cannot yet adopt the stronger approach. Authentication controls still need a deployment and support plan that fits the workforce.
Training should explain what employees will see and what support is available when a control behaves unexpectedly. If the approved route repeatedly prevents legitimate work, investigate and improve it. An inaccessible process creates pressure to find an informal workaround.
Treat reported confusion as design evidence. Several employees asking the same question may indicate that the instruction or interface needs to change, rather than that the audience needs another warning.
Make reporting a supported action
Provide a recognizable reporting method for suspicious messages and access concerns. Explain what information is useful, what to do if someone has already interacted with a message, and which team takes responsibility after the report arrives.
Practice the receiving side as well. A report that waits without acknowledgement teaches employees that the channel may not help. Give responders a way to triage, escalate and return a useful answer without exposing unnecessary personal or sensitive information.
Encourage prompt reporting of mistakes. The immediate priority is understanding and containing the event through the organization's response process. Publicly naming individuals or treating every error as misconduct can discourage the information the response team needs.
If a suspected event is real, use the established incident process and relevant local reporting obligations. An awareness exercise should never replace that operational response.
Measure behaviour and process quality together
Completion rates show participation; they do not establish that a person can handle a difficult request. Combine them with measures tied to the decisions being practised.
For example, sample whether supplier changes include the required verification record. Review how quickly employees report a concern and how quickly the support team acknowledges and routes it. Observe whether staff can find the reporting method without assistance during a practice session.
Interpret these measures carefully. More reports can reflect greater confidence in the channel rather than more attacks. A low simulation click rate may depend on how obvious the example was or which employees received it. Keep scenario difficulty, audience and definitions visible when comparing results.
Choose measures that help improve the process. Avoid league tables that reward teams for having few reports or discourage people from asking for help. Protect the personal information collected during evaluation and limit its use to the agreed purpose.
Build a programme the business can maintain
Start with a small number of high-priority decisions and named owners. Run practice, review the questions and support outcomes, then adjust the instructions or controls before adding more scenarios.
Bring new starters into the process and refresh guidance when roles, systems or threats affecting the work change. Include relevant contractors and external partners where they participate in the same sensitive workflow. The programme needs a continuing owner, a review rhythm and enough capacity to act on what it learns.
Bridges' Cybersecurity services connect awareness with access, policy and operational controls. Our Business Continuity & Resilience work supports preparation for disruption. Discuss the decisions your people need to make with greater confidence.
About this article
Developed from Mohamed Elnahas's original cybersecurity awareness article, with expanded role-based practice and measurement guidance. Scenarios are illustrative; no individual incident, client result or guaranteed reduction in risk is claimed.

