CyberPlay

Security awareness courses: build a programme that connects learning with practice

Build a security awareness programme with short video courses, realistic games and knowledge checks. See role-based examples and what each result can prove.

CyberPlay editorial team · Published · Updated · 8 min read

Guide and exercises in English

Nova introduces a staged security email in CyberPlay’s Modern email phishing course.

Expand image · Course video frame · English interface

Actual CyberPlay course video frame with English on-screen text. The staged email turns a familiar inbox into a decision to practise.

A useful security awareness course programme connects one workplace decision to an explanation, a chance to practise and a review of what still needs support. CyberPlay Courses supplies short narrated lessons with five decision checkpoints; games add a different situation, and game knowledge checks revisit the reasoning. The programme owner connects these activities to the organisation’s actual procedures.

This guide shows how to build that connection for phishing, payment changes and recovery. CyberPlay articles and the platform interface are available in nine languages. Course narration and lesson content currently come in English or Romanian; an interface translation does not create a translated lesson. Check that distinction before inviting a multilingual team.

What you’ll take away

  • Choose a decision people make at work before choosing a course.
  • Use the video, game and knowledge check for different learning purposes.
  • Keep course completion, game evidence and workplace observations separate.
  • End each cycle with an owner for the procedure or learning gap you found.

1. Define the decision the programme should support

“Recognise phishing” is too broad to organise a useful session. Try “When a supplier changes its bank details, pause the payment and verify through the approved contact record.” Finance can recognise that task, a manager can explain the exception route, and a facilitator can build an exercise around it. Define the trigger, the safe action and the person who can remove an obstacle.

NIST’s learning-programme guidance recommends a lifecycle that includes needs assessment, role-based learning and evaluation. Apply that principle locally: ask which decisions cause uncertainty, choose relevant practice, then review the result. Neither a large content catalogue nor an annual completion target answers those questions by itself.

Section sources: Building a Cybersecurity and Privacy Learning Program (SP 800-50 Rev. 1)

2. Give each activity a clear job

In a CyberPlay Course, the video pauses at five checkpoints so the learner chooses before seeing the explanation. Use these moments to articulate a rule: a polished email is not proof, or a real support application does not authenticate its caller. Rewatching the explanation is useful when the reason remains unclear.

Then change the context. A game asks the learner to use the idea within a scenario. Passing that game unlocks its separate 30-question knowledge check. This written check belongs to the game; it is not the five-question video checkpoint sequence. Follow with a short workplace discussion that names your own reporting route and approved tools.

2. Give each activity a clear job
ActivityLearning purposeUseful follow-up
Video courseExplain a decision and reveal the reasoning after each choice.Ask the learner to restate the rule in their own words.
Relevant gameApply related ideas while inspecting evidence or choosing actions.Discuss which clue changed the decision.
Game knowledge checkAnswer written questions after passing the game.Review the explanation and any topic needing support.
Workplace debriefConnect the lesson to your actual process.Assign an owner to an unclear step or missing contact.

3. Build small tracks around actual responsibilities

Start an accounts-payable track with Modern email phishing and Call before you pay. In the first lesson, the focus is the request and the trusted route used to verify it. The payment lesson adds a known-number call and existing approval steps. Ask the finance owner to supply a fictional supplier record so nobody practises with customer or bank data.

For a team that manages shared documents, combine Name the people before you share with I clicked. What now? For colleagues responsible for maintaining important working files, begin with A cloud icon is not a backup. These are editorial track suggestions, not preconfigured course assignments. Share the chosen course links through your normal learning process.

A staged executive email asks for gift-card codes while discouraging calls.

Expand image · Course video frame · English interface

  1. A familiar name is not approval

    Confirm the request through a contact already held in your organisation’s records.

  2. Identify the requested action

    Gift-card codes, new bank details and urgent transfers all need the normal approval process.

Actual frame from Call before you pay, with English on-screen text. The sender and email are fictional; the decision is whether to follow the payment-verification procedure.

4. Carry the lesson into a different scenario

Phishing Detective 3D connects naturally with the payment track. Its investigation includes a genuine supplier mailbox, an existing conversation, a changed bank account and an archived invoice. The learner investigates the evidence behind a frozen supplier payment. A familiar sender or matching invoice design does not settle the question; comparing the changed information matters.

Backup or Lose It connects with the backup lesson. Its scenarios distinguish current local work, company sync, a secure vault and removable storage, then ask the player to recover files after a simulated ransomware event. That makes it a useful discussion about recoverability. It does not test your organisation’s real backup system, restore permissions or recovery time.

A learning cycle from course explanation to game practice, a knowledge check and a workplace debrief.

Expand image

Original CyberPlay learning design. The sequence is a programme suggestion, not an automated assignment workflow.

5. Run a session people can use tomorrow

Before the session, give learners the business situation and confirm their access and lesson language. Let them complete one course, then discuss a checkpoint without treating a wrong answer as a character judgement. Schedule the selected game with enough time for its actual scenario. The written knowledge check can follow after the game is passed; do not promise the entire sequence will fit into a five-minute break.

Close with a local rehearsal: “Show where you would find the verified supplier number” or “Explain how you would report an unexpected approval.” NIST’s phishing guidance links employee training with reporting and technical protections. Keep both in view: an employee should not have to compensate for an absent contact record or broken reporting process.

Section sources: Phishing: small business cybersecurity guidance

6. Make reporting part of the learning

I clicked. What now? distinguishes what happened: following a link, entering a password, allowing access, installing software or making a payment. Use that structure to practise a short internal report: what happened, when, which account or device was involved and what was already done. Do not include passwords or other secrets in the practice report.

NCSC’s security-culture guidance stresses accessible reporting routes and fair treatment when people raise concerns or admit mistakes. A facilitator can model that response by thanking the reporter and explaining the next step. Test the organisation’s contact route separately; knowing the right answer inside a course cannot make an unattended mailbox respond.

Nova explains what to preserve and report after a suspicious action.

Expand image · Course video frame · English interface

  1. Preserve the useful facts

    Keep the message and note what happened and when so the response team can assess it.

  2. Say what changed

    An app permission, installation or payment changes the next response step.

Actual frame from I clicked. What now?, with English on-screen text. Practise explaining what happened, when it happened and what access or payment followed.

Section sources: Cyber security culture principles: Principle 2

7. Record evidence without overstating it

Keep four simple records for a pilot: who had an opportunity to learn, which activity they completed, which decision still needs explanation, and which workplace issue has an owner. A completion result shows an activity was finished under the platform’s rules. It does not establish resistance to every future attack. A classroom discussion is a different evidence source from an operational incident.

Keep course completion, checkpoint results, game decisions and workplace follow-up as distinct types of evidence. Where an eligible plan allows a course certificate to be claimed, it is a certificate of completion. Use the available learning records to maintain your programme schedule and review, and give each follow-up action an owner.

8. Exercise: a correct answer and an unusable process

Use this fictional case to test whether the programme reaches beyond the lesson. Ask the learner, finance manager and security lead to propose one next action each, then compare their responsibilities.

9. Review the first cycle before expanding it

At the review, ask three questions: Could everyone access a suitable lesson? Could they explain and practise the target decision? Could they carry it out using the organisation’s real process? Each answer suggests a different response: language support, another scenario, or a workflow change. Record what remains unknown instead of turning one score into a broad verdict.

Expand the programme when the first track has a clear purpose and a workable follow-up. Modern email phishing, remote-support verification and ClickFix are currently free with an account. Other courses require an eligible plan. Choose the next topic from observed needs, then connect its explanation, practice and review in the same way.

Apply the course ideas in a supplier-payment investigation

Play Phishing Detective 3D in English, inspect the invoice and account evidence, then explain which checks you would use at work. Game access depends on your plan.

Open Phishing Detective 3D

Sources and further reading

  1. Building a Cybersecurity and Privacy Learning Program (SP 800-50 Rev. 1) — NIST. Accessed 2026-10-03
  2. Phishing: small business cybersecurity guidance — NIST. Accessed 2026-10-03
  3. Cyber security culture principles: Principle 2 — UK National Cyber Security Centre. Accessed 2026-10-03

Keep exploring

All articles

Contact · About