Security awareness training for employees: how to choose a programme

Choose security awareness training for employees with practical scenarios, accessible delivery and a clear pilot that checks learning, reporting and programme fit.

CyberPlay editorial team · Published · Updated · 9 min read

Guide and exercises in English

Scene from Secure Your Home Office.

Expand image

From the CyberPlay Secure Your Home Office gallery. Illustrative game scene; any interface text shown is in English.

Security awareness training for employees should help people handle the decisions that appear in their work: checking an unexpected request, protecting an account, sharing information appropriately and reporting a concern. Choosing a programme means examining how those decisions are taught and practised, alongside the practical work of making activities available and supporting the people taking them.

Start with a small set of needs and test a complete experience before committing to a larger rollout. This guide provides an original workplace scenario, a programme-selection checklist and a pilot approach for comparing learning and operational fit. It applies to teams with different roles, languages and working patterns. A useful choice should be understandable to the learner, manageable for the programme owner and honest about the evidence it produces.

What you’ll take away

  • Define the workplace decisions you want employees to practise before comparing providers.
  • Test the complete activity, including feedback, language, controls and the reporting connection.
  • Inspect actual pilot records and administrator workflows rather than relying on feature labels.
  • Use demonstrated suitability and explicit limits to decide whether to expand the programme.

Start with the action employees need to take

Write a concrete objective for each priority audience. Finance staff should verify changed payment instructions through the approved process. Everyone should be able to find the reporting route. Managers should know how to support an employee who pauses a questionable request. These outcomes give a buyer something observable to inspect in a sample lesson.

NIST SP 800-50 Rev. 1 describes an ongoing learning programme tailored to organisational needs, with evaluation and improvement. Apply that principle by asking where employees currently encounter uncertainty and which processes need reinforcement. General awareness, specialist technical instruction and training for people with particular responsibilities may require different activities; one attractive course need not serve every purpose.

Section sources: Building a Cybersecurity and Privacy Learning Program, NIST SP 800-50 Rev. 1

Look inside the learning activity

Ask to complete an activity as an employee would. Notice whether it explains the situation, lets the learner make a meaningful choice and provides feedback about the consequence. A video can introduce a concept, a role-play can rehearse a conversation and a game can provide repeated decisions. Select the format that makes the intended action understandable and available for practice.

Inspect the wrong answers as carefully as the right one. Useful feedback explains why the choice matters and offers a workable alternative. If an activity merely awards points for recognising a label, ask how the learner will connect that result to a workplace task. Also check whether employees can pause, revisit an explanation or ask for help when they remain unsure.

Match the experience to the intended audience

An office administrator, a remote worker and an employee using a shared terminal may face different requests and have different ways to take part. Ask representatives of the intended audience whether the sample feels plausible, whether they understand their role and whether the safe action is possible in their workplace. Keep the scenario fictional while making its process recognisable.

Check the baseline knowledge expected by the content. A newcomer may need a short explanation before a challenge; an experienced payment approver may benefit from a more ambiguous request. The NCSC Top Tips for Staff package provides an example of a non-technical introduction covering practical basics. Its published audience and access information can help buyers articulate what they need from an introductory resource.

Secure Your Home Office gameplay: reviewing a home-working setup.

Expand image · Game screenshot · English interface

  1. Review devices and storage

    Check which devices and storage locations hold work information, and identify any access or sharing questions.

  2. Use approved work channels

    Keep work communication and files in approved channels and storage, even when personal alternatives seem more convenient.

Secure Your Home Office gameplay: reviewing a home-working setup.

Section sources: Top Tips for Staff: help your staff keep your organisation safe online

Test language and accessibility throughout the experience

Check instructions, answer choices, explanations, navigation and error messages in each required language. A language selector on the platform does not establish that a particular activity is fully translated. Ask a learner to explain the safe action in their own words after completing it; this can reveal unclear phrasing that a quick visual review misses.

Test on the actual workplace devices and connection. Check keyboard use, readable text, contrast, sound alternatives and whether time limits create avoidable barriers. Do not make a personal smartphone or private email account an unstated condition of participation. Where an activity cannot meet a learner’s needs, establish an equivalent way to practise the same decision before choosing it for the whole group.

Audience: Understand roles, language and access needs. Objective: Define the decision employees should practise. Experience: Try the activity and its feedback. Evidence: Review learning and follow-up needs.

Expand image

Choose training that fits the work. Match the programme to your employees' decisions and learning needs. Original CyberPlay explanatory diagram.

Try an original supplier-change scenario

Use this fictional example during a provider demonstration or internal pilot. An employee expects an invoice from a regular supplier. A message arrives with the correct order reference but requests a new payment account and supplies a new telephone number for confirmation. The normal supplier record and approval process are available to the employee.

The FBI recommends independent checks for payment and account changes. The activity should help the learner practise your implementation of that check. A familiar sender, expected amount or convincing explanation is not enough to authorise a new payment destination. The learner needs a route to verify and complete legitimate work safely.

Phishing Detective 3D gameplay: reviewing a supplier invoice.

Expand image · Game screenshot · English interface

  1. Compare the changed details

    Check which payment details changed and whether the request matches the expected invoice and work.

  2. Compare with trusted records

    Compare with a trusted invoice, then verify changed bank details through the supplier contact already on record.

Phishing Detective 3D gameplay: reviewing a supplier invoice.

Section sources: Business Email Compromise

Compare programmes with an evidence checklist

Use the same checklist for every option, including an internally facilitated approach. Ask for a demonstration or document that answers each question. Record the exact activity and commercial plan tested, because a capability may exist only in part of a catalogue or at a different service level. Mark an untested item as unresolved rather than assuming it is included.

Compare programmes with an evidence checklist
Selection questionEvidence to requestReason it matters
Does the activity teach a relevant decision?A complete sample with learner choices and feedback.The method must connect to the intended workplace action.
Can the intended audience participate?A device, language and accessibility pilot.A suitable activity must be usable by the people assigned to it.
Can it connect to our procedures?A demonstration of the local reporting and verification instructions.General advice needs a workable route in the organisation.
What does an administrator actually manage?A walkthrough of invitation, assignment and follow-up tasks.Operational effort affects whether the programme can be maintained.
What do the records mean?A sample result or export with field definitions.Completion and assessed performance answer different questions.
What is included in the agreement?The proposed users, term, support, functions and exit arrangements.The buyer needs a clear scope for the evaluated service.

Pilot the administrator’s work as well

Ask the programme owner to perform the tasks needed for the proposed rollout: setting up the intended group, communicating access, selecting an activity, handling a missed session and reviewing results. Use the exact proposed plan and permissions. A demonstration delivered by a provider’s specialist may conceal steps that your administrator will need to perform alone.

Inspect the difficult cases. What happens when someone joins late, changes role, cannot sign in or leaves the organisation? Can an authorised owner resolve the issue, and what support is available? Check any required import, export or integration using a small approved test dataset. Do not treat a feature named in a brochure as evidence that it works with your particular workflow.

Check evidence, access and data handling

Ask which records the programme creates and what each field represents. A completion record shows that an activity was finished under its rules. A game score describes performance in that game. A discussion may produce useful observations without an individual assessment. Keep those distinctions visible when reporting to managers, and ask how a later changed scenario could examine application separately.

Review who can see individual results, how access follows organisational roles and what retention or deletion arrangements apply. Use fictional information for the pilot where possible. Keep a separate improvement log for problems such as an outdated supplier contact or unclear reporting route. Those observations may lead to important changes even when they are not captured in a learner score.

Run a small pilot with explicit success conditions

Choose a group that represents the intended roles, languages and devices. Before starting, agree what you need to observe: learners can access the activity, explain the target decision and find the reporting route; the administrator can perform the required tasks and interpret the resulting records. Add any essential organisational requirements to the same list.

Let participants attempt the sample before coaching them. Then collect feedback about the explanation, controls and relevance. After the debrief, present a changed situation to see how they apply the principle. This is a practical suitability check, not proof of reduced incidents or a controlled evaluation of causal effect. Document limitations and assign any required fixes before expanding.

The Social Engineer gameplay: checking a caller's claimed support role.

Expand image · Game screenshot · English interface

  1. Find the existing directory

    Use the organisation's established helpdesk directory to find a trusted contact before continuing a sensitive request.

  2. Do not reuse supplied numbers

    A number supplied by the caller is part of the request and cannot independently verify it.

The Social Engineer gameplay: checking a caller's claimed support role.

Choose the next step from demonstrated fit

Review the pilot against the success conditions and the proposed agreement. Expand when the essential learning and operating needs are met. Resolve material gaps before a broad rollout, or choose a different format for the affected audience. A small facilitated session can be a sensible starting point when it fits the objective; larger coordination needs may justify dedicated administration.

CyberPlay’s phishing collection provides a starting point for testing interactive practice. Select a relevant game, verify its actual language and controls, and connect its decisions to your organisation’s own procedure during the debrief. Judge the complete experience alongside the records and management features you need. Once that fit is established, use a training plan to organise ongoing delivery and improvement.

Put the decision into practice

Explore the relevant CyberPlay games, choose a suitable challenge, and discuss how its decisions connect to your own workplace procedures.

Explore practice games

Sources and further reading

  1. Building a Cybersecurity and Privacy Learning Program, NIST SP 800-50 Rev. 1 — NIST. Accessed 2026-09-13
  2. Business Email Compromise — FBI. Accessed 2026-09-13
  3. Top Tips for Staff: help your staff keep your organisation safe online — National Cyber Security Centre. Accessed 2026-09-13

Keep exploring

All articles

Contact · About