Awareness programme
Also known as: awareness program, awareness campaign, awareness plan
A planned, ongoing effort to change how staff behave around security - with target groups, messages, methods and measurable goals.
Draft - this entry has not been reviewed yet.
Formal
A structured plan for building security awareness across an organisation - defining the people involved, target groups and messages, choosing methods such as online courses, workshops, phishing simulations and nudges, and tracking results with agreed measures.
In plain English
Like a fitness plan rather than a single gym visit - small, regular sessions matched to each person, with progress checked along the way.
In practice
A municipality plans a year of short monthly topics, a phishing test each quarter and a separate session for managers, and each quarter tells the management team what share of staff report suspicious emails.
Why it matters
One talk a year changes little; lasting change in behaviour needs repetition, relevance and measurement, and NIS2 expects training to be part of the security work.
Technical deep dive
NIST SP 800-50 Rev. 1 (September 2024) models the programme as a four-phase life cycle, one section each: Plan and Strategy (Section 2), Analysis and Design (Section 3), Development and Implementation (Section 4), and Assessment and Improvement (Section 5). The phases may run in sequence or in parallel, and the model is explicitly iterative, so a new threat, an incident or a regulatory change can re-enter the cycle at any point. Inside Section 3 NIST applies the classic ADDIE instructional-design model (Analysis, Design, Development, Implementation, Evaluation): identify learning needs from work-role tasks, define audiences, map needs to audiences, assess current knowledge and determine the gaps before any content is written.
Section 2.7 distinguishes three element types: awareness activities (logon banners, newsletters, posters, timely emails, campaign months) that reach everyone continuously; experiential learning such as phishing, smishing and vishing simulations, tabletop exercises and cyber-range scenarios; and training, which builds skills for roles with significant security or privacy responsibilities. Awareness changes attention, training changes competence; a programme that only has the former cannot fix skill gaps among developers or administrators, and one that only has the latter leaves the general workforce untouched.
Design choices that matter in practice are segmentation by risk exposure rather than by org chart (payment approvers, HR, privileged admins and executives face different pretexts), spacing and repetition instead of one annual block, and just-in-time delivery at the point of decision, where nudges complement formal learning. CIS Controls v8 Control 14 turns this into auditable safeguards, starting with establishing and maintaining the programme, training on social engineering, authentication and data handling, and adding role-specific training.
Measurement is where many programmes fail. Section 2.4 of SP 800-50r1 distinguishes activity metrics (attendance, cost per participant) from behaviour-change metrics such as the share of participants who report a simulated phishing email. Mature programmes track reporting rate, time-to-report, repeat-clicker trends and incidents with a human root cause, and treat click rates with caution because they depend heavily on how hard the template is. Field studies at UC San Diego Health (IEEE S&P 2025) and in a large organisation with more than 14,000 employees (IEEE S&P 2022) found little or no protective effect from annual training and embedded post-click lessons, which argues for pairing the programme with technical controls such as phishing-resistant MFA rather than expecting training alone to carry the risk. On the compliance side the programme is the evidence for ISO/IEC 27001:2022 clause 7.3 and Annex A 6.3, NIS2 Art. 21(2)(g) and, for financial entities, DORA Art. 13(6).
What to learn first
Everything this builds on, foundations first.
- Threat
- →Security awareness
- →Awareness programme
Relationships
- Consists of
- Phishing simulation
- Requires
- Security awareness
- Unlocks
- Awareness officer
- Mitigates
- Human error
- Used with
- NudgingSecurity metrics (KPIs)
Sources & further reading
Standards & official texts
- NIST SP 800-50 Rev. 1 - Building a Cybersecurity and Privacy Learning Program
Course material
- Cyber Security Fast Track - Kursuskompendium, Modul 2
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Check yourself
Loading…