Practical guide
How to create a security awareness development plan
A practical framework for defining target groups, topics, activities, responsibilities and evaluation.
Start with objectives and risks
Do not start with a course list. First define the behaviour you need to change, the risks the organisation faces and how improvement will be recognised.
Segment target groups
Segment employees by responsibility and the situations they face. Management, privileged administrators and ordinary users need different content.
Plan several types of activity
Combine short e-learning, demonstrations, phishing simulations, workshops and reminders. Assign an owner, deadline, target group and evidence to every activity, then use results in the next plan.