Practical guide

How to create a security awareness development plan

A practical framework for defining target groups, topics, activities, responsibilities and evaluation.

Start with objectives and risks

Do not start with a course list. First define the behaviour you need to change, the risks the organisation faces and how improvement will be recognised.

Segment target groups

Segment employees by responsibility and the situations they face. Management, privileged administrators and ordinary users need different content.

Plan several types of activity

Combine short e-learning, demonstrations, phishing simulations, workshops and reminders. Assign an owner, deadline, target group and evidence to every activity, then use results in the next plan.

Related topics

Continue according to your needs