Hi all,
here´s my 50 cent to this discussion on how we made it, that our users are "awake" on cybersecurity, not a psychological approach, but a human, maybe "conservative" one:
Our board of directors was very alarmed by cyber attacks at friendly companies in the immediate vicinity and urgently wanted an awareness solution for employees. Sosafe was implemented and we got the employees on board right from the start with backing from the top.
Every email about new, current threats, special circumstances, etc. always includes a request to “pester” us with questions. The request to use the "SoSafe button" in Outlook one too many times rather than the crucial time too few has also led to colleagues now doing exactly that: it is better to ask IT first whether the link, email, website, app, etc. is "safe" BEFORE clicking. And of course we also help with problems with private devices as far as possible.
The fact that the Management Board also personally checks that employees are doing the trainings and exerts gentle pressure via the department heads without getting angry has also led to employees seeing SoSafe as absolutely normal within a year.
The success: Statistical rates far better than the industry average. And employees who now see IT as a friend and helper because we always have an open ear.