Think it depends of how you do it. Sending a testmail and provide training afterwords will change nothing. Find a combination of mandantory trainings (not once a year but little lessons throughout the year) Communicate the risk with examples and send test mails - make employees aware and to your partner. Not blaming them but motivate them (maybe with a little quiz etc. etc. . With this approach we were able to lower the klick and interaction rates in our company significantly. Not an IT Job - Itβs a Management Job and needs to be a common goal.
Absolutely agree β the how makes all the difference. Continuous trainings, transparent communication, and a motivating, non-blaming culture are key. I also want to highlight what you mentioned here:
make employees aware and to your partner
Viewing employees as partners! π― Also really great to hear youβve seen such a measurable impact in your organization - lowering click and interaction rates! π Michael M. I'd love to hear more about how you approach cybersecurity awareness at your company! If youβd like, feel free to share some insights in 03_best-practices - Iβm sure many would appreciate learning from your experience. π
