Why cyber security awareness needs an engagement strategy

You can give every employee the same training and get a 98% completion rate.

But it’s likely you still have people making the wrong decision when it matters. Simply put, awareness isn’t engagement. Engagement is what turns knowledge into action. 

For years, organisations have approached cyber security awareness primarily as a training challenge: create a module, assign it to employees, track completion and move on to the next.

But the threat landscape has changed, and cyber criminals have evolved as better communicators.

AI can now help create convincing emails, clone voices, deepfake videos and tailor highly personalised messages that feel relevant, familiar and trustworthy. For complex, global organisations, those attacks can arrive via almost any employee channel.

The answer isn’t simply more training, it’s better engagement to drive behaviour change.

The cyber challenge is making people care

Cyber security teams know what employees need to do. Employees are also aware of cyber security. The bigger question is: will employees notice, remember and take action when it matters?

That’s an engagement challenge.

Employees are exposed to hundreds of messages every day and cyber security is competing with business updates, Team’s messages, emails, deadlines, leadership communications and everything else that demands attention. So a cyber message needs to be relevant, recognisable and give people a reason to pay attention.

That’s where a communication strategy becomes critical, and starts with the question “How do we make this matter to people?”

Answering that question means thinking about the employee journey, not the training journey. What do people see first? What makes them curious and understand how relevant the risk is? What reinforces good behaviour? And, ultimately, how do they feel empowered to act?

Employee engagement is built, not delivered

True behaviour change rarely comes from a learning experience.

People need regular interaction with cyber security, seeing how it applies to their role, understanding the simple actions they can take, and receiving enough reinforcement for secure behaviour to become part of everyday work rather than another compliance requirement.

That means thinking about cyber awareness as an ongoing engagement programme. A programme that’s truly tailored:

  • Messages that are relevant and make the risks easy to understand.
  • Risk profiling and audience segmentation to align risks to employees.
  • Channel planning so messages are delivered with the highest visibility and impact.
  • A campaign identity that’s recognisable, tailored to an organisation’s unique challenges, objectives and needs.
  • Reinforcement over time, embedding the campaign amongst your people.

Together, they create something much more powerful – recognition.

Relevance earns attention in global organisations

A global workforce is not one audience.

Leadership, office workers and front-line teams face different attack patterns and different levels of risk, which can be further dissected by department. A one-size-fits-all message can communicate the importance of cyber security, but it can struggle to communicate personal relevance.

People pay attention when a threat feels specific to their role and their decisions. Segmentation helps organisations to move away from a more generic warning, towards situations employees recognise in their own working lives.

  • For finance, that could mean payment diversion or invoice fraud.
  • For an executive assistant, impersonation and urgent requests from senior leaders.
  • For customer service, social engineering and attempts to extract customer information.
  • For senior leaders, the risks associated with impersonation, sensitive information and high-value access.

Segmentation helps to not only tell people what the threat is, it shows them what it looks like in their world.

This is where behaviour-led communication becomes particularly powerful. The aim isn’t to overwhelm people with every possible threat. It is to give each audience a simple mental model for what to watch for, what decision to make and what to do next.

Ben Watson, Blue Goose Managing Director and Strategist, regularly instills the belief that sustainable cyber awareness also starts with culture.

‘We do know that ‘affective security’ – the desire to protect an organisation out of loyalty to it – is a powerful weapon when it comes to information security.
‘A business that has embedded a positive culture and belief in its purpose, can leverage that commitment to ask for support on a broader range of issues – including compliance and cyber security,’ Ben says.

That culture, combined with role relevance also helps create personal ownership. When employees believe in their organisation and understand how cyber security connects to their role, it becomes less about protecting an abstract outcome, for example reputational damage or financial impact, and more about protecting the work, customers, colleagues and information they are responsible for.

Every channel is part of the experience

If attackers are using email, Teams, SMS, phone calls, social media and collaboration platforms to reach employees, cyber awareness can’t exist in a single learning platform. It needs to be front and centre where people actually work.

That doesn’t mean overloading every channel with security messages, it means creating a structured programme of communications, where each channel has a purpose.

  • Leadership communications establish importance.
  • Managers reinforce behaviours.
  • The broader campaign creates attention.
  • Short-form content guide behaviours.
  • Intranet and learning platforms provide detail.
  • Real-world examples make threats tangible.
  • Reminders and nudges convert awareness into action.

The communication strategy is the glue that connects all of these pieces. Without it, organisations can end up producing lots of good content that’s fragmented. 

A clear strategy is particularly important for complex, global organisations, where the challenge is extended to not only reaching people, but creating a consistent experience across different countries, cultures, languages and working environments.

Cyber security – awareness to action

The measure of a cyber awareness programme shouldn’t simply be whether someone completed it. The more important question is what happened as a result.

  • Did people recognise the threats?
  • Did they remember what to do?
  • Did they report something suspicious?
  • Did secure behaviour become easier and more instinctive?
  • Did people engage with the campaign?

These are the outcomes that show awareness is actually translating into action and are the kinds of outcomes CISOs and Communications Directors can align to. They create a shared language between security and internal comms, which is often missing in larger organisations.

Blue Goose has more than 20 years’ experience supporting this kind of programme because our cyber and compliance specialism sits at the intersection of strategy, content, and employee-facing communications. We turn policy into practical messaging that people understand and act on, to ultimately move people from:

Unconscious bad behaviour > Conscious good behaviour > Unconscious good behaviour

Making cyber security something people engage with

The most effective programmes don’t simply tell people what they need to know. They create reasons for people to pay attention, make the message relevant to their world and reinforce the behaviours that matter. That means combining cyber expertise with communications strategy to create programmes that people notice, understand and remember; from audience segmentation and messaging to campaign identity, channel strategy and ongoing reinforcement.

The result is greater confidence to recognise and respond to threats, a more engaging employee experience, and a stronger connection between cyber policy and the decisions people make every day.

Because awareness can tell people what to do. Engagement is the reason to do it.