Skip to content
Skip to content

Mobhitech — Gérard Levicki

Cybersecurity Awareness & Training: Changing Behavior, Not Just Providing Information

Executives, IT teams, employees, and at-risk populations do not share the same responsibilities or face the same risk scenarios. Effective awareness-raising tailors messages, drills, and expected decisions to each audience.

The goal is not to scare people or to simply recite rules: it is to enable everyone to recognize a risky situation, respond appropriately, and know when to raise the alarm.

Developing Your Awareness Program

What is cybersecurity awareness?

Cybersecurity awareness aims to help people understand digital risks and develop behaviors appropriate to their individual roles. It covers everyday practices—such as phishing, passwords, data, access, and remote work—as well as the ability to recognize an incident and use the correct reporting channel.

Cybersecurity training can go a step further by developing knowledge and skills tailored to specific audiences: executives, IT teams, managers, users, or roles that are particularly at risk.

It does not replace technical safeguards, governance, or procedures; rather, it complements these measures.

Cybersecurity Awareness or Training: What's the Difference?

The two approaches are complementary but do not pursue exactly the same objective. Awareness-raising focuses primarily on changing reflexes and behaviors in response to common situations, such as phishing, fraud, data security, access, mobility, or incident reporting. Training is geared more toward acquiring knowledge or skills tailored to a specific role and set of responsibilities.

CriterionCybersecurity AwarenessCybersecurity Training
Main ObjectiveChanging Habits and BehaviorsDevelop targeted knowledge and skills
PublicAll employees or exposed populationsExecutives, IT teams, managers, key contacts, or target audiences
Common FormatsWorkshops, campaigns, simulated phishing, conferences, remindersStructured sessions, exercises, case studies, role-playing exercises
MeasurementReports, Reactions, Behavioral ProgressUnderstanding, ability to apply concepts, and expected decisions

On this page, Mobhitech combines these two approaches to develop a coherent program tailored to specific audiences and risks. The goal is not to present every training course as a certification program: any certification is part of a separate process that must be explicitly planned and documented.

When should you launch a cybersecurity awareness program?

  • you have never established a structured approach to raising awareness;
  • Phishing simulations reveal vulnerabilities;
  • you are preparing for NIS2 and may be subject to its training requirements;
  • Remote work, the cloud, growth, and new tools are changing the way we work;
  • An incident revealed specific training needs;
  • Executives need to better understand and manage cyber risk.

Which awareness-raising format should you choose?

FormatObjectiveSuitable for
Interactive WorkshopWorking on Real-Life SituationsBusiness teams, managers, and at-risk roles
Structured TrainingDevelop knowledge and skillsExecutives, IT teams, liaisons
Phishing SimulationAssessing and Training Certain ReflexesEmployees who use email
Crisis drill / role-playing exercisePractice decision-making, climbing, and coordinationCOMEX, DSI, crisis management team
ConferenceBuilding a Shared UnderstandingGeneral public, seminar, internal event
Short Videos / E-learningRepeating Messages Over TimeLarge or widely distributed populations

Why should training for executives, IT teams, and users be different?

Senior Executives and the Executive Committee: Major Risks, Responsibilities, Trade-offs, Business Continuity, and Crisis Management.

IT teams: identities, configurations, access, logging, incidents, backups, and context-aware security management.

Employees: phishing, fraud, unusual requests, access, data, and reporting.

Managers and Sensitive Roles: Scenarios tailored to finance, HR, procurement, executive management, support, or other high-risk responsibilities.

Cybersecurity Training for Executives: Learning to Make Decisions

A training program for executives must address issues that truly fall within their purview: risks that could disrupt operations, funding priorities, governance, acceptable risk levels, and crisis response.

The ANSSI framework for executives is designed, in particular, to enable them to assess digital risk, identify major risks and priority actions, meet security requirements, and respond to cyber crises.

Primary Source: ANSSI — Cybersecurity for Executives

What Should a COMEX Know About Cyber Risk?

The COMEX does not need to learn how to manage security tools. It must be able to understand scenarios that could affect operations, weigh priorities and resources, identify responsibilities, and make decisions under pressure when an incident occurs.

  • understand the main risk scenarios for the business;
  • challenge cybersecurity priorities and investments;
  • understand the roles and decision-making processes in the event of a crisis;
  • understand the obligations applicable to the organization, when relevant;
  • know what information to request from the IT department or the Chief Information Security Officer (CISO) in order to make a decision.

Phishing Simulation: Measure to Learn, Not to Trap People

A simulation can help measure certain reflexes and identify scenarios that require further training. But the click-through rate should not become the sole metric.

A mature program also focuses on the ability to recognize the message, report it promptly, and use the designated channel. Scenarios should remain proportionate and avoid mechanisms that are humiliating or unnecessarily anxiety-inducing.

Why do awareness programs often fail?

Awareness campaigns often fail not because employees “don’t understand cybersecurity,” but because the messages are too generic, too infrequent, or disconnected from the decisions they actually have to make. Effectiveness therefore depends as much on the design of the program as it does on the participants’ attention.

  • The same content for everyone: responsibilities and risks vary by job.
  • A one-time action: reflexes must be maintained.
  • Fear-based messages: Getting people's attention doesn't necessarily teach them what to do.
  • Tests perceived as traps: a punitive approach can discourage reporting.
  • No clear reporting channels: Recognizing a threat isn't enough if no one knows how to report it.
  • No connection to actual incidents: Feedback should be incorporated into future scenarios whenever possible.

Does NIS2 require training for executives and employees?

For essential and important entities falling within its scope, Article 20 of NIS2 requires that members of management bodies undergo training. Member States must also encourage these entities to regularly provide similar training to their employees so that they can identify risks and assess cybersecurity risk management practices.

This does not mean that every French company is automatically subject to this requirement: applicability must be determined based on the entity’s legal status and scope of operations.

Primary source: EUR-Lex — NIS2 Directive, Article 20

What resources should an awareness program be based on?

Content must remain tailored to the organization’s specific context, but recommendations from the authorities help reinforce key messages. In particular, ANSSI publishes awareness-raising resources and best practices designed to improve security hygiene and understanding of digital risk.

Primary source: ANSSI — best practices for staying safe

How can we measure the effectiveness of cybersecurity awareness campaigns?

IndicatorWhat it can showLimit
Participation / CompletionProgram CoverDoes not prove the development of a reflex
Quizzes or exercisesImmediate UnderstandingDoes not always predict actual behavior
Simulated Phishing ClickSensitivity to a ScenarioDepends heavily on the scenario
Reporting Rate or DeadlineAbility to recognize and scaleRequires a simple, well-known channel
Changes Over TimeProgress or StagnationRequires similar exercises
Reports of Actual IncidentsRelevance to real-life situationsVolumes are sometimes insufficient to draw conclusions

How can we develop an effective awareness program?

  1. Identify target audiences, responsibilities, and risk scenarios.
  2. Define expected behaviors: recognize, verify, protect, report, or decide.
  3. Choose the appropriate formats.
  4. Have students practice using scenarios that are similar to real-life situations.
  5. Measure a few truly useful metrics.
  6. Improve content based on the organization's results, incidents, and developments.

What deliverables can you expect?

  • assessment of target audiences, risks, and educational needs;
  • program and objectives by population group;
  • training or workshop materials;
  • phishing scenarios or role-playing exercises, when planned;
  • reusable containers;
  • contextualized results and indicators;
  • recommendations and improvement plan.

Is awareness alone enough to reduce cyber risk?

No. It reduces certain risks associated with human behavior and decisions, but it does not replace technical controls, identity management, backups, detection, governance, or incident preparedness.

An organization should not place the burden on employees to make up for a flawed architecture or poorly designed processes.

What should be done after an awareness campaign?

The results should lead to decisions: strengthening certain content, simplifying a reporting channel, modifying a procedure, correcting a technical weakness, or better preparing an at-risk population.

When an exercise primarily reveals a problem with tools, processes, access rights, or organization, the solution should not be to provide users with additional training to compensate for a structural weakness. The remedy must address the appropriate cause.

Next steps may include a cybersecurity audit, an outsourced CISO, a risk management process, or preparation for cybersecurity crisis management.

A training program led directly by Gérard Levicki

Gérard Levicki takes an approach that integrates behavior, risk, technology, governance, and business challenges. He has over 25 years of experience in cybersecurity.

Learn about his career · LinkedIn Profile

Frequently Asked Questions About Cybersecurity Awareness

How often should employees be educated on this topic?

There is no one-size-fits-all frequency. An effective program typically combines several follow-ups or actions over time and adapts to changes, incidents, and observed results.

What is the difference between cybersecurity awareness and cybersecurity training?

Awareness-raising is primarily aimed at changing habits and behaviors. Training develops knowledge or skills tailored to a specific role or need. A program may combine both.

Is a phishing simulation enough?

No. It assesses certain behaviors in response to a given scenario, but must be linked to educational guidance, a reporting channel, and follow-up actions.

Should we train leaders differently?

Yes. Above all, they must be able to assess risk, make decisions, organize governance, and respond to crises.

Does NIS2 offer training?

Yes, for the governing bodies of the relevant essential and significant entities, and it encourages similar regular training for the employees of those entities.

How do you measure awareness?

Using several metrics—coverage, comprehension, reporting, simulations, and trends over time—while avoiding the temptation to reduce the evaluation to just the click-through rate.

Does awareness prevent cyberattacks?

No. It reduces certain risks but must be part of a strategy that combines technical and organizational measures with incident preparedness.

How much does a program cost?

The budget depends on the target audience, formats, number of sessions, customization, exercises, and the desired level of follow-up. A scoping exercise helps determine the program's scope.

What behaviors do you really want to change?

The initial assessment helps identify target audiences, scenarios, and objectives before selecting training or awareness-raising formats.

The goal: to develop skills that are useful in real-life situations, not just to check off a training box.

Request my free initial assessment · Contact Gérard Levicki