Mobhitech — Gérard Levicki
Cybersecurity Awareness & Training: Changing Behavior, Not Just Providing Information
Executives, IT teams, employees, and at-risk populations do not share the same responsibilities or face the same risk scenarios. Effective awareness-raising tailors messages, drills, and expected decisions to each audience.
The goal is not to scare people or to simply recite rules: it is to enable everyone to recognize a risky situation, respond appropriately, and know when to raise the alarm.
What is cybersecurity awareness?
Cybersecurity awareness aims to help people understand digital risks and develop behaviors appropriate to their individual roles. It covers everyday practices—such as phishing, passwords, data, access, and remote work—as well as the ability to recognize an incident and use the correct reporting channel.
Cybersecurity training can go a step further by developing knowledge and skills tailored to specific audiences: executives, IT teams, managers, users, or roles that are particularly at risk.
It does not replace technical safeguards, governance, or procedures; rather, it complements these measures.
Cybersecurity Awareness or Training: What's the Difference?
The two approaches are complementary but do not pursue exactly the same objective. Awareness-raising focuses primarily on changing reflexes and behaviors in response to common situations, such as phishing, fraud, data security, access, mobility, or incident reporting. Training is geared more toward acquiring knowledge or skills tailored to a specific role and set of responsibilities.
| Criterion | Cybersecurity Awareness | Cybersecurity Training |
|---|---|---|
| Main Objective | Changing Habits and Behaviors | Develop targeted knowledge and skills |
| Public | All employees or exposed populations | Executives, IT teams, managers, key contacts, or target audiences |
| Common Formats | Workshops, campaigns, simulated phishing, conferences, reminders | Structured sessions, exercises, case studies, role-playing exercises |
| Measurement | Reports, Reactions, Behavioral Progress | Understanding, ability to apply concepts, and expected decisions |
On this page, Mobhitech combines these two approaches to develop a coherent program tailored to specific audiences and risks. The goal is not to present every training course as a certification program: any certification is part of a separate process that must be explicitly planned and documented.
When should you launch a cybersecurity awareness program?
- you have never established a structured approach to raising awareness;
- Phishing simulations reveal vulnerabilities;
- you are preparing for NIS2 and may be subject to its training requirements;
- Remote work, the cloud, growth, and new tools are changing the way we work;
- An incident revealed specific training needs;
- Executives need to better understand and manage cyber risk.
Which awareness-raising format should you choose?
| Format | Objective | Suitable for |
|---|---|---|
| Interactive Workshop | Working on Real-Life Situations | Business teams, managers, and at-risk roles |
| Structured Training | Develop knowledge and skills | Executives, IT teams, liaisons |
| Phishing Simulation | Assessing and Training Certain Reflexes | Employees who use email |
| Crisis drill / role-playing exercise | Practice decision-making, climbing, and coordination | COMEX, DSI, crisis management team |
| Conference | Building a Shared Understanding | General public, seminar, internal event |
| Short Videos / E-learning | Repeating Messages Over Time | Large or widely distributed populations |
Why should training for executives, IT teams, and users be different?
Senior Executives and the Executive Committee: Major Risks, Responsibilities, Trade-offs, Business Continuity, and Crisis Management.
IT teams: identities, configurations, access, logging, incidents, backups, and context-aware security management.
Employees: phishing, fraud, unusual requests, access, data, and reporting.
Managers and Sensitive Roles: Scenarios tailored to finance, HR, procurement, executive management, support, or other high-risk responsibilities.
Cybersecurity Training for Executives: Learning to Make Decisions
A training program for executives must address issues that truly fall within their purview: risks that could disrupt operations, funding priorities, governance, acceptable risk levels, and crisis response.
The ANSSI framework for executives is designed, in particular, to enable them to assess digital risk, identify major risks and priority actions, meet security requirements, and respond to cyber crises.
What Should a COMEX Know About Cyber Risk?
The COMEX does not need to learn how to manage security tools. It must be able to understand scenarios that could affect operations, weigh priorities and resources, identify responsibilities, and make decisions under pressure when an incident occurs.
- understand the main risk scenarios for the business;
- challenge cybersecurity priorities and investments;
- understand the roles and decision-making processes in the event of a crisis;
- understand the obligations applicable to the organization, when relevant;
- know what information to request from the IT department or the Chief Information Security Officer (CISO) in order to make a decision.
Phishing Simulation: Measure to Learn, Not to Trap People
A simulation can help measure certain reflexes and identify scenarios that require further training. But the click-through rate should not become the sole metric.
A mature program also focuses on the ability to recognize the message, report it promptly, and use the designated channel. Scenarios should remain proportionate and avoid mechanisms that are humiliating or unnecessarily anxiety-inducing.
Why do awareness programs often fail?
Awareness campaigns often fail not because employees “don’t understand cybersecurity,” but because the messages are too generic, too infrequent, or disconnected from the decisions they actually have to make. Effectiveness therefore depends as much on the design of the program as it does on the participants’ attention.
- The same content for everyone: responsibilities and risks vary by job.
- A one-time action: reflexes must be maintained.
- Fear-based messages: Getting people's attention doesn't necessarily teach them what to do.
- Tests perceived as traps: a punitive approach can discourage reporting.
- No clear reporting channels: Recognizing a threat isn't enough if no one knows how to report it.
- No connection to actual incidents: Feedback should be incorporated into future scenarios whenever possible.
Does NIS2 require training for executives and employees?
For essential and important entities falling within its scope, Article 20 of NIS2 requires that members of management bodies undergo training. Member States must also encourage these entities to regularly provide similar training to their employees so that they can identify risks and assess cybersecurity risk management practices.
This does not mean that every French company is automatically subject to this requirement: applicability must be determined based on the entity’s legal status and scope of operations.
What resources should an awareness program be based on?
Content must remain tailored to the organization’s specific context, but recommendations from the authorities help reinforce key messages. In particular, ANSSI publishes awareness-raising resources and best practices designed to improve security hygiene and understanding of digital risk.
How can we measure the effectiveness of cybersecurity awareness campaigns?
| Indicator | What it can show | Limit |
|---|---|---|
| Participation / Completion | Program Cover | Does not prove the development of a reflex |
| Quizzes or exercises | Immediate Understanding | Does not always predict actual behavior |
| Simulated Phishing Click | Sensitivity to a Scenario | Depends heavily on the scenario |
| Reporting Rate or Deadline | Ability to recognize and scale | Requires a simple, well-known channel |
| Changes Over Time | Progress or Stagnation | Requires similar exercises |
| Reports of Actual Incidents | Relevance to real-life situations | Volumes are sometimes insufficient to draw conclusions |
How can we develop an effective awareness program?
- Identify target audiences, responsibilities, and risk scenarios.
- Define expected behaviors: recognize, verify, protect, report, or decide.
- Choose the appropriate formats.
- Have students practice using scenarios that are similar to real-life situations.
- Measure a few truly useful metrics.
- Improve content based on the organization's results, incidents, and developments.
What deliverables can you expect?
- assessment of target audiences, risks, and educational needs;
- program and objectives by population group;
- training or workshop materials;
- phishing scenarios or role-playing exercises, when planned;
- reusable containers;
- contextualized results and indicators;
- recommendations and improvement plan.
Is awareness alone enough to reduce cyber risk?
No. It reduces certain risks associated with human behavior and decisions, but it does not replace technical controls, identity management, backups, detection, governance, or incident preparedness.
An organization should not place the burden on employees to make up for a flawed architecture or poorly designed processes.
What should be done after an awareness campaign?
The results should lead to decisions: strengthening certain content, simplifying a reporting channel, modifying a procedure, correcting a technical weakness, or better preparing an at-risk population.
When an exercise primarily reveals a problem with tools, processes, access rights, or organization, the solution should not be to provide users with additional training to compensate for a structural weakness. The remedy must address the appropriate cause.
Next steps may include a cybersecurity audit, an outsourced CISO, a risk management process, or preparation for cybersecurity crisis management.
A training program led directly by Gérard Levicki
Gérard Levicki takes an approach that integrates behavior, risk, technology, governance, and business challenges. He has over 25 years of experience in cybersecurity.
Frequently Asked Questions About Cybersecurity Awareness
How often should employees be educated on this topic?
There is no one-size-fits-all frequency. An effective program typically combines several follow-ups or actions over time and adapts to changes, incidents, and observed results.
What is the difference between cybersecurity awareness and cybersecurity training?
Awareness-raising is primarily aimed at changing habits and behaviors. Training develops knowledge or skills tailored to a specific role or need. A program may combine both.
Is a phishing simulation enough?
No. It assesses certain behaviors in response to a given scenario, but must be linked to educational guidance, a reporting channel, and follow-up actions.
Should we train leaders differently?
Yes. Above all, they must be able to assess risk, make decisions, organize governance, and respond to crises.
Does NIS2 offer training?
Yes, for the governing bodies of the relevant essential and significant entities, and it encourages similar regular training for the employees of those entities.
How do you measure awareness?
Using several metrics—coverage, comprehension, reporting, simulations, and trends over time—while avoiding the temptation to reduce the evaluation to just the click-through rate.
Does awareness prevent cyberattacks?
No. It reduces certain risks but must be part of a strategy that combines technical and organizational measures with incident preparedness.
How much does a program cost?
The budget depends on the target audience, formats, number of sessions, customization, exercises, and the desired level of follow-up. A scoping exercise helps determine the program's scope.
What behaviors do you really want to change?
The initial assessment helps identify target audiences, scenarios, and objectives before selecting training or awareness-raising formats.
The goal: to develop skills that are useful in real-life situations, not just to check off a training box.