Security Awareness Training: How Companies Protect Their Employees from Cyberattacks
Firewalls, antivirus software, and other security solutions form the technical foundation of information security. However, many successful cyberattacks still begin with a human error in judgment. In this insight, you will learn why people have become the preferred target of cybercriminals, why traditional awareness training often falls short, and how organizations can strengthen their resilience against cyber threats by fostering a strong information security culture.
Table of contents
Key Takeaways
- 88% of all cyber incidents can be traced back to human error, making cybersecurity as much a people issue as a technology issue.
- Phishing, social engineering, and AI-powered attacks are increasingly turning employees into the primary targets of cybercriminals.
- One time training sessions are not enough. Sustainable security awareness requires continuous learning, practice, and reinforcement.
- People who actively experience security incidents rather than simply reading about them are better equipped to recognize risks and respond confidently when an incident occurs.
- A strong information security culture significantly strengthens an organization’s long-term resilience against cyber threats.
What Is Security Awareness Training?
Security awareness training (also referred to as cybersecurity awareness, information security awareness, or SecAware) is the process of developing employees’ awareness of cyber and information security risks, as well as their ability and motivation to act in a security-conscious manner.
Its primary objective is to build an understanding of potential threats and to promote secure behavior when using information systems and digital resources. Beyond individual knowledge and skills, security awareness training also aims to foster a security-conscious organizational culture in which all employees understand and embrace their responsibility for protecting information and maintaining cybersecurity.[1]
How EFS Consulting Develops an Effective Security Awareness Program for Your Organization
Effective security awareness does not begin with training. It starts with a clear understanding of the relevant risks, target audiences, and behavioral patterns within an organization. That is why EFS Consulting first assesses the threat landscape, defines target groups and learning objectives, and then develops tailored awareness measures based on these insights. Content, formats, and communication channels are aligned with the organization’s specific risks, regulatory requirements, and level of maturity.
EFS Consulting supports organizations in the design, implementation, and evaluation of traditional awareness initiatives. These include awareness campaigns, role-based training content, workshops, communication measures, and the continuous enhancement of existing awareness programs.
However, success depends not only on what is taught, but also on how it is delivered. Organizations need learning formats that capture attention, reinforce knowledge over time, and encourage secure behavior in everyday work environments.
This is exactly where EFS Consulting’s “True Crime – Cybercrime Edition” comes in.
True Cyber Crime: When Security Awareness Becomes an Interactive Investigation
A limited budget, numerous security risks, and a mandate from the CEO to build an effective Information Security Management System (ISMS). Participants must set priorities and decide which measures to implement. Days later, a security incident occurs. Was the right decision made? Which warning signs were overlooked? And how could the attack have been prevented?
These are exactly the questions participants face in EFS Consulting’s “True Crime – Cybercrime Edition.” Rather than addressing cyber risks solely from a theoretical perspective, participants become investigators in a realistic cyber incident scenario themselves. After all, those who actively experience security incidents gain a far deeper understanding of their dynamics than through traditional training alone.
Learning Like Investigators: The True Crime Concept
The “True Crime – Cybercrime Edition” combines the suspense of real criminal cases with the challenges of modern cybersecurity. During the workshop, participants analyze emails, chat conversations, and other pieces of evidence, identify potential vulnerabilities, and make decisions that directly influence the progression of the case. In doing so, they not only examine technical aspects but also uncover human factors, communication failures, and organizational weaknesses.
The result: information security is not just understood, but experienced firsthand.
Tailored to the Organization and Its Threat Landscape
Before the role-playing exercise begins, EFS Consulting works closely with the organization to ensure thorough preparation. During a dedicated briefing session, the target audience, learning objectives, relevant threat scenarios, and current challenges are defined. The workshop content can be specifically aligned with regulatory and industry requirements such as ISO 27001, NIS2, the Cyber Resilience Act (CRA), VDA ISA/TISAX®, or organization-specific compliance requirements.
Based on these insights, the scenario is tailored to the organization, the participants, and the desired level of maturity. The result is not a generic, off-the-shelf training course, but a practical awareness format that directly reflects the organization’s actual risks, requirements, and challenges.
How the “True Crime – Cybercrime Edition” works
The format is designed as a compact and interactive training experience and typically lasts 90 to 120 minutes. A workshop group usually consists of 10 to 12 participants. For larger audiences, multiple investigation cases can be run in parallel.
During the workshop, participants take on the role of investigators, analyze evidence, discuss potential connections, and make decisions throughout the course of the case. The session is facilitated by one or two EFS experts, who guide participants through the scenario, provide insights, and reflect on the outcomes together with the group.
The workshop concludes with a debriefing session, during which key learnings are translated into the participants’ own organizational context and practical recommendations for everyday work are derived. The format can be delivered either on-site or remotely.
The “True Crime – Cybercrime Edition” is a security awareness measure that can be documented as evidence of completed awareness training for regulatory or internal compliance purposes. As such, the format not only helps organizations raise awareness among their employees but also supports them in meeting training and compliance requirements.
Who Can Benefit from True Cyber Crime?
This format is particularly well suited for organizations that view information security as a shared responsibility across the entire business and want to actively involve their employees in protecting the organization.
The “True Crime – Cybercrime Edition” is especially valuable for organizations seeking to strengthen their information security posture, meet regulatory requirements, or prepare for audits and certifications. This includes organizations working within the frameworks of ISO 27001, NIS2, and other compliance requirements.
The format is designed primarily for Chief Information Security Officers (CISOs), Information Security Officers, Compliance Managers, Risk Managers, and business leaders who aim to embed security awareness sustainably across their organizations.
As the “True Crime – Cybercrime Edition” is delivered and documented as a security awareness training measure, it can also serve as evidence of completed awareness activities for audits, certifications, and regulatory compliance requirements. As a result, organizations not only enhance employee awareness but also support their broader governance, risk management, and compliance objectives.
Learning Outcomes of the True Cyber Crime Approach
Rather than focusing on knowledge tests, the format is designed to drive lasting behavioral change and create meaningful shared learning experiences:
- Greater engagement through active participation rather than passive learning
- Improved knowledge retention through hands-on experience and practical application
- A deeper understanding of roles, responsibilities, and interdependencies during security incidents
- Stronger cross-functional collaboration and communication
- Actionable insights into organizational vulnerabilities and opportunities for improvement
- Long-term reinforcement of security-conscious thinking and behavior
What Participants Say About True Cyber Crime
“The workshop’s interactive and gamified approach makes information security surprisingly accessible, presenting even complex topics in a way that is easy to understand.”
“An outstanding concept that was delivered in a highly realistic way, highlighted the importance of information security, and at the same time strengthened teamwork and communication.”
Why Is Security Awareness More Important Than Ever?
Cyberattacks are becoming increasingly sophisticated and are more frequently targeting people, the largest attack surface within any organization. While technical security controls continue to evolve and improve, attackers deliberately exploit human vulnerabilities such as carelessness, time pressure, trust, and a lack of risk awareness. As a result, employees have become a primary target for phishing, social engineering, and other forms of cybercrime.
According to industry estimates, around 88% of data breaches can be attributed to human error. As a consequence, human risk has become a critical factor in organizational security. Strengthening employees’ ability to recognize threats, make informed decisions, and respond appropriately is therefore essential to reducing cyber risk and improving overall organizational resilience.[2]
Particularly social engineering and phishing attacks demonstrate that cybercriminals today often do not attempt to attack systems directly but instead manipulate employees. Their goal is to obtain confidential information, deploy malware, or initiate financial transactions. Even the most advanced security solutions cannot completely prevent such human errors.
At 16%, phishing is now the most common initial access vector in security incidents. An initial access vector refers to the original entry point through which attackers first gain access to a system or corporate network, for example through phishing emails, stolen credentials, or the exploitation of vulnerabilities.
In addition, hybrid working models and remote work create new challenges. Employees work outside traditional corporate boundaries, use different networks, and increasingly make security-relevant decisions independently. As a result, the potential attack surface for organizations expands significantly.
The risk posed by insider threats is also increasing. Security incidents are not caused exclusively by external attackers but often result from unintentional mistakes, insecure routines, or the improper handling of sensitive information.
At the same time, new technologies such as artificial intelligence enable cybercriminals to create highly convincing phishing messages, personalized fraud attempts, and automated social engineering campaigns at scale. Today, up to 16% of all cyberattacks are supported by the use of AI, and this figure is rising rapidly. As a result, attacks are becoming increasingly difficult to detect and achieve higher success rates than ever before.[3]
This makes it all the more important to complement traditional security awareness with the development of AI literacy. Employees need to understand how AI-generated content is created, what risks are associated with AI-generated texts, images, and deepfakes, and how to critically assess their trustworthiness. AI literacy therefore extends security awareness by equipping employees with the ability to better understand emerging AI-powered threats and identify manipulation attempts more quickly.
Against this backdrop, security awareness is becoming increasingly important. Its goal is to enable employees to accurately assess security risks and respond appropriately in critical situations. Only when potential threats are recognized and security incidents are reported in a timely manner can organizations effectively prevent damage and protect corporate data, business processes, and critical information.
Security awareness is therefore no longer just an IT issue but an essential component of corporate security. Only the combination of technology, knowledge, secure behavior, and a well-established security culture provides the foundation for long-term cyber resilience.
Why Security Awareness Needs a New Approach
Knowledge alone does not protect against cyberattacks. Effective security awareness only develops when employees can recognize risks in realistic situations, make decisions, and embed secure behavior into their daily work routines. This is precisely why practical and interactive learning formats are becoming increasingly important.[4]
The “True Crime – Cybercrime Edition” is an example of such a security awareness training format. It strengthens employees’ security awareness and promotes security-conscious behavior in everyday work. However, to establish a holistic security culture, awareness measures should be complemented by cybersecurity training that also develops professional and technical competencies.
Security Awareness Training vs. Cybersecurity Training
Security awareness and cybersecurity training complement each other as key components of a holistic security culture, but they serve different purposes. While cybersecurity training provides the specific knowledge and skills required to act securely, security awareness training strengthens employees’ understanding of security risks and promotes long-term security-conscious behavior. [5]
Conclusion
Security awareness has long evolved beyond a mandatory training requirement and is becoming a key pillar of a resilient security culture. Organizations are increasingly challenged to actively engage employees and promote security-conscious behavior through practical, real-world learning experiences.
EFS Consulting helps organizations embed security awareness in a sustainable way. Interactive formats such as the “True Crime – Cybercrime Edition” demonstrate how security awareness can go beyond simple knowledge transfer. They make risks tangible, foster cross-functional collaboration, and support organizations in building a lasting security culture.
FAQs
What is security awareness?
Security awareness refers to employees’ awareness and understanding of cyber risks, as well as their ability to recognize security-related threats and respond appropriately. Its goal is to embed secure behavior into everyday work practices over the long term.
Why is security awareness training important?
As many security incidents can be traced back to human error, security awareness training helps employees identify risks at an early stage and act in a security-conscious manner. It not only increases knowledge but also supports the development of a sustainable security culture.
How often should security awareness training be conducted?
Security awareness should not be viewed as a one-time initiative, but rather as a continuous process.
What topics should be included in a security awareness training program?
The content should be tailored to the target audience and should cover current topics such as phishing, social engineering, password security, data protection, and the handling of AI-powered threats. Most importantly, the content should be practical and relevant to employees’ daily work.
What regulatory requirements apply to security awareness training?
Frameworks such as NIS2, ISO 27001, and industry-specific compliance requirements call for regular information security awareness and training activities for employees. The “True Crime – Cybercrime Edition” helps organizations address these requirements through a practical awareness format. Participation can be documented as evidence of a completed security awareness activity while simultaneously promoting sustainable behavioral change.
What makes EFS True Crime different from traditional awareness training?
Our training is not based on theoretical examples, but on the real-world challenges we have encountered through years of supporting organizations in the field of information security. Across numerous projects, we have seen how security incidents actually occur, which mistakes are made under pressure, and which organizational and human factors contribute to them.
We have translated this reality into our “True Crime – Cybercrime Edition” role-playing format. As a result, the training does not simply convey theoretical knowledge but reflects the situations organizations are genuinely likely to face when a security incident occurs.
References
[1] Bundesamt für Sicherheit in der Informationstechnik (BSI): Awareness. Verfügbar unter: https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Informationen-und-Empfehlungen/Empfehlungen-nach-Angriffszielen/Faktor-Mensch/Awareness/awareness_node.html
[2] CISOMAG: “Psychology of Human Error” Could Help Businesses Prevent Security Breaches. Verfügbar unter: https://cisomag.com/psychology-of-human-error-could-help-businesses-prevent-security-breaches/ (Zugriff am 07.07.2026).
[3] IBM: Cost of a Data Breach Report 2025. Verfügbar unter: https://www-api.ibm.com/adobe/assets/urn:aaid:aem:607b9590-38e0-4c91-b433-aa8a17f5b5e8/original/as/cost-of-a-data-breach-2025-full-report.pdf (Zugriff am 03.08.2026).
[4] Lemon Learning: Learning by Doing: Definition, Benefits & Advantages. Verfügbar unter: https://lemonlearning.com/blog/6-advantages-of-learning-by-doing (Zugriff am 08.07.2026)
[5] Emerge Digital: Cyber Security Training vs Awareness: Key Differences. Verfügbar unter: https://emerge.digital/resources/cyber-security-training-vs-awareness-key-differences/