Skip to main content

      With cybercrime on the rise, employees are increasingly vulnerable to online risks. Did you know that human errors are still the leading cause of cybersecurity incidents? Yes, one click, and you hit the jackpot: a whole lot of trouble! Thankfully, we can prevent that with a robust cyber awareness plan. Because, let's be honest, you likely have better things to do than putting out fires, right?

      But how do you start setting up your awareness campaign? What activities do you need to do to avoid these human errors? No worries, we’ve got you covered. Together with our awareness expert, Freya Covens, we’ve listed all the different activities you should include in your awareness campaign - as well as several tips to make them more effective!

      Awareness calendar

      The first thing you need to do is set up an awareness schedule/calendar. An awareness calendar strategically schedules and organizes different cybersecurity activities throughout the year, such as training sessions, phishing exercises, and newsletters. When developing an effective awareness program, it's crucial to be interactive and diverse in the approach. By covering different topics, individuals remain vigilant and informed about potential threats, reducing the likelihood of falling prey to cyber-attacks.

      Benny Bogaerts

      Partner, Technology | Advisory

      KPMG in Belgium


      Security mascot

      Keeping your employees engaged might be a challenging task - have you thought about creating a security mascot?

      Security mascots can become a central figure in your awareness campaigns. The mascot can help you convey important privacy and security messages in a friendly and approachable manner, making the information more digestible and memorable for employees. Additionally, the mascot’s presence attracts your employees’ attention and helps to create a sense of connection and familiarity with your audience, creating a visual recognition point that makes messages more memorable and recognizable.

      Newsletters & flyers

      Frequent distribution of cybersecurity newsletters and flyers keeps employees informed about the latest trends, threats, and best practices. However, what good are these newsletters if employees don’t read them? Have you thought about creating cartoons (e.g., your security mascot) to make these newsletters more interesting? Or creating short scenarios where the decisions of employees lead to different outcomes – such as getting hacked or not?

      The true value of these newsletters lies in employees actively reading and absorbing the insights and advice shared within them, making it very important that the content is presented in an interactive and engaging way.

      Phishing exercises

      Regular phishing exercises are like cyber self-defense: they help to train your employees to spot and avoid actual phishing emails. These exercises provide valuable hands-on experience in identifying and reporting suspicious emails, empowering individuals to play an active role in protecting the organization from potential cyber threats. By identifying and educating employees who may fall for phishing attempts, organizations can proactively strengthen their defenses and minimize the risk of successful phishing attacks.

      A crucial aspect of these phishing exercises is teaching the employees the process for reporting the phishing emails. Based on our experience, we have observed that the more steps employees need to take to report phishing emails, the less likely they are to actually follow through with reporting them. For example, if employees are required to log a ticket instead of simply clicking on a button in Outlook, they are less likely to report a phishing email, so make your reporting process as easy as possible! 

      E-learnings/awareness sessions & rewards

      Regular awareness sessions or e-learning courses offer an opportunity to educate and engage employees on cybersecurity best practices and threat awareness. By fostering a culture of vigilance and proactivity, organizations can reduce the risk of security breaches and data compromises.

      How do you make learning about these topics interesting? Have you considered offering rewards to employees who successfully complete all of their e-learning courses and attend all of the scheduled sessions? Alternatively, you could provide a small incentive to those who achieve a specific grade in quiz assessments, which can encourage employees to remain engaged during the sessions.



      Did you know

      At KPMG, we assist clients in implementing comprehensive security awareness programs? All the activities highlighted in this magazine can be leveraged to support your organization on its cybersecurity journey.


      What did we learn?

      In today's digital landscape, cyber awareness is more important than ever. With the rise of sophisticated cyber threats, individuals and organizations must prioritize cyber awareness to mitigate the risks of cyber attacks and data breaches.

      Implementing a structured calendar of activities is an effective way to reinforce cyber awareness. This includes regular phishing exercises, newsletters, e-learning courses, and in-person sessions. 




      Explore our latest insights on cybersecurity

      KPMG Technology services.

      Stay informed

      Be the first to know about top business trends that can drive success for your company.

      stay informed