Skip to content
Awareness training and Behavioral Defense Engineering

Security awareness training: what to keep and what to add

Keep the courses and the completion records your auditors ask for. Then add what training leaves out. Every report gets an answer, and people practice on the phone as well as in the inbox.

Where the course ends

Awareness training teaches people what an attack looks like and leaves a record your auditor can check. Keep it.

Behavioral Defense Engineering starts after the course. When someone reports a suspicious email, clicks a test link or types a password into a fake login page, Cyberdise uses that moment to decide what they practice next.

SCORM courses come in and go out, so nothing you built is lost. Run the Cyberdise LMS, or keep your own and add the loop around it.

Measuring it and closing the loop

Four places where the day to day picture changes.

The model most programs run today.Security awareness training
The same program with the loop added.Cyberdise Behavioral Defense Engineering
What counts as success
Who finished the course

Completion rates and attendance, the numbers an audit asks for.

Behavior, per person and team

What people report, click and enter, rolled into a behavioral risk score per person, department and tenant.

Click rate as proof
One click rate per campaign

A hard test email pushes it up and an easy one pulls it down, whatever people learned.

Clicks, credentials and reports side by side

Every campaign tracks clicks, credential entry, file opens and reports, so a click rate is read next to what else people did.

After a click
A training page

Most people close it within seconds and get back to work.

Follow-up matched to skill

Training follows each person's level, and practice repeats the scenarios that worked on them. A training page after a click is still there where you want one.

What happens to a report
It lands in a mailbox

Someone works through the reports by hand, and the person who reported often never hears back.

Every report gets an answer

AI scores each reported message and tells the reporter the result. Cases are grouped and go to the SOC through SOAR integration or the REST API.

What changed behavior in our own study

Training alone lowered risky clicking, and realistic AI spearphishing exercises lowered it further.

~60%less risky clicking after AI spearphishing exercises, against baseline
8.9%visited the malicious site after the exercises, down from 22.6%; control group 20.4%
539employees in four randomized groups, November 2024 to June 2025

Source: AISP study

Running it every week

What it takes to keep a program going.

The model most programs run today.Security awareness training
The same program with the loop added.Cyberdise Behavioral Defense Engineering
How often it runs
Once a year, plus a monthly test

The course comes around annually, and simulations follow a fixed calendar.

A continuous loop

Groups update themselves from behavior. Campaigns and e-learning follow each person's level.

Channels
Mostly email

Attackers also call and text. Most programs still test only the inbox.

Email, SMS and voice

Phishing, smishing and phone-based vishing exercises, alone or combined in one campaign.

Training content
The same library for everyone

Ready made modules, assigned by department or by date.

Editable, or entirely your own

Every module can be edited or replaced with your own. Courses are built to WCAG AA, and SCORM goes in and out.

Effort to run it
Every campaign built by hand

Templates, target groups and schedules take hours each month.

Describe the campaign, approve it

The Campaign Automator builds a campaign from a plain language brief, and nothing sends until an operator approves it.

The employee's role
The one who failed the test

A missed simulation feels like a mark against you, so people stop reporting.

A sensor the SOC can use

Every report earns a reply, and good habits get reinforced on the spot.

Awareness training is one layer of the stack

It is not useless. It does its job best with the layers around it.

Email securityFilters and hardening stop what they can before anyone sees it.
Awareness trainingIt gives everyone the baseline and the audit record, and in our own study it lowered risky clicking on its own.
Realistic practiceExercises by email, SMS and phone that feel like the real attack.
Report and responseWhat people report reaches the SOC, and everyone who reports gets an answer.
Is security awareness training still mandatory?
For many organizations, yes. NIS2 asks the EU entities in its scope for cybersecurity training, and ISO 27001 audits look for it. Swiss companies are not bound by NIS2 directly, but operators of critical infrastructure have had to report cyberattacks to the NCSC since April 2025. Keep the training.
Does phishing training work?
It helps, and less than click rates suggest. In our own study, training lowered risky clicking, and AI spearphishing exercises brought about 60% less risky clicking against baseline. The difference was practice with realistic attacks.
How does this relate to human risk management?
Human risk management is the analyst term for measuring and reducing people related risk. Behavioral Defense Engineering is how Cyberdise runs it. Report, analyze, respond, give feedback, practice, repeat.
Can we keep our LMS and our SCORM courses?
Yes. SCORM courses import and export, and every module can be edited. Run the Cyberdise LMS or keep yours.
Will more reporting overload our SOC?
It is built not to. AI scores each report and answers the reporter, so analysts see grouped cases instead of every single message, and cases can go on to your SOAR.

Your training stays. The question is where the loop attaches.

In a 30-minute demo, follow one reported email from the button to the answer the reporter gets.