I am glad to see Secure Code Warrior is not the only one thinking about how to deliver a change in behavior within a company using positive reinforcement and game-based elements.
This article in the WSJ really highlighted that cybersecurity awareness is more effective and has a greater impact on employees when the training is not dreadful, boring, repetitive or just useless. In the past, cybersecurity training was typically delivered by security experts who were technical and provided in-depth material but without much thought on how to deliver key messages that stuck with employees.
However, more and more, certainly with clients we work with, I am seeing how organizations are now involving marketing and communication teams and change managers, as well as using digital animation in their content and running events and challenges to make cybersecurity training more fun and engaging. With cybsersecurity threats growing year after year, security awareness and employee training is the most important investment your organization can make.
Positive-reinforcement campaigns are often one of the best ways to modify risky behavior, but they're "definitely an outlier" in the corporate world, says Ms. Sedova