Visit Award Program for cybersecurity awards and recognition.

How to Recognize Cybersecurity Awareness That Changes Everyday Decisions

Cover Image for How to Recognize Cybersecurity Awareness That Changes Everyday Decisions
David Matthews
David Matthews

A cybersecurity awareness initiative can produce polished videos, busy event calendars, and impressive completion figures. An award nomination still needs to explain what people became better able to do.

That might mean checking an unexpected payment request through an established channel, reporting a suspicious message promptly, or asking for help before sharing sensitive information. These are specific decisions that a learning initiative can support and reviewers can examine.

Recognizing this work fairly means looking at the learning, the workplace around it, and the evidence connecting the two. The strongest nomination describes a bounded improvement without treating attendance as proof of safer behavior or making employees responsible for every security failure.

Start with an everyday decision

Define the situation the initiative was designed to improve. “Raise awareness of cyber threats” is too broad to guide an assessment. “Help purchasing staff verify requests to change supplier payment details” gives reviewers a clear audience, task, and intended action.

Explain the starting difficulty. Perhaps staff knew the policy but could not locate the verification procedure. Perhaps temporary workers received different instructions from permanent employees. Perhaps people hesitated to report a mistake because they did not know what would happen next.

Then describe what the nominee changed: the teaching approach, the supporting instructions, the reporting route, or the coordination between teams. Keep the achievement within the award's eligible period and identify any work that preceded it.

This framing is consistent with NIST's cybersecurity and privacy learning guidance, which emphasizes behavior change and ongoing evaluation. For an award, it also creates a useful test: can the submission show how the initiative helped people make the named decision?

Check who could actually take part

Reach matters when it tells reviewers whether the intended audience had a realistic opportunity to learn. A total attendance figure can hide important gaps.

Ask whether the initiative accommodated shift patterns, remote work, language needs, assistive technology, and differing access to devices. A recording is not automatically accessible, and a session scheduled during a busy operational period may exclude the people who most need it.

Useful evidence could include an explanation of barriers discovered, the adaptations made, and feedback confirming whether those adaptations helped. Reviewers should look for purposeful choices rather than award points simply for offering many formats.

Also distinguish access from effectiveness. Making a session available establishes an opportunity. Completing it establishes participation. Neither alone shows that someone can apply the guidance. Give credit for removing a real barrier while being clear about what the evidence establishes.

Separate participation, understanding, and application

An employee turning from a laptop to ask a trusted colleague a question

Organize the evidence around increasingly practical questions. Did the intended people participate? Did they understand the relevant guidance? Could they use it in a realistic situation? Is there evidence of a useful change in work afterward?

A completion record answers the first question. A short knowledge check may answer part of the second. A scenario in which someone explains their next action can provide evidence about application. An approved account of a later workplace decision can help connect the learning to practice.

None of these is a perfect measure. A correct quiz answer does not guarantee future behavior, and a single positive example does not establish that every participant improved. Combine a few appropriate forms of evidence and state their limits.

For a hypothetical example, staff attend a session on unexpected supplier requests. The nomination becomes more informative if it also shows that participants can find the approved verification procedure, explain when to use it, and identify where to get help. It should not claim that the session prevented a financial loss unless that claim has a defensible basis.

Put phishing exercise results in context

Phishing simulations can contribute evidence, but a lower click rate is difficult to interpret without knowing what changed between exercises. The message, audience, delivery conditions, and task context all matter.

NIST's Phish Scale was developed to help practitioners assess a message's human detection difficulty and interpret simulation results. That reinforces a practical award-review principle: the nomination should explain the comparison before asking judges to celebrate the number.

Were the exercises similarly difficult? Did the same population receive them? Did email filtering, warnings, or reporting tools change? Were staff already familiar with the scenario? A different outcome may reflect several influences alongside learning.

Look beyond clicking, too. A timely report through the correct route, a sound explanation of how to verify a request, or a useful question raised during a debrief can reveal skills the click figure does not capture.

Avoid turning the exercise into a claim about employees being careless. The submission should explain what the team learned about its guidance and working conditions, and how it improved them. A simulation is evidence about a particular exercise, not a complete measure of organizational security.

Examine whether the workplace supports the lesson

Good guidance needs a workable path to action. Teaching people to report suspicious messages is less convincing if they cannot find the reporting channel or receive no useful response.

Ask what happens after someone follows the advice. Can they contact the right team? Is an alternative available when the usual person is absent? Do managers allow time for verification when a request appears urgent? Are instructions consistent across the teams involved?

These questions make collaboration part of the achievement. An awareness lead may work with service desks, finance teams, accessibility specialists, or operational managers to remove obstacles. The nomination should identify those contributions rather than credit every improvement to the training material alone.

The article on breaking down silos in security teams explores why coordination matters. Here, reviewers can look for a concrete handoff that became clearer or a procedure that staff could actually follow after the initiative.

Preserve trust while collecting evidence

A reviewer arranging three groups of blank evidence cards beside a notebook

An award entry should demonstrate improvement without exposing individual employees' mistakes, private messages, or unnecessary personal details. Share only evidence that the organization is authorized to provide through the program's established process.

Aggregated results, approved summaries, and anonymized examples may be sufficient. Check whether a supposedly anonymous account could still identify someone through their role, location, or circumstances. Do not attach raw individual performance exports simply because they are available.

Interpret reporting trends carefully. More reports could reflect greater willingness to ask for help, more suspicious messages arriving, a simpler reporting tool, or several changes together. Fewer reports could also have multiple explanations. State what is known rather than choosing the interpretation that makes the nomination sound strongest.

Reviewers should reward honest limits. A useful initiative can deserve recognition even when its effect cannot be reduced to a single percentage. The guide to documenting cybersecurity impact for an award nomination explains how to connect a starting condition, an intervention, and a result without overstating causation.

Identify what endured and who contributed

Look for useful practices that remained after a campaign finished. That might be an updated verification guide, an improved induction session, a dependable reporting handoff, or a recurring review that changes material when staff encounter confusion.

Ask who maintains those practices and whether someone else can continue them. A campaign that relies on one enthusiastic person answering every question may have created value, but the nomination should acknowledge that dependency.

Attribute the achievement accurately. For an individual entry, identify the nominee's decisions, designs, and coordination. For a team entry, explain the roles of educators, operational staff, and those who supported access or evaluation. A senior sponsor and the person who redesigned the lesson may have contributed differently.

Evaluate that account through a fair cybersecurity award review process, using the published category criteria. A modest initiative that solved a specific problem can offer strong evidence of excellence without matching the scale or budget of a larger campaign.

Build a focused awareness nomination

Before submission, check that the account answers five questions:

  1. Which decision changed? Name the audience, situation, intended action, and starting difficulty.
  2. What did the nominee improve? Explain the learning approach and any supporting workplace changes.
  3. What can the evidence show? Distinguish participation, understanding, application, and observed outcomes.
  4. What limits the conclusion? Identify differences between comparisons, other influences, and uncertainty.
  5. What remains useful? Show how the guidance, support, or evaluation continues, with accurate credit and appropriate disclosure.

Choose a small set of evidence that answers those questions within the program's rules. Explain specialist terms and let an authorized colleague check the account for attribution and confidentiality.

Cybersecurity awareness deserves recognition when it helps people exercise useful judgment in the situations they actually face. A clear nomination shows how that happened, what supports the conclusion, and which people made the improvement possible.