How to hold a Cybersecurity Day for employees: station program, safe drills, team roles, data handling, and budget factors.
Cybersecurity Day for Employees turns familiar rules from a presentation into action: a participant hears about suspicious emails and immediately decides where to report them. In a tabletop exercise, managers find the points where decisions get lost. At Aventura, we build this format together with the client's dedicated team. The Chief Information Security Officer (CISO) is responsible for content and safe boundaries, while we are responsible for the program, routes, equipment, and venue operations.
Subscribe to Aventura's Telegram channelWhat's important to know: Step-by-step preparation
Why does a company need a dedicated Cybersecurity Day?
In short: on this day, the company checks how employees report suspicion, and managers make decisions based on an incident scenario. The format combines explaining the rules, practicing actions, and reviewing processes. A single event does not eliminate risk or replace technical protection. After it, a list of improvements with responsible employees remains.
The U.S. National Institute of Standards and Technology (NIST) describes cybersecurity and privacy training as a continuous program with a recurring cycle of assessment and improvement, so Cybersecurity Day is best placed between other communications. Before the event, collect typical employee difficulties. After it, send short reminders. Separately, check whether the identified gaps have been closed.
Формат особенно полезен, если обычный курс завершает тест, но не показывает, как человек действует в рабочей ситуации. Сотрудник может знать термин «фишинг» и не понимать, куда отправить подозрительное письмо. Руководитель способен помнить план реагирования и при этом не знать, кто принимает решение об остановке операции. День даёт безопасное место для таких вопросов.
До подготовки зафиксируйте управленческую задачу. Подходящие формулировки выглядят так:
- Проверить, знают ли сотрудники штатный канал сообщения о подозрительном запросе.
- Check whether employees know the standard channel for reporting a suspicious request.
- See whether the escalation chain is clear to managers and support.
- Practice verifying a payment or HR request through an independent channel.
- Identify gaps in communication, access, and instructions.
Цель «повысить киберграмотность» слишком широка. Она не подсказывает, что должен сделать участник и какой результат получит заказчик. Мы начинаем бриф с наблюдаемого действия, а уже затем выбираем станции, сцену и оформление.
Boundaries of a safe format
Безопасный День кибербезопасности не требует вредоносного кода, производственных данных или публичного списка ошибок. Учебная среда отделена от рабочего контура. Сценарии проверяют сообщения, решения и роли. Профильная команда заранее утверждает стоп-критерии, тестирует демонстрации и может остановить упражнение без давления на участника.
Агентство по кибербезопасности и защите инфраструктуры США (CISA) строит настольные учения вокруг целей, сценария, вопросов для обсуждения и итогового отчёта. Участники обсуждают, что делать до инцидента, во время него и после. Такой формат позволяет проверить процесс без воспроизведения атаки. На экране может появиться учебное сообщение, но команда не запускает опасный файл и не исследует реальную инфраструктуру.
Мы разделяем разрешённые и запрещённые механики ещё на этапе концепции.
В таблице собраны ключевые пункты раздела: Table. Boundaries of a safe format, Can include. The table summarizes the key points of the section: Point, What the candidate gets, What the team records
| Table. Boundaries of a safe format | Can include |
|---|---|
| Do not include | Mock-ups of suspicious emails and messages |
| Real malicious attachments and links | Verification of a request through the approved channel |
| Phishing report button training | Participants scanning the work infrastructure |
| Tabletop exercise on roles and decisions | Exploitation of a vulnerability in the production environment |
| Demo of multi-factor authentication on a test account | Using a personal device without an agreed business need |
| Crisis message debrief | Public ranking of the 'most inattentive' |
Для каждой демонстрации нужен владелец содержания. Обычно это CISO, сотрудник службы информационной безопасности или приглашённый профильный эксперт со стороны заказчика. Dance groups организаторов не изображает специалиста по киберзащите и не меняет согласованный сценарий ради зрелищности.
Стоп-критерии тоже записывают заранее. К ним относятся неожиданный вывод реальных данных, переход в рабочую систему, потеря контроля доступа и любое отклонение от утверждённой учебной среды. При таком сигнале ведущий ставит блок на паузу, техническая команда отключает его, а участникам сообщают нейтральную причину и следующий шаг.
A program of stations and a joint drill
Рабочая программа сочетает короткий общий старт, несколько станций с конкретными заданиями и финальный разбор. Группы начинают с разных точек, чтобы не создавать очередь. Размер волны задаёт самая тесная станция. Для руководителей можно добавить отдельное настольное учение, пока сотрудники проходят практические модули.
Станция отличается от мини-лекции. Участник сообщает о подозрении, проверяет запрос или принимает решение по вводной. Карточка фиксирует цель, вместимость и ведущего. Equipment, стоп-критерий и резерв записываются отдельно.
Пример программы можно собрать так:
В таблице собраны ключевые пункты раздела: Table. Budget without hidden blocks, What the participant does, What the team records. The table summarizes the key points of the section: Point, What the candidate gets, What the team records
| Table. Budget without hidden blocks | What the participant does | What the team records |
|---|---|---|
| Common start | Learns the goal, rules, and help channel | Understanding boundaries and no punishment |
| Report, don't investigate | Chooses an action for several message mock-ups | Convenience of the standard channel and typical questions |
| Verification via a second channel | Confirms a payment or HR request according to procedure | Routing errors and missing contacts |
| Access and recovery | Works with a test account | Clarity of instructions and points of contact |
| Data minimization | Removes unnecessary fields from a form or list | What data is collected without a business purpose |
| Настольное учение | Tabletop exercise | Discusses decisions on sequential injects |
| Roles, escalation, gaps, and disagreements | Crisis communication | Drafts a short message for the audience |
| Speed of approval and a single version | Final debrief | Cross-checks decisions and asks questions |
The exact set depends on the audience: the finance unit is more interested in verifying a payment request, while the HR team works through the protection of personnel data. Managers make decisions on escalation and priorities. IT specialists, together with the support service, check the receipt of training signals. A single lecture for all these roles rarely delivers equally useful results.
Flows are designed from the narrowest point. If eight people can work safely at a station, a group of twenty-five will create a queue and lose attention. It is better to split the audience into waves, give them different starting numbers, and repeat the route color on the badge, signage, and screen.
Improvement plan and action owners We covered the detailed rotation principle in the article about. For cybersecurity, the content changes, but the operational logic remains: one module, one action, known capacity, transition time, and reserve.
. For cybersecurity, the content changes, but the operational logic remains: one module, one action, known capacity, transition time, and buffer. Request a quote from us.We can link expert content, stations, the venue, and routes in a single scheme.
How to prepare a phishing simulation without setting a trap for employees?
In short: the simulation tests how the system works without looking for someone to blame, so the information security manager, HR, IT, and legal service agree on the goal and audience in advance. They also determine the legal basis for processing and the retention period for results. The training email does not collect real passwords, and the team tests it on a control group. After the exercise, a calm debrief takes place.
The British National Cyber Security Centre directly warns that no training package will teach you to recognize every phishing attempt. Punishing clicks can reduce the willingness to report a mistake. Therefore, a useful metric takes into account not only the action on the email but also reports through the official channel.
The minimum set of pre-launch checks includes:
- Описать цель и границы симуляции одним документом.
- Describe the purpose and scope of the simulation in one document.
- Align the audience, scenario, and data processing with the CISO, HR, IT, and legal team.
- Avoid topics such as illness, death, dismissal, debt, and other distressing lures.
- Do not store entered passwords or use live malicious code.
- Test the email, page, notification, and report with a test group.
- Ensure the support service is ready to receive training messages.
- Appoint someone who can stop the campaign.
- Prepare a supportive debrief and clear instructions.
- Restrict access to the results and determine the deletion period in advance.
Уровень предварительного уведомления зависит от методики и локальных документов. The level of advance notice depends on the methodology and local documents. It is impossible to universally promise complete secrecy or require the same type of consent in all organizations. The decision is made by the client's legal and specialized team
In this article, we raise operational and ethical questions, but we do not replace legal advice.
Team roles and areas of responsibility
The information security officer approves the content and can stop the exercise, while HR monitors labor rules and a non-punitive tone. IT prepares the test environment together with the security operations center (SOC). The legal department checks data handling. At Aventura, we align these decisions with the program, venue, flows, and equipment.. The information security officer approves the content and can stop the exercise, while HR monitors labor rules and a non-punitive tone. IT prepares the test environment together with the security operations center (SOC). The legal department checks data handling
At Aventura, we align these decisions with the program, venue, flows, and equipment.
| Table. Roles and a single route owner | Table. Team roles and areas of responsibility | Responsibilities before the event |
|---|---|---|
| Responsibilities on the day of the event | CISO or training program owner | Goals, content, safe boundaries, evaluation criteria |
| HR | Scenario and escalation decisions | Employment policies, psychological safety, employee participation |
| Support and handling of contentious situations | IT, SOC and support service | Test environment, reporting channel, backup and stop mechanism |
| Signal reception, technical support, stopping the block | Lawyer or data protection officer | Legal basis for processing, notification, access and storage |
| Internal communications | Monitoring compliance with agreed boundaries | Invitation, neutral tone, materials for managers |
| revises the sales feedback guide | Unified messages to participants | Venue, stations, timing, equipment, navigation |
| Managing flows and program versions | Facilitator | Questions and sequence of prompts |
| Discussion pace without hinting at the answer | Evaluator or secretary | Observation form and report template |
| Decisions, gaps and corrective actions | Полномочия и ресурсы | Authority and resources |
The table summarizes the key points of the section: Role, Responsibility before the event, Responsibility on the day of the event
One person can combine several functions, but it is useful to keep the role titles. Then the team understands who observes the signal, who makes the decision, who executes it, who informs the participants, and who records the outcome. We also use this scheme in the event's crisis plan.. One person can combine several functions, but it is useful to keep the role titles. Эту схему мы также используем в the event crisis management plan.
Step-by-step preparation
Preparation starts with the goal, audience, and data boundaries. After that, the team assembles the route, test environment, and communications. Every complex action undergoes a technical rehearsal on the same devices and files that will be used at the venue. The final run closes out remarks with a repeat test instead of a "fixed" note.
The working sequence looks like this:
- One person can combine several functions, but it is useful to keep the role names. Then the team understands who monitors the signal, who makes the decision, who executes it, who informs participants, and who records the outcome. We also use this scheme in
- Assign an owner for the result and formulate an observable participant action.
- Split audiences by roles, departments, shifts, and participation methods.
- Approve permissible training scenarios, data, and stop criteria.
- Select stations and a general drill for each audience's tasks.
- Create a flow map, module capacity, and transition intervals.
- Define registration, access, and the minimum set of fields.
- Prepare test accounts, mock-ups, and backup materials.
- Coordinate invitations, rules, and the message for managers.
- Conduct a technical rehearsal from participant entry to the final report.
- Update the scenario after testing and repeat the problem areas.
The rehearsal requires the same links, devices, screens, and file versions that will be used at the venue. The team goes through invitation, registration, login, station, result capture, and transition. Network failure, device failure, incorrect file, and congestion at a narrow zone are modeled separately.
Prepare the final report form and a corrective action plan. technical event rehearsal.
If participants work in shifts, there is no need to compress the program into one shared window. You can repeat the same modules in several waves, and record the common kickoff or hold it for each shift. Key instructions and access to the expert should remain equivalent.
What data to collect and how to store it?
Collect only the data that is followed by a clear action: for registration, name, department, participation status, and a request for assistance are usually enough. Exercise results are best analyzed in aggregates. Before the event, the team approves the set of fields, access, and retention period. It also sets the rules for anonymization and deletion.
Article 5 of Federal Law No. 152-FZ requires linking data processing to a specific purpose. There should be no more data than is needed for that purpose. Identifying information cannot be stored longer than necessary unless a law or contract provides otherwise. The application of the norm to a specific project is checked by the client's lawyer.
For each field, ask four questions:
- Each issue gets reproduction conditions, an owner, and a deadline. After the fix, the team repeats the same step. A detailed scheme is in the material about
- What decision will we make based on this value?
- Who will see it and why?
- When will it no longer be needed?
For a report to management, the number of completed stations, aggregate audience data, and a list of process gaps are often sufficient. A personal 'who made a mistake' table creates additional risk and rarely helps improve the procedure. If individual results are needed, this decision must have separate justification and restricted access.
Registration is maintained in a single main list. A backup export is stored with a designated employee and used only in case of failure. An accessibility request is framed as necessary assistance, not a request to disclose a diagnosis. Больше практических деталей есть в статье про регистрацию участников мероприятия.
Availability of in-person and hybrid programs
A participant must be able to follow the route in an accessible way: perform an action, observe, listen, read, or ask a question. The venue, broadcast, materials, and backup are checked together. Registration allows confidential requests for assistance. Subtitles, microphones, readable navigation, and text alternatives are retained even when switching to the backup scenario.
The World Wide Web Consortium (W3C) recommends considering the in-person venue and the remote platform, verbalizing significant visual information, and using a quality microphone. The program should begin with a clear overview, and it is useful to repeat the main takeaways in an accessible text format.
Include in the production plan:
- event participant registration
- an accessible route from the entrance to all required areas;
- seats for participants who need to sit or use a wheelchair;
- large signage with sufficient contrast;
- subtitles or a text alternative for key videos;
- pre-event materials in an accessible format;
- a station that does not require a personal smartphone;
- a quiet way to ask a question;
- breaks between intensive blocks;
- maintaining accessibility in the backup environment.
A hybrid attendee should not receive a shortened version without the ability to act. If a station requires sending a training message, prepare a test remote channel. If that is impossible, offer an equivalent scenario for observation and decision-making. Technical guidelines are collected in the material about accessible event streaming.
Metrics without promises of zero incidents
Measure actions and fixes instead of abstract “security.” Useful metrics include use of the standard channel, correctness of escalation, time to first report, support workload, and completion of the improvement plan. A single Cybersecurity Day does not prove compliance with a standard and does not promise the absence of incidents. Trends should only be compared between comparable exercises.
The final document links the exercise objectives to the actions the team could observe. It records strengths, areas for improvement, corrective actions, owners, and deadlines. This is more useful than a single average quiz score and helps teams return to the decisions after the event.
A working set of metrics may include:
The table summarizes the key points of the section: Metric, What It Shows, Limitation. Use it as a quick reference when preparing the event.
| Metric | What it shows | Limitation |
|---|---|---|
| Station completion | Route coverage | Does not prove mastery |
| Training messages via the standard channel | Process usage | Depends on tool availability |
| Time to first message | System response speed | Compared only in similar scenarios |
| Choosing the right escalation | Clarity of roles | Requires a predefined benchmark |
| Load on the support service or SOC | Readiness to handle the flow | Does not assess response quality by itself |
| Identified gaps | What needs to be fixed | A large number can mean honest diagnostics |
| Actions with an owner and deadline | Continuation manageability | A checkpoint date is needed |
| Anonymous clarity assessment | Trust and applicability | Does not replace observation of action |
Do not promise to “eliminate the human factor” or reduce risk by an arbitrary percentage. People work within a system: their actions are influenced by interfaces, access rights, workload, technical barriers, and the quality of support. The European Union Agency for Cybersecurity (ENISA) also builds training programs around audiences, channels, and metrics, rather than around a single one-size-fits-all event.
After the Day, schedule a short owners’ debrief. They close out quick fixes, route complex issues into the work plan, and give employees a clear answer: what the company changed after the exercise. Without this, the format risks remaining a bright but isolated episode.
Cybersecurity Day budget
The budget depends on the number of stations, streams, and repeats. Experts, test equipment, venue, accessibility, and rehearsal are calculated separately. The structure and scope are approved first, then production is costed. We do not quote a universal price per participant: the same number of guests may require one hall or a complex multi-zone program for several shifts.
It is convenient to assemble the estimate by blocks:
The table summarizes the key points of the section: Block, What can be included, Main driver. Use it as a quick reference when preparing the event.
| Table. Budget without hidden blocks | What can be included | Main driver |
|---|---|---|
| Concept and program | Brief, route, station passports, debrief scenario | Number of audiences and modules |
| Experts | Content preparation, facilitation, assessment | Complexity and number of repetitions |
| Venue | Halls, meeting rooms, access hours, furniture | Flows and venue mode |
| Equipment | Screens, sound, network, test devices, backup | Format of demonstrations |
| Registration and navigation | Lists, badges, route materials | Access level and number of waves |
| Dance groups | Producer, coordinators, hosts, technical service | Number of parallel zones |
| Accessibility | Subtitles, translation, adaptation of materials and route | Потребности аудитории |
| Audience needs | Logistics and catering | Delivery, setup, breaks, shift work |
| Geography and duration | Тест площадки, устройств, файлов и резервов | Testing the venue, devices, files and backups |
| Post-event materials | Number of complex transitions | Summary, recording, action plan, available versions |
It is better to cut what does not affect the learning activity. Sometimes you can simplify the decor while preserving the test environment, accessibility, coordination, and rehearsal time. An expensive stage will not fix a non-working message button or replace a specialist who has the authority to make a decision.
Reporting requirements The general logic of budget baskets is covered in the article about. For a preliminary calculation, we need the city, audience, format, number of stations, shift pattern, requirements for data, venue, and hybrid participation.
Brief for the agency: what to prepare
A good brief separates domain content from event organization: the client brings the goal, audience, security owner, and constraints. At Aventura, we clarify the venue, flows, equipment, accessibility, team composition, and decision schedule. If there is not enough input yet, we hold a kick-off meeting and collect questions. The information security policy is determined by the client's domain team.
Before contacting us, it is useful to prepare:
- . For a preliminary estimate, we need the city, audience, format, number of stations, shift pattern, and requirements for data, the venue, and hybrid participation.
- The goal of the Day and the action employees need to practice.
- Audience composition, cities, departments, shifts, and remote participants.
- The content owner and the list of approvers from the CISO, HR, IT and legal teams.
- Acceptable scenarios, data, devices, and stop criteria.
- Desired stations and mandatory internal procedures.
- Requirements for registration, access, photography, recording, and reporting.
- Accessibility and language needs.
- The venue or constraints on its selection.
- The budget range and the line items that cannot be cut.
At Aventura, we can take on the organizational part: concept, scenario plan, venue, routes, equipment, design, coordinators, rehearsal, and work on the day of the event. The client's domain expert approves the content of the stations and the cyber exercise. This division gives the team clear boundaries and helps avoid turning a serious topic into an entertainment quiz.
Frequently asked questions
In short: on this day, the company checks how employees report suspicion, and managers make decisions based on an incident scenario. The format combines explaining the rules, practicing actions, and reviewing processes. A single event does not eliminate risk or replace technical protection. After it, a list of improvements with responsible employees remains.
Безопасный День кибербезопасности не требует вредоносного кода, производственных данных или публичного списка ошибок. Учебная среда отделена от рабочего контура. Сценарии проверяют сообщения, решения и роли. Профильная команда заранее утверждает стоп-критерии, тестирует демонстрации и может остановить упражнение без давления на участника.
Рабочая программа сочетает короткий общий старт, несколько станций с конкретными заданиями и финальный разбор. Группы начинают с разных точек, чтобы не создавать очередь. Размер волны задаёт самая тесная станция. Для руководителей можно добавить отдельное настольное учение, пока сотрудники проходят практические модули.
In short: the simulation tests how the system works without looking for someone to blame, so the information security manager, HR, IT, and legal service agree on the goal and audience in advance. They also determine the legal basis for processing and the retention period for results. The training email does not collect real passwords, and the team tests it on a control group. After the exercise, a calm debrief takes place.
The information security officer approves the content and can stop the exercise, while HR monitors labor rules and a non-punitive tone. IT prepares the test environment together with the security operations center (SOC). The legal department checks data handling. At Aventura, we align these decisions with the program, venue, flows, and equipment.. The information security officer approves the content and can stop the exercise, while HR monitors labor rules and a non-punitive tone. IT prepares the test environment together with the security operations center (SOC). The legal department checks data handling
Preparation starts with the goal, audience, and data boundaries. After that, the team assembles the route, test environment, and communications. Every complex action undergoes a technical rehearsal on the same devices and files that will be used at the venue. The final run closes out remarks with a repeat test instead of a "fixed" note.
The decision management will make after the final debrief. take a look at our portfolioIf you are preparing a Cybersecurity Day for employees, request a quote. To get a preliminary estimate,
Sources
- NCSC: Phishing attacks, defending your organisation
- ICO: Monitoring workers checklists
- W3C WAI: Making Events Accessible
- КонсультантПлюс: Федеральный закон № 152-ФЗ «О персональных данных»
- Microsoft Learn: Attack simulation training
- ENISA: Awareness Raising in a Box
Contents
Was this article helpful?
Looking for an idea or someone to bring your vision to life? Event Agency Aventura has been organizing events in Moscow and across Russia for 16 years. Leave your number and our manager will call you back.
