Combine onboarding, periodic refreshers, role-based modules, just-in-time messages, exercises, manager conversations, security champions, incident lessons learned, and short communications tied to current risk. The objective is repeated exposure to important behaviors in the context where people use them.
Make examples match the organization. A generic lesson about “never clicking links” is less useful than showing how employees should inspect unexpected authentication prompts, what the legitimate finance workflow looks like, how external collaboration is approved, or where the real report-phish button appears.
Design for accessibility, language, job function, location, technology access, and shift patterns. Security learning that requires a desktop browser during office hours may systematically exclude operational, field, clinical, manufacturing, or frontline personnel.