Awareness training need to focus on impact. Not on being fun.

How do you mess up your security awareness program? At Cybersec Netherlands, Arno van den Hof, gave a practical guide: Start without governance. Use a methodology built on assumptions. Assume that people want to take trainings and be sure to have a compliance mindset.

‍

September 22, 2026

The Junglemap breakout session drew a full house when Arno van den Hof, Country Manager in the Netherlands, talked about the mistakes many organisations do when it comes to awareness training. The right security behaviours that any CISO would like to see in their organisation is a combination of knowledge, opportunity and willingness to do the right things.
- We need to stop focusing on the knowledge, said Arno van den Hof. Knowing what’s right doesn’t mean acting in the right way.

Instead,organisations need to start focusing on behaviours. The trainings need to beactionable and relevant. And short.
- We know from our user data that 3 minutes is a max, says Arno van den Hof. If we stretch our NanoLearning lessons to 5 minutes, people will not finish their lessons.

Spaced repetition
Another key success factor is a learning method built on applied spaced repetition that will beat the forgetting curve. This, in combination with low thresholds for end users is what really can help change the culture in the organisation.  
- Many organisations say “let’s make a fun video!”, but that’s the wrong solution, says Arno van den Hof. Focus on impact. Not on the fun.

 

Want to see Arno van den Hofs full presentation on How (not) to mess up your awareness program? Download the video here.