Online Safety and Privacy
|
Min Read
How Awareness Practitioners Are Crushing It: Takeaways from Convene: Boston's Share & Brag
We asked real cybersecurity professionals to share what is working for them – learn free tips from the Convene: Boston 2026 Share & Brag session!

What happens when you put a room full of training and awareness professionals together and ask them to share what’s working? It's not the start of a cybersecurity joke. It was the premise of Share & Brag, a popular session at Convene: Boston on August 13. Hosted again by Jenn deBerge, the director of the Fusion Center at Mastercard and the Vice Chair of the Board of Directors at the National Cybersecurity Alliance, this session is always a highlight of every Convene conference.
In Boston, the prompt was simple: "What is one thing your organization is doing in your security awareness or human risk program that you think others should be doing too — and why is it working?"
After hearing the prompt, a loud convening commenced – exactly what we like to see at Convene. Attendees discussed their ideas at their tables, then selected people to share their favorites with the larger group. The result was a wide-ranging collection of practical ideas from phishing simulations and security champions to community outreach and executive exercises.
But several themes began emerging across the different approaches people shared and bragged about.
Make cybersecurity a shared responsibility
Several attendees described ways they are bringing cybersecurity outside their department. One financial services organization uses tabletop exercises with teams across the business. The goal isn't just to test the organization's response to an incident. It also helps other departments better understand what the cybersecurity team does and why its work matters. Another organization has a program that pairs engineers outside cybersecurity with cyber experts so they can learn from each other. The program creates relationships between teams that might otherwise rarely interact.
A large technology organization takes the idea even further with a global Security Champions community. Thousands of employees participate, including through hackathons where participants have developed proof-of-concept security tools.
A great takeaway was that awareness works better when employees aren't simply the audience for security messages, but also participants.
Building communities to combat the “firehose”
One university cybersecurity program created an Ambassadors and Champions community for school districts across its state. The program grew out of a problem many cybersecurity professionals will recognize: people responsible for security can feel isolated and overwhelmed by the sheer volume of threats, tools, and information coming at them. Bringing interested professionals together gave them a place to share resources and learn from one another. It also expanded the program's reach beyond IT. Classroom teachers have even started reaching out for cybersecurity resources, too.
Sometimes the best awareness resource is a community, not another piece of content.
Flip the script on security awareness
Traditional awareness programs often focus heavily on what employees are doing wrong. Several Share & Brag participants are experimenting with the opposite approach. One organization created a program recognizing employees who consistently demonstrate strong security behaviors, such as using MFA and avoiding risky activity on their devices. Rather than focusing on people who fail simulations, the program identifies employees who consistently do the right things. The presenter encouraged other practitioners to “flip the script” and look for ways to celebrate positive behavior.
Another organization created a phishing challenge where employees develop their own simulated phishing emails. The most convincing examples became part of the organization's phishing simulations during Cybersecurity Awareness Month.
Make training more relevant to the person
Several practitioners, especially those with a worldwide staff, discussed tailoring their programs rather than giving everyone the same training. One global organization uses real malicious emails to inspire its phishing simulations. It also has people in different regions who help develop culturally relevant examples and guidance. This is because what works in one region may not work in another.
Another organization has created a more intensive training program for employees who repeatedly struggle with phishing simulations. Rather than giving everyone more training, the organization provides additional support to the people who need it.
Tell better stories
One technology organization has created fictional audio stories based on real cyberattacks, a similar approach to the NCA's Cybersecurity Awareness Month campaign for 2026. The idea addresses a common problem: Organizations know incidents happen, but legal, compliance, and privacy concerns can make it difficult to openly discuss what went wrong.
Fictional stories offer a way to teach those lessons without putting a real incident or employee under a microscope. The approach also recognizes something important about awareness: stories can be easier to remember than instructions.
Make it personal, even for executives
One presenter offered a blunt reminder: If someone thinks they can't be hacked, they're wrong. And that includes executives.
Instead of simply telling leaders about the risks, the organization creates exercises designed to give executives firsthand experience of how easily they could be compromised. Another organization has changed its phishing exercises so employees don't just identify suspicious messages. They're asked to explain what they would do next, including who they would report the message to.
That extra step can reveal gaps that a traditional phishing simulation might miss. Someone may know an email is suspicious but still not know how to respond.
Go into your community
Awareness doesn't have to stop at employees. One financial services organization recently launched an initiative to bring cybersecurity education to vulnerable communities and members of the public who need additional resources.
The program builds partnerships inside and outside the organization and sends cybersecurity subject matter experts to community events. Materials are tailored to each audience's needs. The goal isn't just to make employees safer at work. It's to give people skills they can use wherever they go online.
A Major Takeaway of Convene: Boston – Give people a reason to participate
The Share & Brag session produced dozens of ideas, but the most striking takeaway was how many practitioners are moving beyond traditional compliance-driven awareness.
They are building communities. Celebrating positive behavior. Bringing security into other departments. Tailoring programs to different cultures and audiences. Giving employees opportunities to create content. Using stories to make threats memorable. And finding ways to make it personal.
If you want more cybersecurity tips and tricks, sign up for our email newsletter! And if you want to participate in the next Share & Brag, check out our next Convene conference!

