forumNew topic

need to train employees on cybersecurity, i don't know anything about this, how do i start

NNeslihan A***New member
Job title
Company Owner
Sector
Plastic
Organization type
chain store
Joined
Aug 2026
Message
4
#1

we have a software company with 20 people. management wants to build a security culture but nobody knows how to start. we want to give awareness training to employees.

hiring a specialized training company seems too expensive and time-consuming. are there simpler, cheaper ways?

what should the training cover? just passwords or other topics too?

GGürkan Y***MemberCommunity member
Joined
Jul 2023
Message
8
Most Helpful#2

employee training is the best security investment. you can start too: 1. hold short monthly seminars of 20 mins 2. topics: password security, email scams, physical security 3. gather content from the internet, prepare a PowerPoint 4. last Monday of every month 15-min live session

it should be comprehensive but not too long. people get bored with long trainings.

key topics: passwords, email opening (suspicious links) personal data, home wifi security. doing these for the first 3 months will make big progress.

AAyşe E***Member
Job title
Graphic Designer
Sector
Paper
Organization type
8-person team
Joined
Feb 2023
Message
302
#3

if you do training please keep it short... employees hate long meetings. edit: even one 30-min session a month is enough

NNeslihan T***MemberCommunity member
Joined
Nov 2022
Message
226
#4

sample training schedule: - Jan: Password security - Feb: Email scams - Mar: Physical security - Apr: Home wifi - May: Data storage - Jun: Reporting after an attack

TTülay K***ExpertCommunity member
Joined
May 2023
Message
182
#5

do a survey before training — what do employees lack knowledge in? how much time will they dedicate? then customize the training.

MMehmet Ç***MemberCommunity member
Joined
Apr 2023
Message
277
#6

use videos reading text is boring. there are security videos on youtube, you can use them ready-made

CCem I***MemberCommunity member
Joined
Sep 2025
Message
4
#7

isn't employee participation hard? some act like security isn't their problem.

PPerihan A***New memberCommunity member
Joined
Sep 2026
Message
7
#8

i think the atmosphere changes when you do training! employees feel responsible warn each other. it's great

SSelçukMember
Job title
Sports club
Organization type
boutique agency
Joined
Jun 2024
Message
76
#9

my perspective changed after exepriencing that. if you get three different answers on a topic, the question was asked wrong.

the biggest time-waster for us was not knowing who had the final say but this is my opinion Im not claiming its absolute truth.

FFurkan E***MemberCommunity member
Joined
Apr 2024
Message
191
#10

I went through the same thing.

BBurak Y***MemberCommunity member
Joined
Aug 2025
Message
74
#11

Timely topic.

EEmre O***MemberCommunity member
Joined
Feb 2024
Message
104
#12

There's a common mistake people make when doing this. Hasty decisions become decisions you have to fix six months later.

When you try to change everything at once, nothing settles.

LLeyla Y***Member
Job title
Software developer
Sector
Plastic
Organization type
family business
Joined
Jun 2025
Message
96
#13

let me share my experience. like having backups accessible on the same newtork and with the same identity makes them part of the target.

this is my opinion I'm not claiming it's absolute truth.

HHakan T***MemberCommunity member
Joined
Nov 2025
Message
106
#14

it's rare to find an explanation this clear.. and don't rely on a single measure; go layer by layer.

forgotten test environments are more often the entry point than live systems.

MMert K***Expert
Job title
Data entry clerk
Sector
Leather
Organization type
40-person manufacturing company
Joined
Jun 2023
Message
18
#15

The answer above hits the nail on the head. Forgotten test environments are more often the entry point than live systems.

KKORİDoki team
Job title
Forum moderator
Sector
Cybersecurity and digital
Organization type
Doki
Joined
Jan 2023
Message
2,840
Sentinel#16

Writing in the log: this thread has become a good resource for those who will ask the same question. If you have anything to add, write it; I'm here.

HHavva M***Member
Job title
Customer service representative
Sector
Real estate
Organization type
sole proprietorship
Joined
Jun 2024
Message
18

Doki · Mobile app · 2023

#17

To get into the details: Most incidents start with a leaked password, not a vulnerability.

Mistakes made on the employee awareness training side are usually reversible but expensive.

NNecati K***MemberCommunity member
Joined
Oct 2023
Message
324
#18

Let me summarize the topic, since several different answers were given. If you scold false alarms, nobody will report again.

Any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

BBanu Ş***Member
Job title
Pharmacist
Joined
Mar 2024
Message
81
#19

I think it's hard to be that definitive about employee awareness training. If you get three different answers on a topic, the question was asked wrong.

Don't rely on a single measure; go layer by layer. If I were you, I'd go this route.

ZZehra G***Member
Job title
Operations director
Sector
Catering
Organization type
boutique agency
Joined
Feb 2024
Message
162
#20

i have no experience with employee awareness training, so I'm asking... like your time to detect an issue directly determines its cost.

everything goes well for the first three months; problems arise in the fourth. if you post the result here, it will help others too.

Reply