SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsMandatory security awareness training is widely deployed, yet frequently criticized for low engagement and limited impact on real-world behavior. This case study shares how one global organization redesigned its mandatory program to address a specific challenge the awareness community continues to struggle with; how to make mandatory training meaningful, role-relevant, and behavior-focused—without adding time or burden. We will walk through how a traditional annual course was replaced with a modular, role-aware learning experience that adapts to employee context, tenure, and risk exposure, including non-office and operational roles. Rather than adding “games” for engagement alone, we applied lightweight gamification techniques—scenario-based decisions, challenges, and immediate feedback—to reinforce secure behaviors employees face in their day-to-day work. The session focuses on what worked well, where assumptions failed, and what we had to course-correct. Lessons include balancing credibility with play, avoiding over-gamification, managing scalability across a global workforce, and resisting reliance on completion metrics as a success signal. Finally, we will share how the program is evolving: moving toward behavior-based measurement, deeper role differentiation, and tighter integration with phishing simulations and coaching. Attendees will leave with practical design principles they can apply to modernize mandatory training in their own organizations.


Nadine Rose Smith is a Product Manager for Secure Behaviour Engagement at Nestlé. She leads the evolution of Nestlé’s Security Awareness & Behaviour programme, shifting it from compliance‑centric training to personalised, risk‑based learning that supports a strong security culture.
Read more about Nadine Rose-Smith