Group Purchasing
Group Purchasing

Treat People Like Adults: How Trusting Employees Transformed Security Training at Postman

Treat People Like Adults: How Trusting Employees Transformed Security Training at Postman (PDF, 1.46MB)Last updated: 27 Aug, 2026

At Postman, we recognized that traditional security awareness training was failing. It didn’t make the company safer but it did make our employees cranky. So we decided to take a step back and ask ourselves: How do we stay compliant while respecting employees' time? How do we deliver training that meets people where they are? How do we know it’s working? Our approach flipped training on its head. Instead of forcing everyone through the same mandatory course, we introduced a test-out option: prove you know the material, and you're done. For everyone else, we replaced passive video-and-quiz formats with one-minute micro-modules followed by hands-on experiential assessments.  The results were immediate. Employees started vociferously and publicly praising security training — some even asked to take it again. Our security engineers called the positive feedback "genuinely wild." We also ran our first "Phish Fry" during Cybersecurity Awareness Month: a reporting-focused competition that rewarded employees for spotting and flagging threats rather than punishing those who clicked. This talk covers three actionable shifts any security awareness team can make: Offer a test-out. We'll share exactly how we structured ours, the completion data that justified it, and the message it sends to your workforce about respecting their expertise. Replace quizzes with experiential assessments. We'll walk through the difference between recognition-based and application-based testing and why it matters for actual behavior change. Reframe phishing simulations as celebrations, not gotchas. We'll break down the Phish Fry format — the contest mechanics, how we positioned reporting over clicking, and what we'd change next time. You'll leave with a concrete playbook for making these changes in your own program.

SANS Security Awareness Summit 2026