Start with the decision a person can influence
A finance approver, service-desk analyst, developer and executive assistant encounter different requests and have different authority. Map the consequential decisions each role makes: changing bank details, resetting an account, sharing a document, accepting a software dependency or approving an urgent exception. Identify the existing control and the evidence that correct use would leave.
Define a learning objective as an observable action. For example, a participant should verify a bank-detail change through an independently established contact route before approval. Recognising that a message looks suspicious is useful, but it does not demonstrate that the person can complete the required verification under realistic time pressure.
Make the safe action practical
Check whether staff can find the verification procedure, reach the right person and report a concern without unreasonable delay. If a service-desk employee is expected to validate identity, the approved method must work when the caller is travelling or has lost a device. An unusable process can produce workarounds even among well-trained staff.
Include the channels and situations the role actually uses: email, voice, collaboration platforms and requests passed through an assistant or supplier. For family offices, clarify responsibilities across principals, assistants, finance staff and external advisers. Familiarity with a voice, writing style or urgent personal detail should not replace the agreed control for a consequential action.
Design a controlled and proportionate exercise
Agree the scenario, participants, permitted data, timing and stop conditions. Use fictitious records, safe destinations and test accounts. A learning exercise should not collect real passwords, trigger live payments or expose confidential family or customer information. Coordinate the design with the organisation’s responsible security, HR and privacy teams as appropriate.
Balance challenge with a fair opportunity to use the process. Avoid scenarios that depend on obscure clues unrelated to the participant’s role. Decide what the assessor observes and how results will be used before the exercise starts. Minimise personal data, restrict access and prefer aggregated improvement reporting over public rankings or embarrassment.

Measure the decision and the reporting path
Track whether the participant used the independent verification route, withheld the consequential action when evidence was insufficient and reported the concern through the intended channel. Record the time to an actionable report and whether it contained useful context. Attendance and quiz scores can support administration, but they do not replace these behavioural observations.
State the number of opportunities observed and the scenario conditions. A click rate alone may be distorted by automated link checks and does not establish whether a harmful action followed. Separate a person’s knowledge gap from a failed tool, unclear authority or conflicting instruction. Different causes require different corrective actions.
Debrief the process and repeat the relevant decision
Explain the scenario, the intended control and what happened without disclosing unnecessary individual details. Give participants a short, accessible procedure they can use in their daily work. Let them practise the correct action and ask where the process breaks down. Capture those obstacles as operational findings with an owner.
Retest comparable decisions after training and process improvements. Keep scope and measurement sufficiently consistent to interpret change, while avoiding memorised answers. Refresh the programme when roles, systems, suppliers or verification methods change. Include onboarding and targeted refreshers for privileged or financially sensitive responsibilities.
Give management evidence of useful improvement
Report the roles assessed, decisions exercised, observed control use, reporting quality, unresolved process issues and follow-up results. Distinguish small-sample observations from organisation-wide conclusions. A useful programme can reveal that a payment workflow or account-recovery process needs redesign as well as showing where learning improved.
TRUST-IT can develop role-specific workshops, safe simulations and follow-up assessments for enterprises, family offices and professional teams. Deliverables can include a role-to-risk map, exercise pack, verification and reporting aids, an improvement register and a measurement plan. The purpose is to help people complete safer decisions within a workable operating process.
Further reading
Put the guidance to work
Role-based education, authorised phishing simulations, and practical training in cybersecurity and responsible AI use.
Awareness & training