Build better security decisions into everyday behaviour.
Universities depend on people making good security decisions every day.
Staff, students, researchers, privileged users, senior leaders and external partners all interact with valuable information and critical digital services — often within deliberately open and collaborative environments.
Effective cyber security awareness is therefore not simply an annual training exercise.
It is about helping people recognise risk, understand their responsibilities, make better-informed decisions and know when and how to raise concerns.
Expede helps universities develop security awareness programmes that turn knowledge into sustainable behaviour and contribute to a stronger institutional security culture.
Awareness is not a compliance exercise.
Move beyond completion rates.
Annual training may demonstrate that a requirement has been met.
It does not necessarily demonstrate that people know what to do when faced with a real situation.
A mature awareness programme should reflect the risks people actually encounter, recognise that different roles require different knowledge and continually reinforce the behaviours the institution needs.
The objective is not to make people afraid of making mistakes.
It is to create an environment in which people:
understand why security matters;
recognise common threats and risky situations;
know what is expected of them;
make informed decisions;
report concerns quickly;
learn from incidents and simulations; and
feel able to ask for help when something does not look right.
The Expede Approach
Build the programme around institutional risk.
There is no single awareness programme that works for every university.
Expede helps institutions understand their current position and design an approach appropriate to their people, risks, technologies and existing security capability.
Understand
Review existing awareness activity, policy requirements, incidents, phishing trends, user populations and areas of particular exposure.
Target
Identify the audiences and behaviours that matter most rather than delivering identical content to everybody.
Engage
Use appropriate combinations of training, communications, campaigns, simulations, workshops and targeted interventions to reinforce secure behaviour.
Measure
Track meaningful indicators of engagement and behaviour, not simply whether a training module was completed.
Improve
Use results, incidents, emerging threats and institutional change to continually adapt the programme.
Role-Based Awareness
The right message for the right audience.
Different communities encounter different risks.
A researcher handling commercially sensitive intellectual property requires different guidance from a student, a finance team processing payments or an administrator with privileged system access.
Expede can help develop targeted awareness for groups including:
Staff & Students
Practical everyday security covering phishing, authentication, information handling, devices, collaboration and incident reporting.
Senior Leaders & Governors
Digital risk, accountability, material incidents, decision-making and the role leadership behaviour plays in establishing security culture.
Researchers & Research Teams
Protection of research data, intellectual property, external collaboration, sensitive projects and international partnerships.
Privileged & Technical Users
Additional responsibilities associated with elevated access, administration, development, configuration and critical technology.
High-Risk Business Functions
Targeted support for teams such as finance, HR, procurement and executive support that are frequently exposed to fraud, impersonation and sensitive information.
New Starters & Role Changes
Embedding appropriate security expectations from the beginning and reinforcing them when responsibilities or access change.
Phishing & Social Engineering Resilience
Use simulation to learn — not to blame.
Phishing simulations can provide valuable insight when they are used as part of a broader programme rather than as a mechanism for catching people out.
We can help institutions design simulation programmes that:
reflect realistic institutional threats;
vary according to audience and risk;
reinforce learning immediately;
encourage reporting;
identify areas requiring additional support;
measure trends over time; and
avoid creating a punitive security culture.
The most useful measure is not simply who clicked.
It is whether people increasingly recognise suspicious activity, report it quickly and make better decisions when confronted with uncertainty.
Measure What Changes
Turn awareness data into assurance.
Security awareness should produce evidence that can inform wider institutional risk and assurance.
Depending on the programme, measures can include:
training participation and completion;
role-based training coverage;
phishing and simulation trends;
reporting rates;
time to report suspicious activity;
repeat-risk patterns;
engagement with campaigns and communications;
incident trends;
targeted intervention outcomes; and
staff confidence and understanding.
Viewed over time, this provides a much richer picture than a single annual completion percentage.
It also helps security teams identify where additional communication, training or control improvement may be required.
Flexible Delivery
Use what works for the institution.
Expede is not tied to a single awareness platform or technology provider.
We can work with an institution's existing tooling and content, help evaluate alternative platforms, or coordinate specialist partners where additional capability is required.
Support can range from an independent review of an existing programme through to the design and coordination of a broader awareness and culture programme.
This can include:
awareness strategy and programme design;
platform and content review;
role-based learning;
phishing and social-engineering simulations;
leadership briefings;
researcher-focused awareness;
communications and campaign planning;
security-culture measurement;
metrics and reporting; and
continual improvement.
Part of Wider Organisational Resilience
Security culture does not exist in isolation.
Awareness is most effective when people have clear responsibilities, policies make sense, reporting mechanisms work and leaders demonstrate the behaviours expected of others.
Where appropriate, Expede can use the Unified Digital Resilience Framework (UDRF) to assess security culture and awareness alongside wider organisational capabilities such as governance, accountability, information asset ownership, incident response and control effectiveness.
This creates a clearer view of whether awareness activity is genuinely contributing to institutional resilience.
Build a culture where secure behaviour becomes normal behaviour.
The objective is not to turn every member of the university into a cyber security specialist.
It is to give people the knowledge, confidence and support to make appropriate decisions in the situations they encounter.