Skip to content
English
  • There are no suggestions because the search field is empty.

Expert Session Recording - Nemlig, Kompasbank and Moxso talk about how to re-engage your employees

"In security, we have a tendency to act like doctors and tell people what's good for them. But ask any doctor how many people actually listen. It's the same in our field. (...) If you don't get people's buy-in, it doesn't matter how good you are, how many resources you get, or how much money you have in your budget."

On September 23rd, 2026, we hosted a webinar on re-engaging your employees.

Please find the recording, a summary and key takeaways below:

Video Recording:

 

Summary:

  • The session brought together two speakers from very different organizations. Ekaterina Christensen (Head of Technology Governance, Kompasbank) comes from a small, heavily regulated bank, and Ali Aziz (Head of Security at Nemlig) from a large, complex business.

  • Speakers shared what first made awareness a priority. For Kompasbank it was regulatory pressure (DORA, audits). For Nemlig it was the need for a full culture shift, because the security team was previously invisible and disconnected from employees.

  • Both speakers agreed that technical controls only go so far when it comes to changing behavior.

    • Ali described a knowledge gap where employees didn't understand why security activities mattered, and noted that people naturally try to avoid controls placed on them.

    • Ekaterina pointed out that there's no one-size-fits-all approach, since tech teams often assume they already know it all while busy teams struggle to find time. She stressed building a culture where people aren't afraid to admit mistakes, so incidents can be reported, traced to a root cause, and used to protect others.

  • The panel covered practical tactics that worked for them:

    • Tech-stack phishing: Ali set up Moxso simulations to mimic the tools Nemlig actually uses (e.g. Salesforce), the same way a real attacker would research a company before targeting it.
    • Targeted credential harvesting: Ekaterina focused simulations on higher-exposure groups, such as executive management handling sensitive information and sales teams who are often on the go and less focused.
    • Manager reports: Instead of chasing individuals, Nemlig sends Moxso's manager reports to team leads, who are responsible for their employees completing training and avoiding risky behavior.
    • Drop-in sessions: Kompasbank ran short, bookable sessions with a security specialist over a few weeks, helping employees set up password managers and showing how to use them at home with their families too.
    • Hands-on "attacks": Ali plugs a device into unlocked computers that changes the password and locks them, and takes unattended access cards. Employees then have to come to his desk, which opens a short, natural conversation about security.
    • Crisis exercises: Ali recommended running company-wide crisis management exercises so employees experience firsthand what happens when things go wrong.

Key takeaways:

  • Security has to go from "nice to have" to "must have." Both organizations moved expectations into formal policies, recurring controls, and onboarding, so secure behavior became the default rather than a request.
  • Show, don't tell. Abstract threats don't change behavior. Real, relevant examples from your own industry or country, simulated attacks, and company-wide crisis exercises make the risk tangible.
  • Relevance drives engagement. Recycled simulations and videos cause fatigue. Tailoring phishing to the tools employees use every day, and targeting higher-exposure groups like executives and sales, catches even the "I know all this" crowd.
  • Route accountability through managers. Manager reports put ownership of completion and risky behavior with team leads, which is more effective and scalable than chasing individuals.
  • Make it personal and approachable. Framing tools like password managers as useful at home too, keeping an open door, and treating mistakes as learning moments... all these steps encourage employees to report issues rather than hide them.

Thank you to all those who attended! We hope to see you at our next one!