Brookhuis manufactures measuring instruments for the wood and cleanroom industries. In that high-tech production environment, employee security awareness is essential. But how do you train in a way that actually sticks?
That was the main challenge for Rick Verlaan, Manager Finance and CISO, who is responsible for ISO 27001 certification within the organization. He shares why they chose Guardey and how it saves him and the organization a great deal of time.
Challenge: mandatory training didn’t stick
Brookhuis is ISO 27001 certified. That means there has long been attention to security awareness, in addition to a wide range of other requirements. In fact, cybersecurity awareness is a mandatory component of the Information Security Management System (ISMS).
Still, it proved difficult to train employees in a way that made the information stick. For example, the company used PowerPoint presentations, organized quarterly meetings, and conducted tests to check knowledge retention.
But, “it took a lot of time and people found it disruptive to their daily work,” says Verlaan. So they looked for an alternative that would be less time-consuming and easier to schedule for mechanics and salespeople, who are often on the road in Brookhuis’s case.
Previous efforts were driven by compliance but didn’t deliver the desired results. Moreover, there was little lasting impact. That’s why they started their search for a better-fitting solution.
Solution: weekly microtraining with gamification
It was the combination of weekly training and gamification that immediately appealed to Brookhuis. They compared another provider, but Guardey was preferred due to its competitive structure. Verlaan explains: “What ultimately convinced me was really the competitive aspect with the leaderboard.”
Within the organization, each department competes in a quarterly competition. There are prizes, such as a dinner voucher for the top individual player. There’s also a small reward for the winning team.
Brookhuis consciously includes every department. That means even the development team participates. Developers use a special Guardey content package with advanced security topics. This keeps them challenged, while other employees engage with more general topics.
Easy to implement and little time required
What Verlaan also appreciates is that he no longer has to spend time planning around the schedules of mechanics and salespeople. Participation in Guardey happens almost automatically. Employees participate without needing constant encouragement. He says: “I haven’t had to chase anyone yet. People often complain about not having enough time, but five minutes is always doable.”
Result: engaged employees and satisfied auditors
Verlaan and Brookhuis train employees to improve their security awareness, which is key to make their information security management system work.
Guardey has already been showcased twice during audits. Neither external auditor had seen Guardey before, but both were immediately enthusiastic. “Both auditors were unfamiliar with it, but thought it was a great method.” That positive feedback strengthens Brookhuis’s belief that this is the best way to train employees sustainably.
Verlaan also appreciates how easily he can generate reports on both participation and training content. These reports show strong employee engagement. “The greatest added value of Guardey is that people stay engaged. And that’s a requirement for your ISMS to work.”
Don’t let hackers outsmart you
Make sure your employees are prepared to recognize security threats with Guardey. Start your 14-day free trial today.