🚨  NIS2 is now in effect. Security awareness is now legally required in the EU.

Check compliance
Start your free trial
Back to cases overview

“Guardey is as close to a silver bullet for security awareness as you can get”

IGL-Technologies is a Finnish operator in electric vehicle charging and parking. The company designs and manufactures its own hardware, supplies components to other manufacturers, and manages the infrastructure behind the scenes. With over 300,000 customers and ISO 27001 compliance, security is critical.

We spoke with Mika Liukkonen, Information Security Officer at IGL, who is also responsible for the company’s infrastructure. As the team expanded and security awareness became harder to scale, Mika started looking for a sustainable training solution.

The challenge: From one-man show to unsustainable

For a long time, Mika handled all security awareness training himself. “I ran these quarterly training sessions. It was always a problem to get enough people to attend at the same time. It was quite a hassle, to put it lightly.”

At the time, IGL had about 30 to 35 employees. “I split them into three groups and hosted roughly one-hour sessions where I covered important, generic topics,” Mika says. But even then, some people couldn’t attend. “Sometimes people couldn’t attend one or even two sessions. That meant it could be half a year before they received any training again.”

To stay top of mind, Mika used Slack to send reminders. But it wasn’t enough. “We also posted reminders in Slack to keep people engaged, but I still believe there was always a knowledge gap. Security awareness would go down significantly between trainings.”

“I ran these quarterly training sessions. It was always a problem to get enough people to attend at the same time. It was quite a hassle, to put it lightly.”
Mika Liukkonen Information Security Officer

As IGL started growing, the situation became even more difficult to manage. “We’re closer to 50 employees now. I would need five groups, and I’m just one person doing this.”

Mika knew something had to change. “Right after training sessions, people would talk about security in the hallways, but it always faded away after a couple of weeks. That was a big selling point. Having a series of small tasks instead of one big chunk.”

The solution: Relevant training that runs itself

Mika found what he was looking for in Guardey. Guardey is a gamified security awareness platform that helps employees build secure habits through short, weekly training challenges. “There’s no way I could provide the same quality and quantity of training on my own. And keeping people interested long term is much easier with Guardey’s gamified platform.”

He launched the program with a short demo during a monthly all-hands meeting. “I showed them the platform, explained the themes, the competition, and the rewards. They received it quite well.”

There’s no way I could provide the same quality and quantity of training on my own. And keeping people interested long term is much easier with Guardey’s gamified platform.”
Mika Liukkonen Information Security Officer

The development team became more engaged once Guardey introduced a specialized content program for developers. “The OWASP training for developers wasn’t available when we first started with Guardey,” Mika explains. “But when it was released, we immediately rolled it out to our development team. It was a really good idea. The developers appreciated it much more because the topics were closer to their level and more relevant to their daily work.”

Mika set up team competitions with prizes. “I split our teams based on departments, with about five people per group. For example, customer support was in its own team. We gave prizes during our summer party: champagne and little trophies for the top three teams.”

The result: Engagement, ownership and impact

Guardey lets teams compete in challenges, track their progress on leaderboards, and earn rewards. This turns awareness training into a shared goal. That competitive edge didn’t go unnoticed internally. “People were talking about the competition and even pushing their teammates to do better. That’s exactly what I hoped for.”

“It’s easy to show proof that we’re actually doing the training during ISO 27001 audits.Also, the auditors loved the gamification aspect. They thought it really helped with creating awareness.”
Mika Liukkonen Information Security Officer

Participation has remained consistently high, and the data helps Mika stay proactive. “I see participation rates between 70 and 85 percent each month. That’s decent. Sometimes I need to remind people, but overall it’s going well.” He also uses topic-level insights to guide follow-ups. “I can easily see which topics are harder—for example, GDPR—and I use that to create small follow-ups. I might mention something in Slack or during our monthly meetings.”

At the same time, Guardey isn’t meant to replace everything. “We still bring in experts for topic-specific training, like GDPR or DevSecOps, for the relevant staff. For some roles, Guardey on its own, complemented with a Slack reminder or a monthly meeting, is already good enough.”

When it comes to audits, Guardey makes life easier. “It’s easy to show proof that we’re actually doing the training during ISO 27001 audits. The auditors loved the gamification aspect. They thought it really helped with awareness.”

For Mika, the value of Guardey’s security awareness program is clear. “Guardey is as close to a silver bullet for security awareness as you can get. It keeps security top of mind and does exactly what it needs to do.”

Don’t let hackers outsmart you

Make sure your employees are prepared to recognize security threats with Guardey. Start your 14-day free trial today.

READY TO GET STARTED?

Join 500+ businesses already protecting their teams with Guardey

Start your free 14-day trial
14 days free · No credit card · Full access · Setup in 5 minutes
Or schedule a personalised demo