🚨  NIS2 is now in effect. Security awareness is now legally required in the EU.

Check compliance
Log in
Back to cases overview

From 50% to 86% participation: how Gemeente Nunspeet made security training a habit

The starting point: a knight that wasn’t going to win the battle

When Elske van der Horst became CISO at Gemeente Nunspeet, she inherited a security awareness program that had already been running for years: one question every week, delivered by an animated character called “the Knight,” alongside several e-learning modules.

On paper, the program looked fine. In practice, participation had dropped to around 50% and wouldn’t move beyond that, no matter what Elske tried. Conversations with employees quickly made it clear that the approach no longer matched the organization, at a time when new requirements were actually calling for greater engagement with information security and privacy.

“I knew straight away: I’m not going to win this battle with the Knight.”

So, together with the Privacy Officer at the time, Elske started looking for an alternative. They explored the market with a clear set of requirements. No training that relied heavily on video, because employees working in an open-plan office were unlikely to turn the sound on. And they wanted broad content that covered not only information security and privacy, but topics such as the AI Act and the Open Government Act as well.

More important than any individual requirement, though, was one thing: it had to fit the organization itself.

When Elske came across Guardey and heard that another municipality was already using it successfully, Nunspeet decided to run a pilot with ambassadors from different parts of the organization. Everyone who took part was immediately enthusiastic. For Elske, that was the moment she knew they’d found the right fit.

Why this approach clicked

One of the first things that stood out was how relatable everything felt. Instead of distant stock photography, the illustrations show people in situations employees recognize from their own working day: checking a phone, sitting behind a screen or dealing with a familiar workplace scenario. Elske also appreciated the diversity of the characters, with different genders and skin tones represented, making it easier for people to recognize themselves in what they see.

But what really made the approach take off was the game element.

Gemeente Nunspeet is a naturally competitive organization, and it didn’t take long for that to show. Team against team, younger colleagues against older ones, employees comparing scores and challenging each other to keep up. Elske no longer had to chase people herself because colleagues were already doing it for each other.

And employees didn’t just complete the questions and move on. They started talking about them.

Some came to Elske because they didn’t understand why they’d answered something incorrectly. Others openly admitted they’d looked up an answer or asked a colleague for help. To Elske, that was exactly the point. People were actively thinking about the content instead of simply ticking off another training requirement.

 

"We're a competitive organization, and it showed right away. Team against team, young against old, everyone comparing scores. I don't have to chase anyone anymore, colleagues do that for each other. And they don't just answer the question and move on, they actually talk about it."
Elske van der Horst CISO at Gemeente Nunspeet

Adoption doesn’t happen by itself

Gemeente Nunspeet went live with Guardey in March 2026, but Elske knew that simply introducing a new platform wouldn’t automatically lead to higher participation.

Together with the CISO, Data Protection Officer, Privacy Officer, system administrator and even the municipality’s Open Government Act coordinator, she carefully planned the rollout. Guardey’s communication templates provided a starting point, but the team rewrote everything in the municipality’s own tone of voice and created at least two communication moments per week in the run-up to launch.

Management was involved from the beginning as well. Every team manager received a short presentation and was explicitly told they had a role to play in getting their teams involved. The management team was asked to support the launch through internal communication and, just as importantly, to participate themselves.

And then there was the prize.

Gemeente Nunspeet put a team barbecue on the line for the team with the most points. Not a token prize, but something people genuinely wanted to win. Food is serious business at Nunspeet, so suddenly everyone wanted that barbecue. Colleagues actively reminded each other to complete their challenges because they wanted their team to come out on top.

The approach has since evolved. Instead of rewarding the best-performing team every time, the highest-scoring person within each team can now win a prize, creating some healthy competition within teams too.

Halfway through the first season, Nunspeet added an extra nudge: an “in-between” encouragement prize, Tony’s Chocolonely bars stamped with “Winnaar Aanmoedigingsprijs Guardey.” According to Elske, a small prize like that partway through the season works well to keep everyone training.

The big prize helped get things moving, but after the first season, Elske noticed something more important: employees needed less and less encouragement. It was becoming a habit. Tuesday simply started to mean: “It’s Tuesday, time for Guardey.”

The result: from 50% to 86% participation

Before Guardey, participation at Gemeente Nunspeet had stalled at around 50%. Today, it sits at 86%.

Elske is very happy with that figure, particularly considering there will always be employees who are absent for longer periods or external staff who only work for the municipality a few hours per week.

The phishing simulations show a clear change too. During the first simulation, 40% of employees still clicked. After one season with Guardey, that had dropped to 20%, a significant improvement in just three months.

But the biggest change isn’t necessarily visible in the numbers.

In the past, employees rarely came to Elske with questions about suspicious emails or security incidents. There was confusion about the difference between spam, phishing, security incidents and data breaches, and employees weren’t actively reporting things.

Now, colleagues call her or stop by her desk to ask whether an email is legitimate. They know they can report suspicious messages in Outlook, and they talk to each other about what they’ve learned through Guardey. Sometimes, they even discuss how they’re applying that knowledge at home.

That extra moment of awareness makes all the difference to Elske. People check before they act, and she’s genuinely happy when they do. Information security has shifted from something employees were expected to complete to something that is simply part of everyday work.

Security awareness from the top down

That shift isn’t limited to employees.

The Director of Operations participates every week, and the municipality’s new executive board has now joined Guardey as well. The importance of that became especially clear during a phishing campaign, when Gemeente Nunspeet noticed that people without a Guardey account performed noticeably worse than colleagues who had already been training.

Elske used that insight internally to reinforce a simple message: everyone needs to participate, including the executive board and directors. Any one of us can be the weak link, and the more you practice, the less likely you are to fall for an attack.

That involvement from management has helped turn security awareness into a responsibility shared across the organization, rather than something owned solely by the CISO.

 

"Before we started with Guardey, we ran a phishing test and forty percent of our employees clicked the link. After one season of weekly Guardey challenges, we ran the same kind of test again and only twenty percent clicked. That's a drop of half, in three months. That's when I knew this approach actually works, not just on paper."
Elske van der Horst CISO at Gemeente Nunspeet

Building on what works

Gemeente Nunspeet is now using insights from Guardey to make its broader security awareness approach even more targeted.

For phishing simulations, for example, the security team can use specific templates for different groups and analyze the results to see where additional attention is needed. Teams that struggle with a particular topic can then receive more targeted training.

Elske also continues to combine Guardey’s weekly challenges with team sessions and targeted training for specific roles. The goal isn’t simply to complete training, but to keep knowledge up to date and continue practicing situations employees may actually encounter in their work.

Her advice to other organizations starting a security awareness program comes directly from what worked at Gemeente Nunspeet: don’t treat implementation as an afterthought. Choose an incentive people genuinely want to compete for, and involve management from the beginning so awareness doesn’t become “the CISO’s project.”

And use ambassadors from across the organization. They can share their own experiences with colleagues, which, according to Elske, often works better than hearing the message from the CISO alone.

When security becomes a conversation at the coffee machine

Perhaps the clearest sign of progress isn’t found in a dashboard at all. It’s at the coffee machine.

Employees compare scores, talk about questions they got wrong and remind each other to complete their weekly challenge. Security awareness has become something colleagues discuss among themselves rather than something Elske constantly has to push.

These days, the conversation at the coffee machine is more likely to be about whether you’ve completed your Guardey challenge yet, or what you thought of that one tricky question.

And that’s exactly where Elske wants security awareness to be: part of the conversation, part of the working day and something the entire organization takes responsibility for together.

"The biggest change isn't in a dashboard, it's at my desk. Before Guardey, nobody ever asked me whether an email looked legitimate. People didn't even know the difference between spam and a real security incident. Now colleagues stop by or call to check before they click, and they talk to each other about what they've learned, sometimes even about how it helps them at home too."
Elske van der Horst CISO at Gemeente Nunspeet

Curious what 86% participation could look like at your organization? Book a demo and we’ll walk you through it, or start a free trial and see for yourself.

READY TO GET STARTED?

Join 500+ businesses already protecting their teams with Guardey

Start your free 14-day trial
14 days free · No credit card · Full access · Setup in 5 minutes
Or schedule a personalised demo