Built In A Day: What Happened When We Stopped Planning and Started Building
# Cybersecurity Awareness Month
# Programme
# Workshop
A room full of practitioners, six topics, one day at the Secure Culture Hub, and the blueprints they built for Cybersecurity Awareness Month
Ant Davis
Most Cybersecurity Awareness Month planning sounds the same.
A meeting. A deck. A list of topics. A rough plan that someone will flesh out closer to October. And somewhere between that conversation and the first week of the month, the momentum dies and you end up running the same thing you ran last year.
I have been in those meetings. I have run those meetings. And I wanted to try something different.
On 10 June 2026, we brought a group of security awareness and human risk practitioners together for a full day at the Secure Culture Hub. The brief was simple: no more brainstorming. We build.
What the room looked like
What struck me straight away was the range of voices in the room.
Different sectors. Different organisation sizes. Different levels of resource, seniority, and budget. Some people had mature programmes with years of data behind them. Others were earlier in the journey, still figuring out what good looks like for their context.
That mix was the whole point. When you get a room like that working on the same problem, you stop hearing the polished version of what people do and start hearing the real version. What is actually hard. What keeps not working. What they wish they had more time to do.
The morning session made that clear immediately.
What isn't landing
We started with a deceptively simple question. Think about your organisation right now. Not your programme, not your strategy. Your people. What is the one behaviour or risk that still isn't landing, no matter what you try?
The responses were candid. Not reporting suspicious emails came up more than anything else. People click things, people see things, and they do not tell anyone. That theme ran through almost every conversation across the day. Password behaviour, AI usage without oversight, locking laptops, shadow IT, the "it's not my issue" mindset. Fifteen distinct behaviours, surfaced in three minutes of honest reflection.
The group also tackled a question that does not get asked often enough: how would you actually know if CAM was a success? The answers split into quantitative and qualitative camps, but the consistent principle underneath all of them was the same. Decide what behaviour you are trying to change before you start. Get a baseline. Track against it. Engagement metrics are useful as a proxy but they are not the same as behaviour change.
The afternoon: no more talking
After lunch we introduced the framework that would shape the rest of the day.
Four questions, applied to any topic. What is the human problem? What is the core message, in one sentence? What is the delivery plan? And what is the hook, written as actual copy rather than a description of copy?
Six groups. Six topics chosen by the room from a vote earlier in the day. Cybersecurity at Home topped the poll with 11 votes, Physical Security came second with 8. Each group had an afternoon to build a complete blueprint.
What came out of that session was genuinely impressive.
A deepfake immersive event with vishing stations, a bingo mechanic, and a live talk delivered as a deepfake of the speaker. A four-week "from screen to front door" home security campaign built around a mascot called Homer. A password hygiene campaign anchored by the header Pa55w0rd_ Hygi3n3*, written deliberately in the style of substitutions people think are secure but are not. An AI safe use campaign with the subject line "Curiosity killed the network." A physical security strapline reworked from the TfL slogan: "See it. Steal it. Sink it."
None of this came from a template. It came from practitioners who know their organisations.
Why I think this document is genuinely useful
We turned everything the room built into a report. Built In A Day: Six Cybersecurity Awareness Month Blueprints from the Secure Culture Hub.
Every blueprint covers the same four things: the human problem, the core message, the delivery plan, and the hook. They are designed to be lifted and adapted, not followed to the letter. Take the core message and make it yours. Take the hook and rewrite it in your organisation's voice. Take the delivery plan and pressure-test it against your channels and your audience.
If your topic is not one of the six covered, the framework still applies. Define the human problem. Write one core message. Plan the delivery. Write the actual words. That process works for any topic, any audience, any organisation.
The report also captures something I think is worth sitting with. Not reporting was the hardest problem in the room. Every group touched it. None of them have fully solved it. That is not a failure of the day. It is an honest reflection of where the profession is right now, and it is the kind of thing you only hear when you get the right people in a room and ask them the right questions.
What comes next
I cannot wait to run the next one.
The energy in the room on the day was something I want to bottle. Different organisations, different challenges, same commitment to making security awareness actually work. That is what the Secure Culture Hub is for.
You can read the report down below. If you attended the day, thank you. What you built is already in the hands of practitioners who are going to use it this October.
And if you were not there this time, come to the next one. Let us know where you want us to be!