Security awareness training
Ongoing education that teaches staff to recognize and report attacks aimed at them.
The annual video achieves very little. What changes behavior is short, frequent, relevant training combined with simulated phishing, so people meet the tactics in a safe context before they meet them for real.
The metric worth watching is the report rate, not the click rate. An organization where people quickly flag suspicious messages gives its defenders early warning; one that only punishes clicks teaches people to stay quiet.
Where this comes up
Security awareness training sits inside our cybersecurity and threats work. If you are trying to work out what this means for your own environment rather than in the abstract, that is the page worth reading next, and a short call will get you a straight answer faster than either.