Use cases
Phishing and cybersecurity awareness: short videos, one reflex each
Awareness that works fits in few words: one reflex per video, repeated often. Here is what to say and in which order, and where the law stands on training staff.
3 min read
This guide is for CISOs, IT managers, L&D teams and small-business owners who need to reach every employee, not only the IT team. It sums up what the texts say, then proposes a series of short videos ready to schedule over a quarter.
What the texts say
In one sentence: no EU law requires every company to run phishing training as such, but GDPR requires appropriate security measures, and NIS2 lists cybersecurity training among the measures expected from regulated entities.
- GDPR, Article 32. Controllers implement appropriate technical and organisational measures to secure personal data. Training staff is one of the organisational measures data protection authorities expect; France’s CNIL lists it among the basic precautions of its security guide.
- NIS2, Articles 20 and 21. Members of the management bodies of essential and important entities must follow training, and entities are encouraged to offer similar training to employees regularly. Risk-management measures include “basic cyber hygiene practices and cybersecurity training”.
- National transposition varies. NIS2 is a directive: each member state transposes it, on its own timetable. Check your national authority for the exact rules that apply to you.
What a good awareness series covers
One video per reflex, 45 seconds to 1 min 30, rather than a one-hour module. Six videos, one every two weeks:
- Spotting a phishing email. An email “from management” asks you to open an invoice. Three signals on screen: urgency, the sender’s address, a link that does not go where it says. The reflex: do not click, report it.
- The fake CEO call. The voice can be imitated by AI. The reflex: hang up, call back on a known number, get approval. This is the example video on this page.
- Passwords and passkeys. One password per service, a password manager, and passkeys where the service offers them.
- Updates. Why the update that has waited for three days matters, in one analogy: a lock everyone knows how to pick.
- Backups. What to back up, where, and how to check that a backup actually restores.
- When in doubt. Who to call, what not to do (switch off, delete), and the line to remember: “reporting is never a mistake”.
Each video ends on one reflex, said and written. That is what viewers should be able to repeat the next day.
How to make it with EducPilot, in three steps
- Upload your sources: your security policy, your reporting procedure, and if useful a public guide from your national agency, added by its web address. The assistant only cites project documents.
- Approve the series plan. The assistant proposes how many videos and the objective of each, then the storyboard. Pick the format: 9:16 for phones, 16:9 for the intranet.
- Correct by annotating, then share. Your CISO pins notes on the frame (“use our reporting address”), from a review link, without an account. Only the annotated scene is rewritten.
What the video does not replace
- Technical measures: email filtering, multi-factor authentication, offline backups.
- Exercises: a simulated phishing campaign measures what the videos got across.
- Your written incident response procedure, which the videos point to.
Frequently asked questions
Is cybersecurity training mandatory?
Not for every company as such. It follows from GDPR’s security obligation (Article 32) and, for entities regulated by NIS2, from the cyber hygiene and training measures of Article 21. For their management bodies, training is explicitly required by Article 20.
How long should an awareness video be?
About a minute, one reflex. Six one-minute videos spread over a quarter beat a one-hour module watched once.
Can the videos be in French for a French subsidiary?
Yes: English, French or Chinese, and one video can switch between languages.
Sources
- Regulation (EU) 2016/679 (GDPR), official text on EUR-Lex, Article 32.
- Directive (EU) 2022/2555 (NIS2), official text on EUR-Lex, Articles 20 and 21(2)(g).
- CNIL, Personal data security guide, 2024 edition (in French), sheet 3 on involving and training users.
Make this video from your documents
Upload your document, approve the plan, correct by annotating. 5 free minutes of video at sign-up.
5 free minutes of video, no card neededSign in with a link sent by email, no passwordHosted in Europe
Read next
- Fake CEO call: 3 reflexes before paying, even when the voice sounds familiar
AI can clone a familiar voice. Hang up, call back, get the transfer approved: 3 reflexes before paying, then 4 steps if the money has already left.
- GDPR awareness training: one video per everyday gesture
GDPR makes staff awareness and training part of the DPO’s tasks (Article 39). The six gestures to get across, with a scene-by-scene video plan.
- AI literacy training under Article 4 of the EU AI Act, as short videos
Since 2 February 2025, the AI Act requires deployers to build staff AI literacy. What Article 4 says after the 2026 amendment, and a video plan.
- Voice-over duration calculator: how long does your script run?
Paste a script or type a word count: the calculator gives the finished video’s length, from measurements on real training videos rather than a generic rate. Free.
- Customer training videos made from your help center
Your help pages already explain your features. Turn them into short videos for customer onboarding and releases, in three languages, plan included.
- Employee onboarding videos made from your welcome handbook
EU law requires safety training on recruitment (Directive 89/391/EEC). How to turn your welcome handbook into five short onboarding videos.
- Rolling out a new internal tool: the video that explains why before how
New software often fails on the why, not the clicks. What EU law says about training on new technology, and four videos timed to your rollout.