Issue029 1 September 2026

The Cheapest Thing That Works

Amy Stokes-Waters 3 min read

The debrief is the most important part of what we do, and I’d argue the most interesting part too.

Of course, the game gets all the attention. It’s fun, it’s loud, people get properly competitive about it, and they learn a serious amount while it’s happening. We’ve spend years making it that good and no, I’m not gonna be modest about it.

But playing the game and changing what you’d actually do under pressure are two different jobs, and the second one happens afterwards. Once the adrenaline has gone, and everyone’s sat down, and we start dissecting what they all just did.

That’s when we get the stories. The near misses. The actual incidents. The “something like this happened to me, actually”. And that bit is BRILLIANT. Because it shows that people feel safe to talk about the times they’ve been fooled. The times when they’ve fucked up. The times when they, whether accidental or not, got it wrong. Those are the moments we learn from. When we’re able to speak about them.

SANS have recently published their annual security awareness report, and this year they asked 4,500 people in the field an open question: “What completely failed? And what did you learn from it?” One respondent came back with an answer that I found really interesting.

One approach that failed badly was a fear-based phishing awareness campaign built around ‘gotcha’ simulations and public benchmarking of failure rates… A lower click rate is meaningless if employees simultaneously lose trust, hide mistakes, or disengage.

A campaign that worked great. The click rate was low. Right up until you realise what you’ve done to the psychological safety of the people in the building. And I mean we know this, right? We’ve all sat in a company where mistakes only get you into a meeting. And we know what we’ve done in those businesses. We’ve shut the fuck up. Said nothing. And a workforce that says nothing is not the position a business wants to be in.

Another respondent in the survey talked about a programme they implemented which went in the exact opposite direction. They stopped flagging failures and started publicly naming people who demonstrated strong security behaviours, which they called Caught You Doing It Right. Their report rate went up by nearly 40% in three months, and people started coming to the security team BEFORE something went wrong rather than after.

And in a team where a few select security champions openly shared their own near misses, phishing reporting increased by 70%. Calling it “stronger than incentives, stronger than gamification”.

Yes, those two numbers are individual programmes rather than widely reported statistics, but I can completely see why they were so effective. They’re not complicated interventions. They have absolutely jack shit to do with learning anything. Nobody taught anybody a new fact. The companies just changed their minds about what a normal person does here. Someone respected made it normal to say “I nearly fell for that”. And so it became normal.

And that’s culture. Doing the thing that culture does. And it all happened without a single module. It also happened without a single purchase order. No new integration. No renewal dates. No Q4 target attached to it. Recognition costs nothing. No procurement. No vendor. And you don’t need permission from anyone. You could start it this afternoon if you wanted.

It’s the same principle under everything we build at The Cyber Escape Room Co. Put people somewhere they’re allowed to be wrong in front of each other, and behaviour moves. Take away the fear of being wrong and you get told things. As one of the respondents in the SANS survey put it: people follow people, not policies.

So, go and find whoever reported something last month. And say their name out loud. Publicly. In a room with other people in it. And then do it again next month.

That's it for this week. Reply and tell me what you think.

Amy

Amy Stokes-Waters · Founder, The Cyber Escape Room Co.