Guide · Technology & SaaS · By the AutoScribble Team · Published 22 September 2026
Creating cybersecurity awareness explainers for non-technical staff
Short answer
Pick one behaviour per video — spotting phishing, using a password manager, approving multi-factor prompts carefully — show a realistic example, give three simple rules and a clear reporting route. Base the advice on recognised guidance such as the NCSC's, keep videos to 60–90 seconds, and have your IT or security team approve the script.
Who this guide is for
IT managers, security teams and HR in organisations without dedicated awareness platforms, or as a supplement to one. It's part of our technology & saas resources.
What you'll need
- Your IT reporting route
- Your organisation's password and MFA policy
- Recent real (anonymised) examples of attacks
Step by step
- 1
One behaviour per video
‘Report suspicious emails’ is memorable. ‘Cyber hygiene’ isn't.
- 2
Show a realistic example
A convincing fake invoice email beats a cartoon hacker in a hoodie.
- 3
Three rules maximum
People remember three things.
- 4
Make reporting easy and blame-free
Say exactly how to report and that reporting is always welcome.
- 5
Security team approval
Check advice matches your policies and current guidance.
Illustrative script: spotting a phishing email
Scene 1 — An email marked ‘URGENT: invoice overdue’. “This looks like it's from a supplier. It isn't.” Scene 2 — Magnifying glass over the sender address. “First, check the sender. A letter out of place is a warning sign.” Scene 3 — A ticking clock. “Second, pressure to act now is a classic trick.” Scene 4 — A link with a hover preview showing a strange address. “Third, hover before you click. If the link doesn't match, don't.” Scene 5 — A ‘Report’ button and a thumbs-up. “Not sure? Report it. We'd always rather check.”
Illustrative example written for this guide.
Copy the AutoScribble prompt
Complete prompt
Make a 90-second portrait whiteboard video teaching non-technical staff how to [behaviour, e.g. spot a phishing email]. Show one realistic example, give three simple warning signs or rules consistent with NCSC guidance, explain how to report it to [IT contact] and say reporting is always welcome. No jargon.
Common mistakes
- Fear-based messaging
- Too many rules
- No clear reporting route
Review before publishing
- Advice matches current guidance and your policies
- Reporting route is correct
- Tone is blame-free
Questions
Is this a replacement for a security awareness platform?
No. It's a quick way to create clear explainers; platforms add phishing simulations and tracking.
Where can I find authoritative advice?
The UK's National Cyber Security Centre publishes guidance for staff and small organisations.
Sources and further reading
