Guide · Technology & SaaS · By the AutoScribble Team · Published 22 September 2026

Creating cybersecurity awareness explainers for non-technical staff

Short answer

Pick one behaviour per video — spotting phishing, using a password manager, approving multi-factor prompts carefully — show a realistic example, give three simple rules and a clear reporting route. Base the advice on recognised guidance such as the NCSC's, keep videos to 60–90 seconds, and have your IT or security team approve the script.

Who this guide is for

IT managers, security teams and HR in organisations without dedicated awareness platforms, or as a supplement to one. It's part of our technology & saas resources.

What you'll need

  • Your IT reporting route
  • Your organisation's password and MFA policy
  • Recent real (anonymised) examples of attacks

Step by step

  1. 1

    One behaviour per video

    ‘Report suspicious emails’ is memorable. ‘Cyber hygiene’ isn't.

  2. 2

    Show a realistic example

    A convincing fake invoice email beats a cartoon hacker in a hoodie.

  3. 3

    Three rules maximum

    People remember three things.

  4. 4

    Make reporting easy and blame-free

    Say exactly how to report and that reporting is always welcome.

  5. 5

    Security team approval

    Check advice matches your policies and current guidance.

Illustrative script: spotting a phishing email

Scene 1 — An email marked ‘URGENT: invoice overdue’.
“This looks like it's from a supplier. It isn't.”

Scene 2 — Magnifying glass over the sender address.
“First, check the sender. A letter out of place is a warning sign.”

Scene 3 — A ticking clock.
“Second, pressure to act now is a classic trick.”

Scene 4 — A link with a hover preview showing a strange address.
“Third, hover before you click. If the link doesn't match, don't.”

Scene 5 — A ‘Report’ button and a thumbs-up.
“Not sure? Report it. We'd always rather check.”

Illustrative example written for this guide.

Copy the AutoScribble prompt

Complete prompt

Make a 90-second portrait whiteboard video teaching non-technical staff how to [behaviour, e.g. spot a phishing email]. Show one realistic example, give three simple warning signs or rules consistent with NCSC guidance, explain how to report it to [IT contact] and say reporting is always welcome. No jargon.
Use this prompt

Common mistakes

  • Fear-based messaging
  • Too many rules
  • No clear reporting route

Review before publishing

  • Advice matches current guidance and your policies
  • Reporting route is correct
  • Tone is blame-free

Questions

Is this a replacement for a security awareness platform?

No. It's a quick way to create clear explainers; platforms add phishing simulations and tracking.

Where can I find authoritative advice?

The UK's National Cyber Security Centre publishes guidance for staff and small organisations.

Make your first 90-second security explainer

Start with phishing. 100 free credits.