Raising security awareness through marketing

Seven steps to build and promote your
information security brand


By Dr Gary Hinson PhD MBA CISSP

June 2013


An effective way to raise awareness of information security is to treat the awareness program as a marketing activity, promoting and selling information security to employees as if it were a commercial product they valued highly enough to buy.



This white paper describes the marketing approach as a sequence of seven simple steps. There is no compulsion to follow these seven steps. Many awareness programs aren’t conceived, planned and conducted this methodically, while others use more conventional or traditional approaches. As to how effective they are, I can’t say … but if you don’t know where you’re headed, and have all the time in the world, any route will do!


