Pedagogy, far more than a simple learning method, turns out to be a powerful lever in change management. Through different methods, it makes it easier to acquire the reflexes essential to memory, and so ensures that the change achieved actually lasts.
Redesigning pedagogy to create new learner experiences
The human being remains the essential link in any transformation; understanding their resistances, needs and motivations is paramount. That's where pedagogy takes on its full meaning. I deliberately use the word "pedagogy" rather than "training." Training is a means, whereas pedagogy is truly a methodology. You can find the codes and markers of an effective pedagogical logic in serious games, poster campaigns, videos… and not only in "training" in the strict sense of the term.
So where does training fit in?
The evolution of ways of working, learners' expectations, and the value placed on skills all call for us to rethink our pedagogical approaches. After the revolution of hybrid training, which opened a new horizon for acquiring skills, we're going even further to give training meaning. We now talk about Learnal Branding. This concept treats an organisation's entire training offer as a brand in its own right. It gives meaning to the learner experience. Whatever the subject, you find a shared promise and a single storytelling thread. This approach, well established in some training organisations, can absolutely be applied within a company by rethinking its approach. A company's ability to take this turn, to transform its internal training offer, will be a major asset.
With a better learner experience, we can foster the anchoring of knowledge and give rise to solid, lasting skills.
Designing a quality pedagogical approach
When building your training path, you'll need a three-part approach:
- The learning objectives: the knowledge, techniques and reflexes to be acquired.
- The format: the timing, the modalities used…
- The pedagogical logic: the optimal method for the learner to assimilate the knowledge.
Putting it into practice
Say you want to strengthen your users' ability to detect malicious emails (phishing). You might be tempted to hand them a list of 5 or 6 crucial points to keep in mind, hoping they'll learn and memorise them as if by magic. But reality is quite different. Even if they've taken in the information, you need to go further to root a reflex and drive a behaviour change.
So we return to our simple three-step approach:
- Learning objective(s): this is where your pedagogical thinking begins. Too often, learning objectives aren't dug into deeply enough, and the training fails to meet them. For a single topic, the objectives can be multiple, and each will need a different approach. If we stop at "I want my users to be able to detect a phishing email," we lump too many learner needs into one. Many training materials are just a string of rules: "Beware of phishing," "Think before you click"… Stopping at that kind of message shares information but doesn't give the learner the keys to build skills. I recommend starting from your main need and breaking it down into sub-skills to acquire: "Develop online vigilance," "Recognise the characteristics of a phishing email," "Systematically report emails deemed suspicious"…
- The format: to choose the best format, the advisory dimension comes into play: your company's current training context, the resources available (LMS…), the company culture (in-person, digital, remote or blended learning). To address the objectives listed above, my proposal would be a digital modality, in a short format (2 min), to give learning a rhythm, integrated into a broader training path on cybersecurity.
- The pedagogical logic: this is where it all plays out. If we want a reflex to be acquired, the learner will have to practise and repeat the right actions. If we ask them to develop their vigilance, we have to play the hackers' game and put them in real conditions. Finally, if we expect an action from them (report and flag), we have to give it meaning and give them an incentive to act. We start with a flipped-learning approach, applying the expected reflexes.
In flipped learning, we let the learner practise by making application easier. That's what serves the learning. Knowledge comes in a second stage.
- Gamify and mix the modalities: we display a phishing email on which the learner must spot the suspicious elements. Each "red flag" is then explained and debriefed at the end of the activity, to reinforce the learning phase. This debrief can be done via a podcast, to reach the learner through several entry points.
- Anchor the knowledge: we offer a downloadable cheat sheet to use as a reminder. To create habits and reflexes, you have to practise, train, repeat… Additional phishing exercises (phishing campaigns) can be run over the year to keep the training going. That said, a phishing exercise is not an end in itself: if you don't integrate it into a learning logic, it will be of no use in shifting behaviours.
Launching large-scale phishing exercises will have an impact if, and only if, corrective support actions are put in place, through targeted pedagogical approaches based on the results and user profiles.
- Motivate action: to increase reporting, we value users and give meaning to the action. They are the eyes and ears of cybersecurity on the ground. You can also offer a reward system: each month, pick a few users who made qualified reports and send them a small gift. It's always appreciated and contributes greatly to maintaining good reflexes!
Mastering these levers and adapting them to each context is an indispensable asset in change management, whatever the subject. So think "pedagogy," for a stronger learning culture that's closer to learners' needs.