7–9 Apr 2026
Jaarbeurs Supernova
Europe/Amsterdam timezone

Security Days Organisational Committee

Onboarding as a security process – How new employees are introduced to information security in a welcoming and comprehensive manner

8 Apr 2026, 11:00
25m
Mission 2 Room (Jaarbeurs Supernova)

Mission 2 Room

Jaarbeurs Supernova

Utrecht, Netherlands
Single Presentation (25 min) Presentations 2 Human Factor

Speaker

Fabio Greiner (Switch)

Description

Many companies rely on training, awareness campaigns and technical controls for human centred security – but one crucial moment is often underestimated: the first day of new employees. This is precisely when the security culture becomes tangible – or not. A well-designed onboarding process not only ensures compliance but also invites new employees to understand security as part of their daily work – and to live it. For new employees, human-centred security does not begin with an introductory training course, but with a clear, inviting and well-thought-out onboarding process.

This presentation will contribute to the GÉANT Security Days by showing how a well-designed onboarding process can make a decisive contribution to human-centred security – beyond campaigns and training courses. Many relevant foundations are laid during the first few days at a new company. Not only the content conveyed, but also the way it is conveyed influences the perceived importance of the topic and has a lasting impact on how employees deal with information security during their induction and their membership within the organisation. The aim of the presentation is to inspire information security professionals to understand processes as a security tool: How do you design an onboarding process that introduces new employees to the company's security policies in a way that is understandable, inviting and comprehensive?

The presentation will address the importance of onboarding for security culture, outline the elements and roles that must be incorporated into an effective onboarding process, and use a concrete example from practice to illustrate how we have revised our onboarding process and what we have learned from it.

To this end, the term ‘security culture’ will be critically reviewed during the presentation and embedded in the context of human-centred security. The typical elements of an onboarding process will be examined in detail and the relevant stakeholders in the organisation will be introduced. Supporting documents and complete documentation of the process are also important components. The example from our organisation covers practical topics: communication surrounding the first day of work was analysed to find out where information on information security can be appropriately placed. Of course, security introductions when handing over work equipment also play an important role, with important tools such as password managers and VPNs being introduced. In addition, it was important to identify relevant contact persons for the new employees, such as their team leaders, and to support those persons with appropriate assistance in answering questions from the new employees. In addition, important stakeholders for the design of the process were identified and cooperation with them will be explained.

Finally, the audience is given specific take-home points that they can implement directly in their own organisations, such as how to plan communication around the start of employment or how to get in contact with relevant stakeholders to start adapting the onboarding process.

The presentation is aimed at information security professionals who are already familiar with human-centred security and are looking for practical approaches to not only communicate security, but also to embed it sustainably in an organisation.

Author

Fabio Greiner (Switch)

Presentation materials