This document proposes a framework for progressively engaging employees in cybersecurity through training. It argues that current generic, web-based training does not reliably change behaviors and recommends tailored, skills-based training aligned with employee roles. The framework involves: 1) Ensuring security behaviors don't hamper productivity; 2) Communicating correct behaviors through tailored training that builds skills relevant to roles; 3) Measuring training effectiveness and refining it over time. The goal is for security to become a natural part of employee engagement rather than just awareness.