Aetna implemented a successful security awareness program through a systematic approach that engaged employees. They provided both formal and informal training, testing, and reminders about security. This included mandatory exams through an outsourced online portal. Though a small group, Aetna's ISPP was able to administer security exams to over 27,000 employees through a phased and continuously improving approach. Justifying security program expenses requires considering both quantitative metrics and qualitative factors like stakeholder interviews to understand effectiveness.