Most organisations have a security awareness programme. Employees complete annual training, click through phishing simulations, sign acceptable use policies. Completion rates get reported upward. The box gets ticked.
And then the incidents happen anyway.
The failure is rarely that employees don’t know the rules. The failure is that security hasn’t become part of how people actually make decisions. There’s a real difference between knowing what the policy says and asking the right question before clicking a link at 4pm on a Friday.
The CISO has a translation problem
Security teams communicate in a specific language. Risk scores, compliance requirements, CVE severity ratings, phishing statistics, policy frameworks. That language makes sense inside a security team. It lands badly everywhere else.
A marketing manager thinks about campaigns and clients. A finance director thinks about cash flow and reporting deadlines. An HR partner thinks about people and process. None of them move through their working day thinking about threat vectors and attack surfaces. When security messaging arrives in that register, it gets filed as something that belongs to IT, not to them.
The CISO’s job, in part, is to translate. Not to dumb things down, but to convert security concepts into the terms each part of the business already uses to think about risk.
The difference between “never share credentials” and “if someone gets into your account, they may not need to break into anything else” is not a small one. The second version describes a consequence rather than a rule. A non-technical person can reason about consequences.
The risk is not the same for everyone
Generic awareness training treats the organisation as a single audience. The result is messaging that fits nobody in particular.
Risk profiles vary significantly by role. A finance team member faces business email compromise, invoice fraud, and payment manipulation. The scenario where an attacker intercepts a supplier payment by impersonating a known contact is concrete and worth explaining in terms of how that specific process works in that company.
HR teams hold employee data, payroll access, and identity records, which makes them a target for data theft and salary redirect fraud. Sales teams have CRM access and customer relationships that can be used for impersonation. Developers sit on source code, API keys, and production access, often with credentials scattered across repositories and local machines.
Executives face a different category of threat. CEO fraud and deepfake impersonation have moved from theoretical to documented. In early 2024, an employee at Arup in Hong Kong transferred 25 million dollars after joining a video call where every other participant, including the CFO, was a deepfake. The call looked real, sounded real, and involved people the employee recognised. No malware was involved. The attack worked because it was convincing enough to push past doubt.
Awareness training has to speak to each of these groups differently, because the threats they’re most likely to face and the decisions they’re most likely to need to make are not the same.
People are not the weakest link
The security industry has spent years repeating the phrase “people are the weakest link.” It captures something real but points toward the wrong solutions.
When an employee clicks on a well-crafted AI-generated phishing email that bypasses filters, passes visual inspection, and arrives in a thread that looks like a real conversation, blaming that employee misses the point. The failure is in the system. The gap sits in the email security setup, the authentication controls, the privilege management, the incident response process, and the culture around reporting.
Good security design starts from the assumption that people will occasionally make mistakes, and builds systems that limit the damage when they do. That means MFA, restricted access, detection capabilities, and fast response, not a search for someone to blame after the fact.
The framing matters. “People are the weakest link” tends to produce programmes designed to catch employees failing rather than environments designed to make secure behaviour the obvious choice.
What AI has changed about awareness
Security awareness training has taught employees to spot phishing emails by looking for spelling errors, odd sender addresses, and clumsy formatting. That approach is now much less reliable than it used to be.
AI-generated phishing is grammatically correct, tonally matched, and personalised. It can reference real projects, real colleagues, and real context pulled from public information. The signals employees were trained to look for are no longer dependable.
The shift this requires is a change in what awareness is actually teaching. The question is no longer primarily “does this email look suspicious?” The more useful question is “is this message asking me to do something that bypasses an established process?”
Urgency that overrides normal approval steps. Requests to act outside usual channels. Instructions to keep something confidential before checking independently. These patterns appear in social engineering regardless of how polished the message looks. Teaching people to spot process violations rather than visual warning signs will hold up better as attack techniques keep improving.
Security champions over security dependence
A CISO cannot be the security conscience of five thousand employees. A centralised function that only gets involved when something has already gone wrong doesn’t scale, and it creates friction. When security feels like a bottleneck rather than a resource, people work around it, which is exactly the behaviour that creates risk.
A more practical model is developing security champions inside business units. Not cybersecurity specialists, but people within finance, HR, legal, sales, operations, and engineering who know enough to ask the right questions, spot something worth escalating, and act as a point of contact between their team and the security function.
The aim is to put security thinking where decisions actually get made, rather than keeping it in a separate function that gets called in after the fact.
Completion is not awareness
The metric most organisations report is training completion. Ninety-two percent of employees finished the annual module. That number says almost nothing about whether security behaviour has actually changed.
Better questions: how many employees report suspicious emails, and how quickly? How many know who to contact when something feels wrong? How long does it typically take from an employee noticing something odd to that observation reaching someone who can act on it? Does behaviour shift after training, or does it revert within a few weeks?
Completion measures whether people sat through training. Behaviour measures whether it did anything. Most awareness programmes are currently operating in the gap between the two.
The goal
Security awareness programmes often end up measuring the wrong thing. Success becomes the absence of visible failures rather than the presence of a culture where people actually think about security.
The problem with that definition is that it includes everything swept under the rug, resolved quietly, or never reported because employees don’t know the threshold for reporting or worry they’ll be blamed for raising something.
A culture where people flag close calls, ask security questions early rather than after, and find secure behaviour the easier option is built through communication, leadership, and how the organisation is structured, not just through technical controls.
The goal of security awareness is not to make every employee a security expert. It is to make secure behaviour the easiest behaviour to choose. Whether an organisation has actually built that environment, or only documented that it intended to, is what determines the outcome.
Sources: Verizon, Data Breach Investigations Report 2026; IBM, Cost of a Data Breach Report 2025; SANS Institute, Security Awareness Report 2025; Proofpoint, State of the Phish 2025; CyberArk, 2025 Identity Security Landscape