Security Awareness Is Not a Training Problem

Security Awareness Is Not a Training Problem

Most organisations have a security awareness programme. Employees complete annual training, click through phishing simulations, sign acceptable use policies. Completion rates get reported upward. The box gets ticked.

And then the incidents happen anyway.

The failure is rarely that employees don’t know the rules. The failure is that security hasn’t become part of how people actually make decisions. There’s a real difference between knowing what the policy says and asking the right question before clicking a link at 4pm on a Friday.

The CISO has a translation problem

Security teams communicate in a specific language. Risk scores, compliance requirements, CVE severity ratings, phishing statistics, policy frameworks. That language makes sense inside a security team. It lands badly everywhere else.

A marketing manager thinks about campaigns and clients. A finance director thinks about cash flow and reporting deadlines. An HR partner thinks about people and process. None of them move through their working day thinking about threat vectors and attack surfaces. When security messaging arrives in that register, it gets filed as something that belongs to IT, not to them.

The CISO’s job, in part, is to translate. Not to dumb things down, but to convert security concepts into the terms each part of the business already uses to think about risk.

The difference between “never share credentials” and “if someone gets into your account, they may not need to break into anything else” is not a small one. The second version describes a consequence rather than a rule. A non-technical person can reason about consequences.

The risk is not the same for everyone

Generic awareness training treats the organisation as a single audience. The result is messaging that fits nobody in particular.

Risk profiles vary significantly by role. A finance team member faces business email compromise, invoice fraud, and payment manipulation. The scenario where an attacker intercepts a supplier payment by impersonating a known contact is concrete and worth explaining in terms of how that specific process works in that company.

HR teams hold employee data, payroll access, and identity records, which makes them a target for data theft and salary redirect fraud. Sales teams have CRM access and customer relationships that can be used for impersonation. Developers sit on source code, API keys, and production access, often with credentials scattered across repositories and local machines.

Executives face a different category of threat. CEO fraud and deepfake impersonation have moved from theoretical to documented. In early 2024, an employee at Arup in Hong Kong transferred 25 million dollars after joining a video call where every other participant, including the CFO, was a deepfake. The call looked real, sounded real, and involved people the employee recognised. No malware was involved. The attack worked because it was convincing enough to push past doubt.

Awareness training has to speak to each of these groups differently, because the threats they’re most likely to face and the decisions they’re most likely to need to make are not the same.

People are not the weakest link

The security industry has spent years repeating the phrase “people are the weakest link.” It captures something real but points toward the wrong solutions.

When an employee clicks on a well-crafted AI-generated phishing email that bypasses filters, passes visual inspection, and arrives in a thread that looks like a real conversation, blaming that employee misses the point. The failure is in the system. The gap sits in the email security setup, the authentication controls, the privilege management, the incident response process, and the culture around reporting.

Good security design starts from the assumption that people will occasionally make mistakes, and builds systems that limit the damage when they do. That means MFA, restricted access, detection capabilities, and fast response, not a search for someone to blame after the fact.

The framing matters. “People are the weakest link” tends to produce programmes designed to catch employees failing rather than environments designed to make secure behaviour the obvious choice.

What AI has changed about awareness

Security awareness training has taught employees to spot phishing emails by looking for spelling errors, odd sender addresses, and clumsy formatting. That approach is now much less reliable than it used to be.

AI-generated phishing is grammatically correct, tonally matched, and personalised. It can reference real projects, real colleagues, and real context pulled from public information. The signals employees were trained to look for are no longer dependable.

The shift this requires is a change in what awareness is actually teaching. The question is no longer primarily “does this email look suspicious?” The more useful question is “is this message asking me to do something that bypasses an established process?”

Urgency that overrides normal approval steps. Requests to act outside usual channels. Instructions to keep something confidential before checking independently. These patterns appear in social engineering regardless of how polished the message looks. Teaching people to spot process violations rather than visual warning signs will hold up better as attack techniques keep improving.

Security champions over security dependence

A CISO cannot be the security conscience of five thousand employees. A centralised function that only gets involved when something has already gone wrong doesn’t scale, and it creates friction. When security feels like a bottleneck rather than a resource, people work around it, which is exactly the behaviour that creates risk.

A more practical model is developing security champions inside business units. Not cybersecurity specialists, but people within finance, HR, legal, sales, operations, and engineering who know enough to ask the right questions, spot something worth escalating, and act as a point of contact between their team and the security function.

The aim is to put security thinking where decisions actually get made, rather than keeping it in a separate function that gets called in after the fact.

Completion is not awareness

The metric most organisations report is training completion. Ninety-two percent of employees finished the annual module. That number says almost nothing about whether security behaviour has actually changed.

Better questions: how many employees report suspicious emails, and how quickly? How many know who to contact when something feels wrong? How long does it typically take from an employee noticing something odd to that observation reaching someone who can act on it? Does behaviour shift after training, or does it revert within a few weeks?

Completion measures whether people sat through training. Behaviour measures whether it did anything. Most awareness programmes are currently operating in the gap between the two.

The goal

Security awareness programmes often end up measuring the wrong thing. Success becomes the absence of visible failures rather than the presence of a culture where people actually think about security.

The problem with that definition is that it includes everything swept under the rug, resolved quietly, or never reported because employees don’t know the threshold for reporting or worry they’ll be blamed for raising something.

A culture where people flag close calls, ask security questions early rather than after, and find secure behaviour the easier option is built through communication, leadership, and how the organisation is structured, not just through technical controls.

The goal of security awareness is not to make every employee a security expert. It is to make secure behaviour the easiest behaviour to choose. Whether an organisation has actually built that environment, or only documented that it intended to, is what determines the outcome.

Sources: Verizon, Data Breach Investigations Report 2026; IBM, Cost of a Data Breach Report 2025; SANS Institute, Security Awareness Report 2025; Proofpoint, State of the Phish 2025; CyberArk, 2025 Identity Security Landscape

APPLY FOR ACCESS

Next IT Security

Apply for access to Europe’s leading conference for c-suite cybersecurity executives.

Session reserved
05:00
Your registration session is active. Complete your application within the reserved time.
Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Attendance by invitation only
Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Next IT Security · Nordics
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. October 22, Stockholm.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Next IT Security · Benelux
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. November 12, Amsterdam.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Next IT Security · DACH
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. November 26, Frankfurt.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Next IT Security · Nordics
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. March 11, Stockholm.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Next IT Security · Benelux
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. April 15, Amsterdam.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials