Security Awareness Is Not a Training Problem

Security Awareness Is Not a Training Problem

Most organisations have a security awareness programme. Employees complete annual training, click through phishing simulations, sign acceptable use policies. Completion rates get reported upward. The box gets ticked.

And then the incidents happen anyway.

The failure is rarely that employees don’t know the rules. The failure is that security hasn’t become part of how people actually make decisions. There’s a real difference between knowing what the policy says and asking the right question before clicking a link at 4pm on a Friday.

The CISO has a translation problem

Security teams communicate in a specific language. Risk scores, compliance requirements, CVE severity ratings, phishing statistics, policy frameworks. That language makes sense inside a security team. It lands badly everywhere else.

A marketing manager thinks about campaigns and clients. A finance director thinks about cash flow and reporting deadlines. An HR partner thinks about people and process. None of them move through their working day thinking about threat vectors and attack surfaces. When security messaging arrives in that register, it gets filed as something that belongs to IT, not to them.

The CISO’s job, in part, is to translate. Not to dumb things down, but to convert security concepts into the terms each part of the business already uses to think about risk.

The difference between “never share credentials” and “if someone gets into your account, they may not need to break into anything else” is not a small one. The second version describes a consequence rather than a rule. A non-technical person can reason about consequences.

The risk is not the same for everyone

Generic awareness training treats the organisation as a single audience. The result is messaging that fits nobody in particular.

Risk profiles vary significantly by role. A finance team member faces business email compromise, invoice fraud, and payment manipulation. The scenario where an attacker intercepts a supplier payment by impersonating a known contact is concrete and worth explaining in terms of how that specific process works in that company.

HR teams hold employee data, payroll access, and identity records, which makes them a target for data theft and salary redirect fraud. Sales teams have CRM access and customer relationships that can be used for impersonation. Developers sit on source code, API keys, and production access, often with credentials scattered across repositories and local machines.

Executives face a different category of threat. CEO fraud and deepfake impersonation have moved from theoretical to documented. In early 2024, an employee at Arup in Hong Kong transferred 25 million dollars after joining a video call where every other participant, including the CFO, was a deepfake. The call looked real, sounded real, and involved people the employee recognised. No malware was involved. The attack worked because it was convincing enough to push past doubt.

Awareness training has to speak to each of these groups differently, because the threats they’re most likely to face and the decisions they’re most likely to need to make are not the same.

People are not the weakest link

The security industry has spent years repeating the phrase “people are the weakest link.” It captures something real but points toward the wrong solutions.

When an employee clicks on a well-crafted AI-generated phishing email that bypasses filters, passes visual inspection, and arrives in a thread that looks like a real conversation, blaming that employee misses the point. The failure is in the system. The gap sits in the email security setup, the authentication controls, the privilege management, the incident response process, and the culture around reporting.

Good security design starts from the assumption that people will occasionally make mistakes, and builds systems that limit the damage when they do. That means MFA, restricted access, detection capabilities, and fast response, not a search for someone to blame after the fact.

The framing matters. “People are the weakest link” tends to produce programmes designed to catch employees failing rather than environments designed to make secure behaviour the obvious choice.

What AI has changed about awareness

Security awareness training has taught employees to spot phishing emails by looking for spelling errors, odd sender addresses, and clumsy formatting. That approach is now much less reliable than it used to be.

AI-generated phishing is grammatically correct, tonally matched, and personalised. It can reference real projects, real colleagues, and real context pulled from public information. The signals employees were trained to look for are no longer dependable.

The shift this requires is a change in what awareness is actually teaching. The question is no longer primarily “does this email look suspicious?” The more useful question is “is this message asking me to do something that bypasses an established process?”

Urgency that overrides normal approval steps. Requests to act outside usual channels. Instructions to keep something confidential before checking independently. These patterns appear in social engineering regardless of how polished the message looks. Teaching people to spot process violations rather than visual warning signs will hold up better as attack techniques keep improving.

Security champions over security dependence

A CISO cannot be the security conscience of five thousand employees. A centralised function that only gets involved when something has already gone wrong doesn’t scale, and it creates friction. When security feels like a bottleneck rather than a resource, people work around it, which is exactly the behaviour that creates risk.

A more practical model is developing security champions inside business units. Not cybersecurity specialists, but people within finance, HR, legal, sales, operations, and engineering who know enough to ask the right questions, spot something worth escalating, and act as a point of contact between their team and the security function.

The aim is to put security thinking where decisions actually get made, rather than keeping it in a separate function that gets called in after the fact.

Completion is not awareness

The metric most organisations report is training completion. Ninety-two percent of employees finished the annual module. That number says almost nothing about whether security behaviour has actually changed.

Better questions: how many employees report suspicious emails, and how quickly? How many know who to contact when something feels wrong? How long does it typically take from an employee noticing something odd to that observation reaching someone who can act on it? Does behaviour shift after training, or does it revert within a few weeks?

Completion measures whether people sat through training. Behaviour measures whether it did anything. Most awareness programmes are currently operating in the gap between the two.

The goal

Security awareness programmes often end up measuring the wrong thing. Success becomes the absence of visible failures rather than the presence of a culture where people actually think about security.

The problem with that definition is that it includes everything swept under the rug, resolved quietly, or never reported because employees don’t know the threshold for reporting or worry they’ll be blamed for raising something.

A culture where people flag close calls, ask security questions early rather than after, and find secure behaviour the easier option is built through communication, leadership, and how the organisation is structured, not just through technical controls.

The goal of security awareness is not to make every employee a security expert. It is to make secure behaviour the easiest behaviour to choose. Whether an organisation has actually built that environment, or only documented that it intended to, is what determines the outcome.

Sources: Verizon, Data Breach Investigations Report 2026; IBM, Cost of a Data Breach Report 2025; SANS Institute, Security Awareness Report 2025; Proofpoint, State of the Phish 2025; CyberArk, 2025 Identity Security Landscape

Get your pass

The most exclusive Cyber Security EVENTS in the world.

Exclusive C-level cybersecurity gatherings across Europe. Limited seats, maximum impact.

Session reserved
05:00
Your registration session is active. Complete your application within the reserved time.
Next IT Security · East Central
Main Conference Ticket
€495
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. September 30, Belgrade.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
Workshops — Sold Separately
Workshop 1 Chapter 1 · Compliance & Regulation
From Regulation to Reality: Making NIS2 & DORA Work in Practice
A working session for security leaders who need to translate regulatory requirements into operational plans. Participants work through actual compliance gaps, build a self-assessment framework, and leave with a prioritised action list — without dedicated compliance teams or enterprise-level budgets.
Time
09:00 – 11:00
Format
Masterclass + working groups
Duration
2 hours
Capacity
Limited seats
Workshop 2 Chapter 2 · AI & Emerging Threats
Shadow AI: How to Find It, Govern It, and Not Kill Innovation Doing It
A practical masterclass for security leaders dealing with AI tools that were never approved, deployed without oversight, and are already inside the environment. Participants map their own shadow AI exposure and build a proportionate governance framework.
Time
11:15 – 13:15
Format
Masterclass + case analysis
Duration
2 hours
Capacity
Limited seats
Workshop 3 Chapter 3 · Vendor Dependency & Sovereignty
Managing Vendor Risk Without Rebuilding Your Stack
A strategic working session on third-party risk, technology dependency, and realistic options for East Central organisations. Participants conduct a structured dependency audit, evaluate viable European alternatives, and leave with a vendor risk strategy that is operationally grounded.
Time
13:15 – 15:15
Format
Masterclass + structured audit
Duration
2 hours
Capacity
Limited seats
Workshop 4 Chapter 4 · Cybercrime in a Borderless Threat Landscape
Cross-Border Cybercrime: What Private Sector Security Leaders Need to Know
A practitioner-led masterclass bridging private sector incident response and the realities of cross-jurisdictional law enforcement. Participants learn how cybercrime investigations unfold across borders and how to build an incident posture that works with — not against — public sector constraints.
Time
15:30 – 17:30
Format
Masterclass + Q&A
Duration
2 hours
Capacity
Limited seats
By submitting this form, you acknowledge that you have read and agree to our Privacy Policy .
Next IT Security · Nordics
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. October 22, Stockholm.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
By submitting this form, you acknowledge that you have read and agree to our Privacy Policy .
Next IT Security · Benelux
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. November 12, Amsterdam.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
By submitting this form, you acknowledge that you have read and agree to our Privacy Policy .
Next IT Security · DACH
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. November 26, Frankfurt.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
By submitting this form, you acknowledge that you have read and agree to our Privacy Policy .
Next IT Security · Nordics
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. March 11, Stockholm.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
By submitting this form, you acknowledge that you have read and agree to our Privacy Policy .
Next IT Security · Benelux
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. April 15, Amsterdam.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials