CYBERPLANZ
  • Home
  • Services
    • 1. Cyber Governance Audit
    • ​2. Cyber Resilience Program
    • 3. Executive Cyber Advisory
    • 4. Staff Engagement & Culture Program
  • Products
  • Resources
    • The Cyberplanz Board Governance Framework >
      • The Boardroom Guide to Cyber & AI Governance
      • Board Cyber & AI Governance Self-Assessment
  • About Us
  • Contact Us
  • Blogs
Picture
Picture
“Plans are of little importance, but planning is essential.”
― Winston Churchill

1 July Post

7/1/2026

0 Comments

 

Why Security Awareness Training Often Fails (And What Boards and Leaders Should Do Instead in the Age of AI)

Picture
Every year, organisations invest millions of dollars in cybersecurity awareness training.
Employees complete online modules.
They answer multiple-choice questions.
A certificate is issued.
The compliance box is ticked.
Yet organisations continue to fall victim to phishing attacks, business email compromise, ransomware, insider threats, and increasingly sophisticated AI-enabled cybercrime.
If awareness training is so widespread, why do so many organisations continue to experience preventable cyber incidents?
The answer is surprisingly simple.
Most organisations measure participation.
Very few measure behavioural change.
Cybersecurity awareness is not a training programme.
It is an organisational culture.
Compliance Does Not Equal Resilience
For many organisations, cybersecurity awareness has become a compliance exercise.
Staff are required to complete annual training because regulations, insurers, or auditors expect it.
Completion rates become the primary measure of success.
"We achieved 98% completion."
That sounds impressive.
But it tells us very little.
It does not tell us whether employees:
  • Recognise sophisticated phishing emails.
  • Know how to safely use AI tools.
  • Feel confident reporting suspicious activity.
  • Understand how their everyday decisions affect organisational risk.
  • Would know what to do during a cyber incident.
Compliance measures attendance.
Resilience measures capability.
The two are not the same.
The Threat Landscape Has Changed Faster Than Training
Traditional awareness programmes were designed for a different era.
Today, employees face threats that barely existed a few years ago, including:
  • AI-generated phishing emails that are almost impossible to distinguish from legitimate communications.
  • Deepfake voice and video scams targeting executives and finance teams.
  • Shadow AI, where employees unknowingly expose confidential information to public AI platforms.
  • AI-assisted social engineering attacks.
  • Supply chain compromises affecting trusted vendors.
Meanwhile, many organisations are still delivering the same annual training they have used for years.
Cybercriminals innovate daily.
Training often changes annually.
That imbalance creates risk.
People Are Not the Weakest Link
One of the most damaging phrases in cybersecurity is:
"People are the weakest link."
People are not the weakest link.
They are the most targeted.
When employees receive thousands of emails, constant Teams or Slack messages, phone calls, and AI-generated content every week, expecting perfect decision-making every time is unrealistic.
Instead of blaming employees, organisations should ask:
  • Have we given them the knowledge they need?
  • Have we created simple processes to follow?
  • Do they feel safe reporting mistakes?
  • Have we designed systems that support secure behaviours?
The goal should be to build confidence, not fear.
Boards Set the Tone
Cybersecurity culture starts long before an employee receives awareness training.
It starts in the boardroom.
If boards treat cybersecurity as an annual compliance exercise, management often does the same.
If boards instead ask:
  • How are we improving cyber behaviours?
  • How are we measuring our security culture?
  • Are employees confident in identifying cyber threats?
  • How are we preparing staff for the responsible use of AI?
...the entire organisation begins to think differently.
Culture follows leadership.
Awareness Should Be Continuous
Learning is most effective when it is ongoing.
The same applies to cybersecurity.
Rather than relying on a single annual training session, organisations should create continuous engagement throughout the year.
Examples include:
  • Five-minute monthly security updates.
  • AI awareness briefings.
  • Department discussions.
  • Short video messages from executives.
  • Phishing simulations followed by coaching.
  • Security tips aligned with current events.
  • Quarterly cyber resilience workshops.
  • Incident reviews that focus on learning rather than blame.
Cyber awareness should become part of everyday work—not an annual interruption.
AI Literacy Is the New Security Awareness
Artificial Intelligence has fundamentally changed the way people work.
Employees increasingly use AI to:
  • Draft emails.
  • Summarise reports.
  • Analyse data.
  • Generate marketing content.
  • Write code.
  • Improve productivity.
Yet many organisations have provided little or no guidance on its safe use.
Without governance, employees may:
  • Upload confidential information into public AI tools.
  • Trust inaccurate AI-generated outputs.
  • Accidentally expose intellectual property.
  • Create regulatory compliance issues.
  • Introduce bias into business decisions.
Security awareness programmes must now include AI literacy.
Employees need to understand not only how to use AI effectively, but also how to use it responsibly.
Make Cybersecurity Relevant
Generic awareness programmes often fail because employees struggle to relate them to their daily work.
The risks faced by a finance manager differ from those faced by a software developer, HR advisor, receptionist, or board member.
Training should reflect those differences.
Examples include:
Finance Teams
Business email compromise, invoice fraud, executive impersonation.
Human Resources
Sensitive personal information, recruitment scams, AI-generated CV fraud.
Marketing
Brand impersonation, AI-generated content, social media attacks.
Executives
Whaling attacks, deepfake communications, strategic decision-making.
Board Members
Cyber governance, AI governance, organisational resilience, regulatory oversight.
People engage when learning feels relevant.
Build a Culture Where Reporting Is Encouraged
One of the strongest indicators of cyber maturity is how quickly employees report concerns.
Unfortunately, many organisations unintentionally discourage reporting.
Employees worry about:
  • Looking incompetent.
  • Being blamed.
  • Disciplinary action.
  • Embarrassment.
This delays incident response.
Instead, organisations should celebrate reporting.
An employee who reports a suspicious email—even if it turns out to be harmless—has demonstrated the exact behaviour leaders should encourage.
Reporting should be recognised as a positive contribution to organisational resilience.
Measure Behaviour, Not Attendance
If awareness programmes are to improve, organisations must rethink what they measure.
Useful indicators include:
  • Phishing reporting rates.
  • Time taken to report incidents.
  • AI usage awareness.
  • Employee confidence surveys.
  • Security culture assessments.
  • Participation in discussions.
  • Lessons learned from near misses.
  • Trends in security-related behaviours.
These metrics provide a far more accurate picture of organisational resilience than training completion rates alone.
Leadership Must Participate
Nothing undermines an awareness programme faster than leaders who fail to participate.
When executives ignore security policies or directors bypass governance processes, employees notice.
Leadership should:
  • Attend awareness sessions.
  • Follow the same security practices expected of staff.
  • Talk openly about cyber and AI risks.
  • Share lessons from incidents.
  • Celebrate good security behaviours.
Culture is built through visible leadership.
Security Awareness Is Really Organisational Awareness
The most resilient organisations understand that cybersecurity is not simply about technology.
It is about decision-making.
Communication.
Trust.
Leadership.
Behaviour.
And increasingly, it is about how people use artificial intelligence responsibly.
Technology can block many threats.
But it cannot replace informed judgement, ethical leadership, or a workforce that understands its role in protecting the organisation.
The question boards and executives should ask is no longer:
"Have our people completed cybersecurity training?"
It should be:
"Have we created a culture where our people think securely, act responsibly, and feel empowered to protect the organisation every day?"
That is the difference between compliance and resilience.
And in today's rapidly evolving digital landscape, resilience is what truly matters.

0 Comments



Leave a Reply.

    Author

    Patrick – Founder of Cyberplanz | Business Strategist | Cyber Governance Advocate

    Patrick combines deep business experience, including an MBA with up-to-date cybersecurity expertise, including certification as a PECB ISO/IEC 27001 Lead Implementer. He helps businesses grow while staying secure—bridging the gap between cybersecurity and real-world operations with clear, human-centric solutions. Passionate about culture, clarity, and resilience, Patrick champions the belief that cybersecurity is everyone’s business—not just IT’s.

    Archives

    July 2026
    June 2026
    May 2026
    April 2026
    March 2026
    February 2026
    January 2026
    December 2025
    November 2025
    October 2025
    September 2025
    August 2025
    July 2025
    June 2025
    May 2025
    April 2025
    March 2025
    February 2025
    January 2025
    December 2024
    November 2024
    October 2024
    September 2024
    August 2024
    July 2024
    June 2024
    January 2024

    Categories

    All

    RSS Feed

Human-Centric Cyber Governance & AI Security for NZ Organisations

Picture
A Corna Consulting Company
  • Home
  • Services
    • 1. Cyber Governance Audit
    • ​2. Cyber Resilience Program
    • 3. Executive Cyber Advisory
    • 4. Staff Engagement & Culture Program
  • Products
  • Resources
    • The Cyberplanz Board Governance Framework >
      • The Boardroom Guide to Cyber & AI Governance
      • Board Cyber & AI Governance Self-Assessment
  • About Us
  • Contact Us
  • Blogs