Why Security Awareness Training Often Fails (And What Boards and Leaders Should Do Instead in the Age of AI)Every year, organisations invest millions of dollars in cybersecurity awareness training.
Employees complete online modules. They answer multiple-choice questions. A certificate is issued. The compliance box is ticked. Yet organisations continue to fall victim to phishing attacks, business email compromise, ransomware, insider threats, and increasingly sophisticated AI-enabled cybercrime. If awareness training is so widespread, why do so many organisations continue to experience preventable cyber incidents? The answer is surprisingly simple. Most organisations measure participation. Very few measure behavioural change. Cybersecurity awareness is not a training programme. It is an organisational culture. Compliance Does Not Equal Resilience For many organisations, cybersecurity awareness has become a compliance exercise. Staff are required to complete annual training because regulations, insurers, or auditors expect it. Completion rates become the primary measure of success. "We achieved 98% completion." That sounds impressive. But it tells us very little. It does not tell us whether employees:
Resilience measures capability. The two are not the same. The Threat Landscape Has Changed Faster Than Training Traditional awareness programmes were designed for a different era. Today, employees face threats that barely existed a few years ago, including:
Cybercriminals innovate daily. Training often changes annually. That imbalance creates risk. People Are Not the Weakest Link One of the most damaging phrases in cybersecurity is: "People are the weakest link." People are not the weakest link. They are the most targeted. When employees receive thousands of emails, constant Teams or Slack messages, phone calls, and AI-generated content every week, expecting perfect decision-making every time is unrealistic. Instead of blaming employees, organisations should ask:
Boards Set the Tone Cybersecurity culture starts long before an employee receives awareness training. It starts in the boardroom. If boards treat cybersecurity as an annual compliance exercise, management often does the same. If boards instead ask:
Culture follows leadership. Awareness Should Be Continuous Learning is most effective when it is ongoing. The same applies to cybersecurity. Rather than relying on a single annual training session, organisations should create continuous engagement throughout the year. Examples include:
AI Literacy Is the New Security Awareness Artificial Intelligence has fundamentally changed the way people work. Employees increasingly use AI to:
Without governance, employees may:
Employees need to understand not only how to use AI effectively, but also how to use it responsibly. Make Cybersecurity Relevant Generic awareness programmes often fail because employees struggle to relate them to their daily work. The risks faced by a finance manager differ from those faced by a software developer, HR advisor, receptionist, or board member. Training should reflect those differences. Examples include: Finance Teams Business email compromise, invoice fraud, executive impersonation. Human Resources Sensitive personal information, recruitment scams, AI-generated CV fraud. Marketing Brand impersonation, AI-generated content, social media attacks. Executives Whaling attacks, deepfake communications, strategic decision-making. Board Members Cyber governance, AI governance, organisational resilience, regulatory oversight. People engage when learning feels relevant. Build a Culture Where Reporting Is Encouraged One of the strongest indicators of cyber maturity is how quickly employees report concerns. Unfortunately, many organisations unintentionally discourage reporting. Employees worry about:
Instead, organisations should celebrate reporting. An employee who reports a suspicious email—even if it turns out to be harmless—has demonstrated the exact behaviour leaders should encourage. Reporting should be recognised as a positive contribution to organisational resilience. Measure Behaviour, Not Attendance If awareness programmes are to improve, organisations must rethink what they measure. Useful indicators include:
Leadership Must Participate Nothing undermines an awareness programme faster than leaders who fail to participate. When executives ignore security policies or directors bypass governance processes, employees notice. Leadership should:
Security Awareness Is Really Organisational Awareness The most resilient organisations understand that cybersecurity is not simply about technology. It is about decision-making. Communication. Trust. Leadership. Behaviour. And increasingly, it is about how people use artificial intelligence responsibly. Technology can block many threats. But it cannot replace informed judgement, ethical leadership, or a workforce that understands its role in protecting the organisation. The question boards and executives should ask is no longer: "Have our people completed cybersecurity training?" It should be: "Have we created a culture where our people think securely, act responsibly, and feel empowered to protect the organisation every day?" That is the difference between compliance and resilience. And in today's rapidly evolving digital landscape, resilience is what truly matters.
0 Comments
Leave a Reply. |
AuthorPatrick – Founder of Cyberplanz | Business Strategist | Cyber Governance Advocate Archives
July 2026
Categories |
RSS Feed