CYBERPLANZ
  • Home
  • Services
    • 1. Cyber Governance Audit
    • ​2. Cyber Resilience Program
    • 3. Executive Cyber Advisory
    • 4. Staff Engagement & Culture Program
  • Products
  • Resources
    • The Boardroom Guide to Cyber & AI Governance
    • Board Cyber & AI Governance Self-Assessment
    • Cyberplanz Cyber Culture Dashboard
    • Cyberplanz Board Third-Party Cyber & Ai Risk Dashboard
  • About Us
  • Contact Us
  • Blogs
Picture
Picture
“Plans are of little importance, but planning is essential.”
― Winston Churchill

28 July Blog

7/28/2026

0 Comments

 

​From Human Firewall to Human Advantage

Picture
For years, organisations have been encouraged to think of their employees as the human firewall.
The idea was simple.
Technology cannot stop every cyber-attack.
Eventually, every suspicious email, unusual request or unexpected phone call reaches a person.
Employees become the final barrier between attackers and organisational systems.
While this concept has helped organisations recognise the importance of people in cybersecurity, it also has an unintended consequence.
It frames employees as the last line of defence.
A barrier.
A control.
Something that stands between the organisation and a cyber incident.
Today's organisations need to think differently.
People are not simply a firewall.
They are an organisation's greatest competitive advantage.
A Firewall Doesn't Learn
Traditional firewalls follow rules.
They inspect traffic.
They block known threats.
They do exactly what they have been programmed to do.
People are different.
People learn.
They adapt.
They collaborate.
They ask questions.
They recognise unusual behaviour.
They solve problems.
They make decisions in situations that technology has never encountered before.
Artificial Intelligence may process information faster than people.
But it still depends on human judgement, context and values.
The organisations that succeed in the future will not simply have better technology.
They will have better people, supported by better leadership.
The Human Advantage
The Human Advantage is created when employees are empowered to become active contributors to organisational resilience.
Rather than seeing cybersecurity as someone else's responsibility, people understand that they have an important role in protecting customers, colleagues and the organisation.
This doesn't happen because employees fear making mistakes.
It happens because they feel trusted, informed and supported.
The Human Advantage combines knowledge with confidence.
Technology with judgement.
Governance with culture.
Why Technology Alone Is Not Enough
Cybersecurity technology has advanced dramatically.
Artificial Intelligence can identify anomalies.
Security platforms can detect threats in seconds.
Automated tools can isolate compromised devices.
Yet many successful cyber-attacks still begin with a human interaction.
An employee approves a fraudulent payment.
A manager shares information with an impersonated executive.
A supplier receives a convincing AI-generated email.
A customer service representative resets an account after being deceived.
Technology provides important protection.
People provide context.
Together they create resilience.
Leadership Creates the Advantage
Employees rarely become engaged because of policies.
They become engaged because of leadership.
Leaders influence how people think about cyber risk.
They determine whether cybersecurity is viewed as:
An IT problem.
Or everyone's responsibility.
When leaders regularly discuss cyber resilience, recognise positive behaviours and demonstrate responsible use of AI, employees are more likely to follow.
Culture is shaped by what leaders consistently reinforce.
Trust Unlocks Potential
People perform at their best when they feel trusted.
When organisations create a Just Culture, employees are more likely to:
  • Report suspicious activity.
  • Admit mistakes quickly.
  • Ask questions before taking action.
  • Challenge unusual requests.
  • Share ideas for improvement.
  • Help colleagues stay safe.
Trust transforms cybersecurity from a compliance exercise into a shared organisational responsibility.
Every Conversation Matters
Cyber resilience is rarely built during annual awareness training.
It is built through everyday conversations.
A manager asking whether an unusual email looks legitimate.
A colleague reminding someone not to upload confidential information into a public AI platform.
A Cyber Champion discussing a recent phishing attempt during a team meeting.
A Board reviewing lessons from a recent near miss.
These conversations create awareness.
Awareness shapes behaviour.
Behaviour creates culture.
AI Makes Human Judgement More Important
Artificial Intelligence is changing the workplace faster than many organisations expected.
Employees increasingly rely on AI to improve productivity.
AI can generate reports.
Summarise meetings.
Write software code.
Analyse data.
Create content.
But AI also creates new risks.
It can confidently produce incorrect information.
It can reflect hidden bias.
It can generate convincing phishing emails.
It can be used to create deepfake voices and videos.
This is why organisations need more than AI capability.
They need human judgement.
The Human Advantage recognises that people remain responsible for questioning, validating and making ethical decisions.
Technology can recommend.
People remain accountable.
Cyber Champions Build the Human Advantage
One of the most effective ways to strengthen organisational resilience is to empower people throughout the business.
Cyber Champions encourage conversations.
Share practical guidance.
Promote responsible AI use.
Support colleagues.
Identify emerging risks.
They demonstrate that cybersecurity is not owned solely by IT.
It belongs to everyone.
Every department contributes to resilience.
Measuring What Matters
Many organisations continue measuring awareness through:
  • Training completion rates.
  • Phishing simulation results.
  • Policy acknowledgements.
These measures have value.
But they tell only part of the story.
A true Human Advantage can be seen through different indicators.
How quickly are suspicious activities reported?
Do employees challenge unusual requests?
Are near misses shared openly?
Do teams discuss cyber and AI risks regularly?
Do leaders actively promote cyber resilience?
These behaviours provide a far richer picture of organisational maturity.
The Board's Role
Boards have a critical role in creating the Human Advantage.
Directors should ask:
  • Do our people understand why cybersecurity matters?
  • Do employees feel safe reporting concerns?
  • Are leaders reinforcing positive behaviours?
  • Is AI being adopted responsibly?
  • How are we measuring cyber culture?
  • Are we investing in people as much as technology?
These questions shift the conversation from compliance to capability.
A Competitive Advantage
Customers increasingly trust organisations that demonstrate responsible governance.
Investors look for organisations that manage risk effectively.
Employees want to work where leadership values openness, learning and innovation.
The Human Advantage strengthens all three.
It improves resilience.
Builds trust.
Supports innovation.
Creates stronger organisational culture.
Enhances reputation.
These are outcomes that extend well beyond cybersecurity.
The Future Belongs to People
Artificial Intelligence will continue to evolve.
Technology will become faster.
Automation will become more sophisticated.
Cybercriminals will continue finding new ways to exploit organisations.
The organisations that succeed will not simply deploy the latest security technologies.
They will develop workplaces where people think critically.
Speak openly.
Challenge assumptions.
Learn continuously.
And work together to protect what matters most.
The future of cybersecurity is not about building a stronger human firewall.
It is about creating a Human Advantage.
Because technology may detect threats.
But it is people—guided by leadership, empowered by trust and supported by good governance—who create truly resilient organisations.

0 Comments

20 July Blog

7/20/2026

0 Comments

 

Creating a Just Culture: Why Employees Must Feel Safe Reporting Cyber Mistakes

Picture
Imagine this scenario.
An employee receives an email that appears to come from a trusted supplier.
Everything looks legitimate.
The branding is correct.
The language is professional.
The request seems routine.
Without realising it, they click a link and enter their credentials.
Within seconds, they suspect something isn't right.
Now they face a decision.
Do they report it immediately?
Or do they hope nobody notices?
That decision may determine whether the organisation experiences a minor security event—or a major cyber incident.
The greatest cyber risk is often not the mistake itself.
It is the delay in reporting it.
We Are All Human
Every employee makes mistakes.
Directors make mistakes.
CEOs make mistakes.
IT professionals make mistakes.
Cybersecurity specialists make mistakes.
Even experienced security professionals occasionally click suspicious links or overlook warning signs.
Cybercriminals understand this.
Modern cyber attacks are no longer crude or obvious.
They use Artificial Intelligence.
They research social media.
They impersonate trusted colleagues.
They exploit urgency, curiosity and human emotion.
Their objective is not to defeat technology.
It is to exploit perfectly normal human behaviour.
Organisations should not expect perfection.
They should expect humanity.
The Cost of Silence
In many organisations, employees hesitate to report cyber mistakes because they fear:
  • Embarrassment.
  • Blame.
  • Disciplinary action.
  • Damage to their reputation.
  • Looking incompetent.
  • Letting colleagues down.
These fears are understandable.
Unfortunately, they can significantly increase organisational risk.
An email reported within five minutes may affect one employee.
The same email reported six hours later may affect hundreds.
Time matters.
The sooner an organisation knows about an incident, the more options it has to contain it.
What Is a Just Culture?
A Just Culture recognises an important truth.
People should not be punished for making honest mistakes.
Instead, organisations should seek to understand:
What happened?
Why did it happen?
How can we reduce the likelihood of it happening again?
A Just Culture does not remove accountability.
Deliberate misconduct, reckless behaviour and intentional policy violations still require appropriate action.
However, honest mistakes become opportunities for learning rather than occasions for blame.
High-performing industries such as aviation and healthcare have embraced this approach for decades because they understand that learning depends on openness.
Cybersecurity should be no different.
Fear Is the Enemy of Resilience
Many organisations invest heavily in security technology while unintentionally creating cultures where employees fear speaking up.
This creates a dangerous contradiction.
Leaders ask employees to report incidents immediately.
Employees worry they will be criticised if they do.
The result is predictable.
Problems remain hidden.
Opportunities to contain incidents are lost.
Resilience suffers.
Trust is built when people believe they can admit mistakes without fear of unfair consequences.
Boards Set the Tone
Culture starts in the boardroom.
Boards influence organisational behaviour through the questions they ask, the behaviours they recognise and the values they reinforce.
Directors should ask:
  • Do employees feel psychologically safe reporting cyber incidents?
  • How quickly are potential incidents reported?
  • What have we learned from recent near misses?
  • Are we recognising good reporting behaviours?
  • Are leaders modelling openness and accountability?
The objective is not to eliminate mistakes.
It is to ensure mistakes become learning opportunities.
Managers Shape Everyday Behaviour
While Boards establish expectations, managers influence daily culture.
Employees watch how leaders respond when something goes wrong.
If the first response is:
"Who made this mistake?"
Employees quickly learn to remain silent.
If the response becomes:
"What can we learn from this?"
The conversation changes completely.
Managers should thank employees for reporting concerns.
Recognise honesty.
Focus on solutions.
Celebrate transparency.
People repeat behaviours that are acknowledged and valued.
Shadow AI Makes Trust Even More Important
Artificial Intelligence has introduced new reporting challenges.
Imagine an employee accidentally uploads confidential information into a public AI platform.
Will they immediately report it?
Or will they hope nobody notices?
As AI becomes more common, organisations will inevitably experience accidental misuse.
The organisations that respond most effectively will be those where employees feel safe admitting what happened.
AI governance depends as much on culture as it does on policy.
Near Misses Are Valuable Intelligence
One of the most overlooked sources of organisational learning is the cyber near miss.
Examples include:
  • A phishing email identified before anyone clicked it.
  • An employee questioning an unusual payment request.
  • Suspicious AI-generated content being challenged.
  • An accidental disclosure quickly reported.
  • A supplier requesting unusual information.
Every near miss provides valuable insight.
Rather than asking,
"Who was responsible?"
Leaders should ask,
"What can this teach us?"
Near misses often reveal weaknesses before they become major incidents.
Building a Reporting Culture
Creating a Just Culture requires deliberate effort.
Organisations should:
  • Make reporting simple.
  • Thank employees for speaking up.
  • Share lessons learned across the organisation.
  • Focus on improvement rather than blame.
  • Encourage curiosity.
  • Regularly discuss cyber and AI risks.
  • Recognise positive security behaviours.
When reporting becomes normal, resilience improves.
Cyber Champions Can Help
Cyber Champions play an important role in building trust.
Because they work within individual teams, colleagues often feel more comfortable discussing concerns with them than approaching IT directly.
Cyber Champions encourage conversations.
Answer questions.
Support colleagues.
Promote responsible AI use.
Most importantly, they help create an environment where seeking advice becomes normal rather than something to avoid.
Trust Is a Competitive Advantage
Customers trust organisations that respond openly to incidents.
Employees trust leaders who support learning.
Investors trust Boards that demonstrate strong governance.
Trust is built long before an incident occurs.
It is built every time an employee feels confident enough to say:
"I think I've made a mistake."
Without fear.
Without blame.
With confidence that the organisation will help solve the problem.
The Future Belongs to Learning Organisations
Technology will continue to improve.
Artificial Intelligence will continue to evolve.
Cyber threats will become even more sophisticated.
The organisations that remain resilient will not be those with the most advanced technology alone.
They will be those where people feel trusted.
Where leaders encourage openness.
Where reporting is recognised as a strength rather than a weakness.
Because in cybersecurity, silence is often far more dangerous than mistakes.
The most resilient organisations understand that culture is not simply another security control.
It is the foundation upon which every other control depends.
Creating a Just Culture is not about accepting failure.
It is about creating an organisation that learns faster, responds sooner, and becomes stronger because its people are confident enough to speak up.
In today's digital world, that may be one of the greatest competitive advantages any organisation can build.

0 Comments

14 July Blog

7/14/2026

0 Comments

 

The Rise of Shadow AI: What Every Board Should Know

Picture
Artificial Intelligence is transforming the way organisations operate.
Employees are using AI to write reports, analyse spreadsheets, prepare presentations, summarise meetings, write software code, create marketing campaigns, and automate repetitive tasks.
For many organisations, this is increasing productivity, improving customer service, and creating new opportunities for innovation.
But there is another side to this transformation.
It is happening quietly, largely unnoticed, and often without Board oversight.
It is known as Shadow AI.
Just as organisations once discovered employees were using unauthorised software and cloud services—known as Shadow IT—many are now discovering that staff are using AI tools every day without clear governance, policies, or understanding of the risks involved.
The question for Boards is no longer:
"Should our organisation use AI?"
The question is:
"Do we know how AI is already being used across our organisation?"
For many Boards, the honest answer is: probably not.
What is Shadow AI?
Shadow AI refers to the use of Artificial Intelligence tools or services that have not been approved, governed, or adequately monitored by an organisation.
It often begins with good intentions.
An employee wants to save time writing a report.
A manager uses AI to analyse customer feedback.
A marketing team generates campaign ideas.
A developer uses AI to accelerate coding.
A finance team asks AI to summarise complex spreadsheets.
None of these actions are necessarily inappropriate.
In fact, many deliver genuine business value.
The problem is that they often occur without anyone considering:
  • What data is being shared?
  • Where is that information stored?
  • Who owns AI-generated content?
  • How accurate are the results?
  • Are regulatory obligations being met?
  • Could confidential information be exposed?
Without governance, innovation can unintentionally become organisational risk.
Why Boards Should Care
Artificial Intelligence is no longer confined to technology teams.
It is being adopted across every department.
That means AI-related decisions are influencing:
  • Business strategy
  • Customer experience
  • Financial reporting
  • Human Resources
  • Marketing
  • Procurement
  • Operations
  • Risk management
Poorly governed AI can lead to:
  • Confidential information being entered into public AI platforms
  • Privacy breaches
  • Incorrect or fabricated information influencing decisions
  • Intellectual property leakage
  • Biased or discriminatory outcomes
  • Reputational damage
  • Regulatory scrutiny
  • Loss of stakeholder trust
Ultimately, these are governance issues—not just technology issues.
Shadow AI Is Often Invisible
One of the greatest challenges with Shadow AI is that organisations frequently don't know it exists.
Employees are not trying to bypass governance.
They are simply trying to work more efficiently.
AI tools are often:
  • Free
  • Easy to access
  • Available from any web browser
  • Integrated into existing software
  • Recommended by colleagues
Without clear guidance, employees naturally adopt the tools that help them perform their jobs.
The risk isn't that people are using AI.
The risk is that leadership has no visibility over how it is being used.
Banning AI Isn't the Answer
Some organisations have responded by attempting to ban AI altogether.
This is rarely effective.
Employees who see clear productivity benefits are unlikely to abandon AI simply because policies prohibit it.
Instead, AI usage often becomes even less visible.
History has shown this before.
When organisations banned cloud storage, employees found alternatives.
When organisations restricted mobile devices, staff brought their own.
The same applies to AI.
Effective governance is built on enablement, not prohibition.
The objective should be to create an environment where employees can use AI safely, responsibly, and confidently.
Questions Every Board Should Be Asking
Rather than focusing solely on technology, Boards should ask strategic questions.
For example:
  • Where is AI currently being used across our organisation?
  • Which AI tools have been approved?
  • Do we have an AI Governance Framework?
  • What information should never be entered into public AI platforms?
  • How are AI-generated outputs reviewed?
  • Who is accountable for AI-related decisions?
  • How are we educating employees about responsible AI use?
  • Are AI risks included in our enterprise risk register?
These conversations shift AI from an operational issue to a governance priority.
AI Governance Is About Trust
Good AI governance is not about slowing innovation.
It is about building trust.
Employees need confidence that they understand organisational expectations.
Customers need confidence that their information is protected.
Boards need confidence that AI supports business objectives without introducing unnecessary risk.
Trust becomes a competitive advantage.
Organisations that demonstrate responsible AI governance are increasingly viewed as more reliable by customers, regulators, investors, and business partners.
Building an AI-Aware Culture
Policies alone are not enough.
AI governance must become part of organisational culture.
This means:
  • Providing practical AI guidance rather than lengthy policy documents.
  • Helping employees understand both opportunities and risks.
  • Encouraging questions before problems occur.
  • Creating safe reporting channels.
  • Celebrating responsible AI use.
  • Updating governance as technology evolves.
Culture always moves faster than policy.
Strong organisations recognise this and invest in both.
The Role of Cyber Champions
Cyber Champions can play an important role in helping organisations manage Shadow AI.
Because they work within different departments, they often identify emerging AI use before leadership becomes aware of it.
They help colleagues understand:
  • Approved AI tools
  • Safe information handling
  • Responsible prompting
  • Verification of AI-generated content
  • Organisational AI expectations
Cyber Champions become trusted advocates for responsible innovation.
AI Governance Is a Leadership Opportunity
The organisations that gain the greatest value from AI will not necessarily be those using the most sophisticated tools.
They will be the organisations with the strongest governance.
Boards that embrace AI thoughtfully can encourage innovation while maintaining trust, protecting information, and meeting their governance responsibilities.
This requires curiosity.
Leadership.
Clear accountability.
And a willingness to ask better questions.
The Future Belongs to Governed Innovation
Artificial Intelligence will continue to evolve.
Employees will continue discovering new ways to use it.
Customers will increasingly expect organisations to use AI responsibly.
The question is no longer whether AI belongs in your organisation.
It almost certainly already does.
The real question is whether your Board has the visibility, governance, and leadership to ensure AI is being used safely, ethically, and in ways that strengthen—not weaken—your organisation.
Shadow AI should not be viewed as a hidden threat waiting to be eliminated.
It should be viewed as a signal.
A signal that innovation is happening.
The role of the Board is to ensure that innovation is guided by governance, supported by culture, and aligned with the organisation's values.
Because in the age of Artificial Intelligence, organisations will not be defined simply by how quickly they adopt AI.
They will be defined by how well they govern it.

0 Comments

6 July Post

7/6/2026

0 Comments

 

Building Cyber Champions: Why Every Department Needs a Security Advocate

Picture
For many organisations, cybersecurity still sits within the IT department.
When employees have a security question, they contact IT.
When a phishing email arrives, they forward it to IT.
When a cyber incident occurs, everyone expects IT to fix it.
This mindset creates a significant problem.
Cybersecurity is no longer simply an IT function.
It is an organisational capability.
The most resilient organisations recognise that cyber vigilance cannot be delivered by one department alone. It must be embedded throughout the business, with people at every level understanding their role in protecting the organisation.
One of the most effective ways to achieve this is by building a network of Cyber Champions.
What is a Cyber Champion?
A Cyber Champion is not another IT support person.
They are not expected to investigate cyber incidents, configure security systems or become cybersecurity experts.
Instead, they act as a trusted advocate for cyber resilience within their own team.
Cyber Champions help connect organisational security objectives with everyday business activities.
They encourage conversations.
Promote good security practices.
Support colleagues.
Provide feedback.
Identify emerging risks.
Most importantly, they help make cybersecurity part of everyday work rather than something that only appears during annual awareness training.
Why Every Department Needs One
Cyber risks exist across every part of an organisation.
Finance teams face invoice fraud and business email compromise.
Human Resources manages highly sensitive employee information and is increasingly exposed to AI-generated recruitment fraud.
Marketing teams use AI tools to create content while managing brand reputation and social media risks.
Operations teams rely on business systems that support day-to-day service delivery.
Customer service teams regularly verify identities and manage personal information.
Legal teams oversee contracts, privacy obligations and intellectual property.
Every department faces different risks.
A Cyber Champion understands how cyber and AI risks affect their own team and helps translate organisational policies into practical behaviours.
Creating a Human Firewall
The phrase "human firewall" is often used in cybersecurity.
While it conveys an important message, people are much more than a barrier between attackers and systems.
People are decision-makers.
Problem-solvers.
Communicators.
Leaders.
Cyber Champions help create an environment where secure decision-making becomes a normal part of everyday business.
They encourage colleagues to ask questions before sharing sensitive information.
They promote responsible AI use.
They reinforce good cyber habits.
Over time, these small conversations help create lasting behavioural change.
Bridging the Gap Between IT and the Business
One of the biggest challenges facing many organisations is communication.
Security teams often understand technical risks.
Business teams understand operational priorities.
Cyber Champions help bridge the gap.
Because they work within the business, they understand both the pressures their colleagues face and the importance of protecting organisational information.
They help explain security requirements in language that makes sense to their team.
Equally important, they provide valuable feedback to security and leadership teams about practical challenges, emerging concerns and opportunities for improvement.
This two-way communication strengthens governance and supports continuous improvement.
Cyber Champions and AI Governance
Artificial Intelligence has introduced a new dimension to organisational risk.
Employees increasingly use AI tools to:
  • Draft emails
  • Summarise reports
  • Analyse information
  • Generate presentations
  • Write software code
  • Improve productivity
These technologies create enormous opportunities.
They also create new governance challenges.
Cyber Champions can play an important role in helping colleagues understand:
  • Which AI tools are approved.
  • What information should never be entered into public AI platforms.
  • How to verify AI-generated outputs.
  • Ethical considerations when using AI.
  • Organisational AI policies and expectations.
As AI adoption accelerates, Cyber Champions become valuable advocates for responsible AI use.
What Makes a Great Cyber Champion?
The best Cyber Champions are not necessarily the most technical people.
They are people who are:
  • Trusted by their colleagues.
  • Good communicators.
  • Curious and willing to learn.
  • Positive role models.
  • Influential within their teams.
  • Passionate about helping others.
They encourage conversations rather than enforce rules.
They build confidence rather than fear.
They create engagement rather than compliance.
Supporting Your Cyber Champions
Simply appointing Cyber Champions is not enough.
Organisations should provide them with:
  • Regular updates on emerging threats.
  • AI governance guidance.
  • Practical discussion topics for team meetings.
  • Access to security specialists when needed.
  • Opportunities to share ideas with other Champions.
  • Recognition for their contribution.
When Cyber Champions feel supported, they become powerful advocates for organisational resilience.
The Board's Role
Boards and executive leaders have an important role in ensuring Cyber Champion programmes succeed.
They should ask:
  • Do we have Cyber Champions across the organisation?
  • Are they supported by leadership?
  • How do we measure their impact?
  • Are they helping improve our cyber culture?
  • Are they promoting responsible AI use?
Cyber Champion programmes should not be viewed as another awareness initiative.
They are a leadership investment.
They strengthen organisational culture, improve communication and increase resilience.
Measuring Success
Success should not be measured by the number of Cyber Champions appointed.
Instead, organisations should ask:
  • Are employees reporting suspicious activity sooner?
  • Has confidence in identifying cyber threats improved?
  • Are departments discussing cyber and AI risks more regularly?
  • Are security behaviours improving?
  • Are AI tools being used more responsibly?
  • Has collaboration between business teams and security improved?
These indicators provide a much better picture of organisational resilience than attendance records or training completion rates.
Every Organisation Can Benefit
You do not need thousands of employees to build a Cyber Champion programme.
For a small business, the owner or a senior team member may naturally become the Cyber Champion.
Medium-sized organisations may appoint one Champion for each department.
Larger organisations may build networks of Champions across offices, regions and business units.
The model is flexible because every organisation is different.
The principle remains the same.
Cyber resilience is strongest when responsibility is shared.
Turning Awareness into Action
Technology will continue to evolve.
Artificial Intelligence will continue to reshape the workplace.
Cyber threats will continue to become more sophisticated.
The organisations that succeed will not simply invest in better technology.
They will invest in better conversations.
Cyber Champions create those conversations.
They turn policies into behaviours.
Awareness into action.
Compliance into culture.
And colleagues into confident advocates for organisational resilience.
Building a network of Cyber Champions is not simply another cybersecurity initiative.
It is one of the most effective ways an organisation can embed cyber vigilance, strengthen AI governance and build a resilient culture that protects the business long into the future.

0 Comments

1 July Post

7/1/2026

0 Comments

 

Why Security Awareness Training Often Fails (And What Boards and Leaders Should Do Instead in the Age of AI)

Picture
Every year, organisations invest millions of dollars in cybersecurity awareness training.
Employees complete online modules.
They answer multiple-choice questions.
A certificate is issued.
The compliance box is ticked.
Yet organisations continue to fall victim to phishing attacks, business email compromise, ransomware, insider threats, and increasingly sophisticated AI-enabled cybercrime.
If awareness training is so widespread, why do so many organisations continue to experience preventable cyber incidents?
The answer is surprisingly simple.
Most organisations measure participation.
Very few measure behavioural change.
Cybersecurity awareness is not a training programme.
It is an organisational culture.
Compliance Does Not Equal Resilience
For many organisations, cybersecurity awareness has become a compliance exercise.
Staff are required to complete annual training because regulations, insurers, or auditors expect it.
Completion rates become the primary measure of success.
"We achieved 98% completion."
That sounds impressive.
But it tells us very little.
It does not tell us whether employees:
  • Recognise sophisticated phishing emails.
  • Know how to safely use AI tools.
  • Feel confident reporting suspicious activity.
  • Understand how their everyday decisions affect organisational risk.
  • Would know what to do during a cyber incident.
Compliance measures attendance.
Resilience measures capability.
The two are not the same.
The Threat Landscape Has Changed Faster Than Training
Traditional awareness programmes were designed for a different era.
Today, employees face threats that barely existed a few years ago, including:
  • AI-generated phishing emails that are almost impossible to distinguish from legitimate communications.
  • Deepfake voice and video scams targeting executives and finance teams.
  • Shadow AI, where employees unknowingly expose confidential information to public AI platforms.
  • AI-assisted social engineering attacks.
  • Supply chain compromises affecting trusted vendors.
Meanwhile, many organisations are still delivering the same annual training they have used for years.
Cybercriminals innovate daily.
Training often changes annually.
That imbalance creates risk.
People Are Not the Weakest Link
One of the most damaging phrases in cybersecurity is:
"People are the weakest link."
People are not the weakest link.
They are the most targeted.
When employees receive thousands of emails, constant Teams or Slack messages, phone calls, and AI-generated content every week, expecting perfect decision-making every time is unrealistic.
Instead of blaming employees, organisations should ask:
  • Have we given them the knowledge they need?
  • Have we created simple processes to follow?
  • Do they feel safe reporting mistakes?
  • Have we designed systems that support secure behaviours?
The goal should be to build confidence, not fear.
Boards Set the Tone
Cybersecurity culture starts long before an employee receives awareness training.
It starts in the boardroom.
If boards treat cybersecurity as an annual compliance exercise, management often does the same.
If boards instead ask:
  • How are we improving cyber behaviours?
  • How are we measuring our security culture?
  • Are employees confident in identifying cyber threats?
  • How are we preparing staff for the responsible use of AI?
...the entire organisation begins to think differently.
Culture follows leadership.
Awareness Should Be Continuous
Learning is most effective when it is ongoing.
The same applies to cybersecurity.
Rather than relying on a single annual training session, organisations should create continuous engagement throughout the year.
Examples include:
  • Five-minute monthly security updates.
  • AI awareness briefings.
  • Department discussions.
  • Short video messages from executives.
  • Phishing simulations followed by coaching.
  • Security tips aligned with current events.
  • Quarterly cyber resilience workshops.
  • Incident reviews that focus on learning rather than blame.
Cyber awareness should become part of everyday work—not an annual interruption.
AI Literacy Is the New Security Awareness
Artificial Intelligence has fundamentally changed the way people work.
Employees increasingly use AI to:
  • Draft emails.
  • Summarise reports.
  • Analyse data.
  • Generate marketing content.
  • Write code.
  • Improve productivity.
Yet many organisations have provided little or no guidance on its safe use.
Without governance, employees may:
  • Upload confidential information into public AI tools.
  • Trust inaccurate AI-generated outputs.
  • Accidentally expose intellectual property.
  • Create regulatory compliance issues.
  • Introduce bias into business decisions.
Security awareness programmes must now include AI literacy.
Employees need to understand not only how to use AI effectively, but also how to use it responsibly.
Make Cybersecurity Relevant
Generic awareness programmes often fail because employees struggle to relate them to their daily work.
The risks faced by a finance manager differ from those faced by a software developer, HR advisor, receptionist, or board member.
Training should reflect those differences.
Examples include:
Finance Teams
Business email compromise, invoice fraud, executive impersonation.
Human Resources
Sensitive personal information, recruitment scams, AI-generated CV fraud.
Marketing
Brand impersonation, AI-generated content, social media attacks.
Executives
Whaling attacks, deepfake communications, strategic decision-making.
Board Members
Cyber governance, AI governance, organisational resilience, regulatory oversight.
People engage when learning feels relevant.
Build a Culture Where Reporting Is Encouraged
One of the strongest indicators of cyber maturity is how quickly employees report concerns.
Unfortunately, many organisations unintentionally discourage reporting.
Employees worry about:
  • Looking incompetent.
  • Being blamed.
  • Disciplinary action.
  • Embarrassment.
This delays incident response.
Instead, organisations should celebrate reporting.
An employee who reports a suspicious email—even if it turns out to be harmless—has demonstrated the exact behaviour leaders should encourage.
Reporting should be recognised as a positive contribution to organisational resilience.
Measure Behaviour, Not Attendance
If awareness programmes are to improve, organisations must rethink what they measure.
Useful indicators include:
  • Phishing reporting rates.
  • Time taken to report incidents.
  • AI usage awareness.
  • Employee confidence surveys.
  • Security culture assessments.
  • Participation in discussions.
  • Lessons learned from near misses.
  • Trends in security-related behaviours.
These metrics provide a far more accurate picture of organisational resilience than training completion rates alone.
Leadership Must Participate
Nothing undermines an awareness programme faster than leaders who fail to participate.
When executives ignore security policies or directors bypass governance processes, employees notice.
Leadership should:
  • Attend awareness sessions.
  • Follow the same security practices expected of staff.
  • Talk openly about cyber and AI risks.
  • Share lessons from incidents.
  • Celebrate good security behaviours.
Culture is built through visible leadership.
Security Awareness Is Really Organisational Awareness
The most resilient organisations understand that cybersecurity is not simply about technology.
It is about decision-making.
Communication.
Trust.
Leadership.
Behaviour.
And increasingly, it is about how people use artificial intelligence responsibly.
Technology can block many threats.
But it cannot replace informed judgement, ethical leadership, or a workforce that understands its role in protecting the organisation.
The question boards and executives should ask is no longer:
"Have our people completed cybersecurity training?"
It should be:
"Have we created a culture where our people think securely, act responsibly, and feel empowered to protect the organisation every day?"
That is the difference between compliance and resilience.
And in today's rapidly evolving digital landscape, resilience is what truly matters.

0 Comments

    Author

    Patrick – Founder of Cyberplanz | Business Strategist | Cyber Governance Advocate

    Patrick combines deep business experience, including an MBA with up-to-date cybersecurity expertise, including certification as a PECB ISO/IEC 27001 Lead Implementer. He helps businesses grow while staying secure—bridging the gap between cybersecurity and real-world operations with clear, human-centric solutions. Passionate about culture, clarity, and resilience, Patrick champions the belief that cybersecurity is everyone’s business—not just IT’s.

    Archives

    September 2026
    August 2026
    July 2026
    June 2026
    May 2026
    April 2026
    March 2026
    February 2026
    January 2026
    December 2025
    November 2025
    October 2025
    September 2025
    August 2025
    July 2025
    June 2025
    May 2025
    April 2025
    March 2025
    February 2025
    January 2025
    December 2024
    November 2024
    October 2024
    September 2024
    August 2024
    July 2024
    June 2024
    January 2024

    Categories

    All

    RSS Feed

Human-Centric Cyber Governance & AI Security for NZ Organisations

Picture
A Corna Consulting Company
  • Home
  • Services
    • 1. Cyber Governance Audit
    • ​2. Cyber Resilience Program
    • 3. Executive Cyber Advisory
    • 4. Staff Engagement & Culture Program
  • Products
  • Resources
    • The Boardroom Guide to Cyber & AI Governance
    • Board Cyber & AI Governance Self-Assessment
    • Cyberplanz Cyber Culture Dashboard
    • Cyberplanz Board Third-Party Cyber & Ai Risk Dashboard
  • About Us
  • Contact Us
  • Blogs