Skip to main content
Cyber Security

Security Awareness Training That Actually Changes Behaviour

The annual compliance video is the most widely deployed and least effective security control in existence. What works instead is smaller, more frequent and considerably less comfortable to run.

SF

Smart Forum

3 min read

Every organisation we assess has security awareness training. Almost none of them can show it changed anything. The reason is consistent: the training is designed to be completed, not to be effective, and those two goals pull in opposite directions.

A completion-optimised programme is annual, universal, video-based and followed by a five-question quiz that nobody fails. It produces a clean compliance record and a workforce that has learned exactly one thing — that security training is something you click through.

Start from your incidents, not from a syllabus

Generic curricula cover the full threat landscape because they have to sell to everyone. Your organisation does not face the full threat landscape; it faces a handful of realistic attack paths, and it has a history of the ones that nearly worked.

Before writing any material, we go through the incident log, the helpdesk tickets and the results of a baseline phishing simulation. That produces a ranked list of what actually reaches your people. In most organisations the top three are business email compromise, credential phishing against the single sign-on portal, and a supplier-invoice fraud pattern targeting finance specifically.

Three risks, three tailored modules, delivered to the roles they affect. That is a very different programme from twelve chapters delivered to everyone.

Make it short, frequent and role-specific

Attention is the constraint. A forty-minute annual session is worse than eight five-minute sessions spread across the year, and dramatically worse than a two-minute intervention delivered at the moment somebody nearly falls for something.

Role-specific matters as much as short. The finance team needs to be genuinely expert at spotting payment-redirection fraud, because they are the ones targeted by it. The engineering team needs to understand credential hygiene and dependency risk. The reception desk needs to know what physical pretexting looks like. Sending all three the same content wastes everyone's time and teaches the specialists nothing.

Simulate, but do it honestly

Phishing simulation is the only part of most programmes that produces real data, and it is frequently run in a way that destroys trust.

Two rules make the difference. First, never punish a click. The moment reporting a mistake becomes risky, people stop reporting, and your detection time goes from minutes to weeks. The metric that matters is not click rate; it is report rate, and specifically the time from first delivery to first report.

Second, do not use cruel lures. Simulated bonus announcements and fake redundancy notices work spectacularly in the click statistics and cost you the goodwill of the entire workforce. The point is to build a reporting reflex, not to prove people can be fooled — everyone can be fooled by a sufficiently good lure, including the security team.

Measure something that means anything

Completion percentage measures compliance. These measure security:

  • Time to first report on a simulated campaign, tracked over successive rounds
  • Report rate as a proportion of recipients, not just of clickers
  • Repeat-click cohort size, which tells you where targeted coaching is needed
  • Real incidents caught by a person, versus caught by tooling

The last one is the point of the whole exercise. A workforce that reports quickly turns a potential breach into an alert, and that is worth more than any percentage on a compliance dashboard.

Give people somewhere to go

The most valuable output of a good programme is not knowledge, it is a habit: when something feels wrong, tell someone immediately.

That requires a route that takes seconds and carries no social cost — a report button in the mail client, a channel that is monitored, and a visible practice of thanking people for reports that turn out to be nothing. Organisations that get this right find their mean time to detection drops before their click rate does.

Security awareness training is part of our managed services practice, alongside security risk analysis and employee training sessions built around the systems your staff actually use.

  • #Security
  • #Training
  • #Phishing
  • #Risk
Share

More stories

All articles
5G & Telecom

What 5G Standalone Actually Changes — and What It Doesn't

Most 5G in service today is non-standalone: a new radio bolted onto an LTE core. The features that made 5G interesting only arrive with a standalone core, and the difference is worth understanding before you plan around it.

SF

Smart Forum

3 min read

Artificial Intelligence

Building RAG Systems That Survive Contact With Production

Most retrieval-augmented generation demos work beautifully and then fall apart on real documents. Here is what separates a convincing prototype from a system your team will still trust in twelve months.

SF

Smart Forum

3 min read

Ready when you are

Let us scope your project properly

Tell us what you are trying to build. We will come back with an honest view of the approach, the effort and whether we are the right team for it.

  • Reply within one business day
  • NDA signed before details
  • No obligation, no hard sell

Or write to us directly at info@smartforum.org