Skip to main content
Back to Blog
Security AwarenessConcept Explainer 6 min read

Security Awareness Training Is Broken. Here's What Actually Works.

Most organisations run annual security awareness training that nobody remembers by March. The research on what actually changes human behaviour tells a different story.

L
Lavanyah Prabu
Nov 30, 2024
Security Awareness Culture Human Risk Leadership

Key Takeaways

  • 1Annual mandatory training has minimal impact on behaviour — completion rates are vanity metrics
  • 2Psychological safety is foundational — employees who fear punishment hide mistakes instead of reporting them
  • 3Role-relevant, just-in-time training outperforms generic quarterly modules significantly
  • 4Security champion networks embedded in business teams drive more behaviour change than centralised programmes
  • 5Measure leading indicators (report rates, near-miss rates) not lagging ones (completion rates)

The $3 billion security awareness industry is largely failing

Here's the uncomfortable truth: annual mandatory security awareness training, followed by a phishing simulation, has marginal impact on organisational security. Academic research on behaviour change consistently shows this. Practitioners know it. Vendors know it too, but they're selling completion rates to compliance teams.

Yet organisations continue to buy the same LMS modules every year, report completion rates to the board, and call it done.

Why Traditional Training Fails

It's divorced from context.

A generic video about password security watched in January is forgotten by March. Worse, it's watched on a Tuesday afternoon when the employee is trying to finish a deadline — not when they're actually facing a suspicious email. People don't connect generalised training to their real work environment.

It focuses on compliance, not behaviour.

Checking a box is not the same as changing how someone evaluates a suspicious link at 4:30 PM on a Friday. The goal of most security awareness programmes is auditor satisfaction, not human behaviour change. These are different objectives that require different approaches.

It treats humans as the problem.

When the central message of your training programme is "humans are the weakest link," you've already lost the culture battle. This framing creates shame rather than ownership, and shame is a terrible motivator for sustained behaviour change.

It ignores psychological safety.

If employees believe that clicking a phishing simulation will result in embarrassment, discipline, or being used as a bad example in the next all-hands, they will hide their mistakes. A culture of blame produces hidden near-misses. A culture of psychological safety produces reported near-misses — which is vastly more valuable for your security programme.

What Actually Works

Short, frequent touchpoints over long, periodic modules

Five-minute monthly communications — a real phishing example from this week's threat landscape, a quick case study from a relevant industry breach — are more effective than 60-minute quarterly modules. Frequency and relevance beat duration.

Role-relevant content

Finance teams should get wire fraud and BEC training. HR teams should get recruitment phishing training (fake LinkedIn InMails, fake job applications are a common attack vector). Engineering teams should get social engineering and phishing-for-credentials training. One-size-fits-all is none-size-fits-anyone.

Just-in-time training

The most effective training moment is immediately after a near-miss. When someone almost clicks a phishing simulation, the teachable window is open. Automated systems that deliver a brief, contextualised learning moment right at that point significantly outperform scheduled training blocks.

Security champion networks

Identify security-aware employees in each business unit and invest in them. Give them early visibility into emerging threats, recognition for their security behaviour, and a direct line to the security team. Champions embedded in business teams drive behaviour change more effectively than centralised awareness campaigns because they have context, relationships, and credibility.

Leadership modelling

If the CISO completes the phishing training from a personal mobile in three minutes without reading it, everyone knows. If the CEO asks the security team for a briefing on phishing trends, people notice. Leadership behaviour is the most powerful signal in any culture programme.

Measuring the right things

Completion rates tell you nothing about behaviour change. Measure:

  • Phishing simulation click rates (and trend over time, not just point-in-time)
  • Near-miss report rates (are people reporting suspicious emails?)
  • Help desk security-related query volume (are people asking before acting?)
  • Time-to-report for suspected phishing

Increasing near-miss report rates is one of the most valuable security metrics an organisation can track. It means people are seeing the threat and choosing to act correctly.

For Security Professionals Building This Programme

If you're in GRC, security management, or heading toward a security leadership role, designing and measuring a security awareness programme is a high-value skill that differentiates mid-level from senior candidates.

Articulating the shift from compliance-driven to behaviour-driven awareness — and demonstrating you can measure what actually matters — signals strategic maturity.


If you're a cybersecurity professional looking to build your career in security management or GRC leadership, our coaching programmes include strategy and communication skills development.

Contact Us →

Ready to Apply This in Your Career?

LumaShift helps you turn insights like these into tangible career progress. Let's talk about where you are and where you want to be.

LumaShift Career Advisor

Cybersecurity career guidance

Hi! I'm LumaShift's Career Advisor. I can help you find the right coaching service, understand cybersecurity career paths, or answer questions about certifications and salaries.


What can I help you with today?

Or email lumashift@outlook.com

Chat on WhatsApp