Cyber awareness that changes behaviour
For CISOs, executives, and the leaders who set the security culture
10 June 2026
Most security awareness programs can prove exactly one thing: that people clicked through the training. Completion sits at some high and reassuring number, the annual phishing simulation produces its annual chart, and the incidents keep arriving through the same human doorways they always have. The problem is not that awareness does not matter — the human layer sits inside most incident chains. The problem is that completion measures compliance, and compliance was never the risk.
1. Measure behaviour, not attendance
The unit of awareness is not the course completed; it is the behaviour under pressure. Does the unexpected invoice get paid or queried? Does the odd login prompt get entered or reported? Does the urgent request from the CEO's address get actioned or verified? These are observable events — simulation results, reporting rates, response times, real-incident entry points — and together they describe the organisation's actual human risk far better than any completion dashboard. Measure those, trend them, and let them drive the program.
2. Segment by risk, not by headcount
Awareness delivered identically to everyone is awareness calibrated for no one. Finance approvers face invoice fraud; engineers with production access face credential theft; executive assistants face impersonation; new starters face everything at once. Map the roles that attackers actually target — the money-movers, the access-holders, the identity-adjacent — and weight the effort there. The annual all-staff module can stay as the floor; the program lives in the targeted work above it.
3. Intervene at the moment, not the anniversary
Behaviour changes closest to the decision. A short, specific nudge when someone is about to do the risky thing — or immediately after a near-miss, while the memory is real — outweighs an hour of generic content on the anniversary of last year's hour. Build the loop small and frequent: simulations that reflect current attacker behaviour, feedback that teaches rather than shames, and content that arrives because a signal suggested it was needed, not because the calendar did.
4. Make reporting the win condition
The single most valuable human security behaviour is reporting early — the suspicious email, the clicked link, the credential entered in a moment of autopilot. Every program choice either encourages that or suppresses it. If clicking a simulation triggers public embarrassment or remedial punishment, people learn to hide, and the organisation loses its early-warning system precisely where it needs it most. Celebrate the report, time-stamp the response, and treat a rising report rate as the success metric it is — a reported click is a contained incident; a hidden one is an investigation.
5. Culture is set above, evidenced below
Teams calibrate on what leaders do. An executive who verifies an unusual payment request out loud, reports their own near-miss, and accepts security friction without theatre does more for the human layer than any campaign. This is also where obligations meet behaviour: CPS 234 and the Essential Eight assume controls operate as designed, and humans operate the controls. A board that asks for behavioural risk measures — not completion rates — signals what the organisation should optimise for.
6. The first 90 days
Baseline honestly: current reporting rate, simulation outcomes by role, and where real incidents actually entered. Identify the five highest-risk role groups and design their targeted interventions first. Reset the reporting experience so the fastest reporters are visibly valued. Retire the metrics that measure activity, and stand up the two that measure risk: behaviour under test, and time-to-report. Then run the loop and let the trend — not the calendar — set the cadence.
An awareness program succeeds when the phrase changes: from everyone completed the training to the organisation reports faster than the attacker moves. One is a certificate. The other is a control.