Why Traditional Security Training Fails and What You Can Do About It

Written by John Scott, Lead Security Researcher, CultureAI

No matter the size, industry, or location of a company, one thing is almost certain: they are providing some level of security training to their employees. For some, it’s an annual PowerPoint and mandatory quiz. However, many more businesses are now spending a significant amount of time, money, and resources on security awareness training, aiming to transform their employees into lean, mean, risk-spotting machines.

Despite best intentions, many of these companies find that their training programmes are not producing the desired outcomes. So, why does traditional security training miss the mark, and what are the essential improvements needed to effectively tackle human risk?

Out with: Tick-box training  

A one-size-fits-all approach overlooks each employee’s unique needs and responsibilities. Not to mention, employees during irrelevant lectures and lengthy presentations. This method addresses only part of the problem and cannot inherently motivate everyone. For security training to genuinely change behaviour, it needs to be a primary focus, but achieving universal dedication is unrealistic when employees have their jobs to do.

In with: Targeted coaching  

Training can help correct mistakes but falls short in preventing the slips and lapses that even the most proficient employees may experience. Effective security coaching is both continuous and adaptive, offering immediate and relevant guidance tailored to specific situations. This approach underscores real-time decision-making, ensuring best practices are followed effectively when they matter most. It also respects the time of those employees who consistently demonstrate positive behaviours.

Out with: ‘Finger in the air’ training  

Too many organisations attempt to mitigate workforce risk by focusing on the latest trending topic like Generative AI to quishing. This approach often leads to a scattered focus, lacking in both depth and effectiveness, as it doesn’t address the highest risks. Employees are expected to keep up with an ever-evolving array of threats, which is unrealistic and overwhelming. Without a clear prioritisation strategy, organisations risk wasting valuable time and resources on issues that may not pose a significant threat, ultimately benefiting no one.

In with: Detecting employee security behaviours    

Rather than guessing what training and interventions would be most relevant for employees, it would be better to leverage real-time data to understand where the vulnerabilities lie. While security behaviours like phishing email clicks are well understood, there are many more behaviours that are crucial to managing human risk that are important to account for. Human Risk Management platforms integrate with existing technology tools to detect and respond to a broad range of human-related risks.

Out with: A focus on completion rates  

Focusing solely on completion rates for training can be misleading, as high participation does not guarantee the knowledge has been internalised or understood. Employees will often see it as another task to be completed and will keep making the same security mistakes. This approach overlooks the Kirkpatrick Model’s emphasis on evaluating the effectiveness of training through reaction, learning, behaviour, and results.

In with: Enhanced behavioural metrics  

Real-time behavioural data and analytics are going to be far more powerful than training completion rate when it comes to getting a good picture of employee behaviours and risk levels. According to the Kirkpatrick Model, this aligns more effectively with the learning and behaviour levels, offering insight into how training impacts employee actions and overall risk. It is also a more powerful metric for success, as you can see changes in risk over time.

Out with: Punitive measures 

Regrettably, some security teams prefer the ‘stick’ over the ‘carrot’ approach, penalising those who fail training or phishing simulations. This fear-based strategy not only proves ineffective but also undermines the development of a strong, positive security culture and adversely affects workplace well-being. Incessant notifications can also be perceived as a corrective action, potentially harming employee morale.

In with: Positive reinforcement  

When an organisation celebrates and reinforces positive security actions, individuals feel more motivated and encouraged to maintain those behaviours. Using gamification and rewards, can also boost employee engagement. Recognising achievements lifts morale and helps build a proactive security culture, ultimately leading to a safer environment. Providing regular feedback and maintaining a supportive atmosphere further encourage adherence to security best practices.

Out with: Lip service security  

Security must be woven into the fabric of every organisational process, transcending beyond mere checkbox exercises. It’s not enough to mandate a few training modules for employees and call it a day. True security demands a multi-layered approach, integrating comprehensive human risk management strategies. This means equipping teams with the tools, knowledge, and mindset to proactively identify and mitigate risks. Security isn’t a one-time task; it’s an ongoing commitment.

In with: Security-conscious cultures  

Without a culture that prioritises security, there will never be buy-in to acquire the necessary security tools and technologies to enhance security posture. A cyber-secure culture begins at the top, requiring leadership commitment. It must be a priority for the company, with organisations taking a proactive approach to protect employees.

Out with: Traditional security approaches 

As technology advances enable more effective threat campaigns, security teams must follow suit and adopt an “out with the old and in with the new” approach to counter possible threats, particularly those using new technologies and approaches and preying on human risk. Security teams must adopt a comprehensive, multi-layered approach to security to maximise the impact and reduce the risk. Companies that move beyond traditional security training, will benefit from a more strategic approach that uses real-time insights, security coaching and human risk management strategies to create immediate awareness of potential risks amongst employers, alert to risky behaviour and mitigate potential threats before they lead to a security breach. Improving the security posture of an organisation starts with the realisation that it is an ongoing commitment that needs to combine several approaches to be effective.