Let me describe a scene that will be familiar to almost everyone reading this.
Once a year, an email arrives. “Please complete your mandatory security awareness training by Friday.” You click the link. A series of slides appear. Some of them have animations. There’s a module about not clicking suspicious links. Another one about strong passwords. A short quiz at the end with questions you could answer correctly without having watched any of it. You pass. You close the tab. You go back to work.
Six months later, someone in the finance team clicks a phishing email and transfers money to an attacker.
That training didn’t fail because the content was wrong. It failed because a once-a-year slideshow has never — in the history of human behaviour — changed how anyone responds under pressure. Knowing something and doing it instinctively when you’re tired, distracted, and under deadline pressure are two entirely different things.
This is the gap most security awareness programmes live in. And closing it requires a fundamentally different approach.
The Problem With Annual Checkbox Training
The annual compliance training model exists for one reason: it satisfies an audit requirement. It proves, on paper, that the organisation “provided security training to all staff.” It does not prove that anyone learned anything. It does not prove that anyone changed their behaviour. It just proves that everyone clicked through the slides.
The psychology here is straightforward. For learning to stick, it needs to be repeated, contextual, and connected to real consequences. A single annual event provides none of those things. By the time the next phishing campaign hits — which might be two weeks after the training or two months — the content has faded almost completely.
There’s also a relevance problem. Generic training modules talk about phishing in abstract terms. They show obviously suspicious emails with bad spelling, urgent language, and suspicious sender addresses. Real phishing attacks targeting your organisation look nothing like that. They’re tailored, contextual, and often indistinguishable from legitimate internal communication at first glance. Training people to spot the generic version doesn’t prepare them for the real one.
And perhaps most damaging — the compliance framing sends a message. Security is something you do once a year to stay out of trouble, not something that’s part of how you work every day.
What Effective Awareness Training Actually Looks Like
The organisations I’ve seen with genuinely strong security cultures don’t run training as an event. They run it as an ongoing conversation.
What does that look like in practice?
Short, frequent, relevant communication. A monthly email or Teams message that says “here’s a phishing attempt that’s currently targeting organisations in our industry — this is what it looks like and this is why it’s convincing” is worth more than an annual training module. It’s timely. It’s specific. It connects to something real.
Integration into existing workflows. Security awareness doesn’t need to be a separate programme. It can be woven into onboarding, into team meetings, into the way incidents are communicated internally. When a phishing attempt is blocked by your email gateway, telling people “we blocked 47 phishing attempts targeting our domain this week, here’s what they looked like” turns an invisible security event into a learning moment.
Role-specific content. The threats facing someone in finance are different from the threats facing someone in IT operations. A finance team member needs to understand business email compromise, invoice fraud, and wire transfer scams. An IT admin needs to understand credential phishing, MFA bypass, and social engineering targeting service desk staff. Generic content that tries to cover everything ends up being specific to nothing.
Leadership involvement. When executives talk about security — genuinely, not just in a compliance video — it signals to the whole organisation that this is taken seriously. When a CEO mentions in a town hall that they personally received a spear-phishing attempt last week and here’s how they spotted it, that’s more effective than any training module.
Simulated Phishing — Done Right
Phishing simulations are one of the most powerful tools in a security awareness programme. They’re also one of the most commonly misused.
Done wrong, a phishing simulation is a gotcha exercise. You send a convincing fake email, track who clicks, and then send the people who clicked a shaming notification and make them do extra training. The message this sends is: security is something you get punished for getting wrong. The result is that people hide mistakes rather than report them.
Done right, a phishing simulation is a learning exercise. The goal isn’t to catch people out — it’s to give people a realistic experience of what a phishing attempt feels like and immediate feedback that helps them understand what to look for.
When someone clicks a simulated phishing link, they should see an immediate, non-judgmental explanation of what just happened and why. What made this email convincing? What signals should have triggered suspicion? What’s the right action when you’re not sure? That immediate teachable moment — while the experience is fresh — is when learning actually happens.
The metrics you track should reflect this. Click rates matter, but so does report rates. If your simulated phishing report rate is increasing over time — meaning more people are flagging suspicious emails rather than just ignoring or clicking them — that’s your real indicator of cultural change.
A few practical points on simulation design: vary the difficulty. Start with more obvious simulations and gradually increase the sophistication as your team develops their instincts. Use real-world templates that reflect the actual threats targeting your industry. And avoid timing simulations around high-stress periods — running a phishing simulation during a month-end close or a major project deadline will skew your results and frustrate your staff.
Making Security Relevant to Non-Technical People
This is where most security programmes lose people, and it’s entirely avoidable.
Technical people have a tendency to explain security in technical terms. We talk about threat vectors and attack surfaces and defence in depth. To a finance manager or an HR professional, this is meaningless noise. It doesn’t connect to anything in their daily experience and so it doesn’t change their behaviour.
The translation is simple: connect security to things people already care about.
For finance teams — talk about invoice fraud and wire transfer scams in terms of money that leaves the business and doesn’t come back. Talk about the reputational damage of a breach. Talk about regulatory fines. Money and professional consequences are things finance people understand and take seriously.
For HR teams — talk about data protection in terms of the personal information they handle every day. Payroll data. Medical information. Personal addresses. “If this information was exposed, here’s what it could mean for the people whose information it is.” That framing makes it personal and real.
For everyone — use real examples. Not hypothetical scenarios, actual incidents. There’s no shortage of public breach reports, news stories, and case studies. “This is what happened to a company similar to ours. This is how it started. This is how much it cost them.” Real consequences, real numbers, real companies.
The goal is to make security feel like something that matters to them in their job — not something that belongs to the IT department.
The Culture Side — Reporting Without Fear
Here’s something that most organisations get completely backwards.
When someone makes a security mistake — clicks a phishing link, falls for a social engineering call, sends sensitive data to the wrong address — what happens next determines your entire security culture.
If the response is punishment, mandatory retraining framed as consequences, or public embarrassment — you’ve just trained every other person in the organisation to hide their mistakes. The next time someone clicks something suspicious, they won’t report it. They’ll close the browser and hope nobody noticed. Because the cost of admitting it is too high.
And that’s exactly the scenario where a phishing attack that could have been contained becomes a full breach. The attacker has hours or days to operate before anyone even knows something happened — because the person who could have triggered the incident response process was afraid to speak up.
The organisations with the strongest security cultures treat security mistakes the way aviation treats near-misses: as valuable data that makes the whole system safer. When someone reports that they clicked a suspicious link, the response should be: thank you for telling us, let’s check your machine now, here’s what we found. The person who reported is the hero of that story, not the villain.
This doesn’t mean there are no consequences for deliberate or repeated negligence. It means that honest mistakes, promptly reported, are treated as opportunities to improve — not as disciplinary events.
Building this culture requires explicit, repeated communication from leadership. It requires following through consistently. And it requires tracking your report rate as a key metric — because a rising report rate is one of the clearest signals that your security culture is actually improving.
Measuring Whether It’s Actually Working
If you can’t measure it, you can’t improve it. And too many security awareness programmes run on hope rather than data.
The metrics that actually tell you something useful:
Phishing simulation click rate over time. Is it going down? That’s progress. Is it flat or rising? Something needs to change. Break it down by department, by simulation type, by seniority level — the patterns tell you where to focus.
Phishing report rate. This is the metric that most programmes ignore and shouldn’t. How many people, when they receive a suspicious email, actually report it rather than delete it or click it? A rising report rate is a leading indicator of cultural change. People who report suspicious emails are actively engaged with security — that’s exactly what you want.
Time to report. When someone does report a suspicious email or a potential incident, how long does it take from the event to the report? Shorter is better. If people are sitting on concerns for days before saying something, there’s a barrier — cultural, process-related, or both — that needs to be understood and removed.
Training completion isn’t a metric. I’m including this explicitly because completion rates are what most programmes measure and report to leadership. Completing a training module proves someone clicked through slides. It proves nothing about learning or behaviour change. It’s a useful compliance metric and a useless security metric.
The data you collect should feed back into your programme. If one department consistently has higher click rates, they need different content or more frequent engagement. If report rates are low across the board, the reporting process is probably too complicated or the cultural barrier to reporting is too high.
The Bottom Line
Security awareness training works when it’s continuous, contextual, relevant, and connected to a culture where people feel safe reporting mistakes.
It doesn’t work when it’s an annual compliance exercise, delivered in generic modules, to a workforce that’s learned the fastest way through it is to click next until the quiz appears.
The technology matters. Firewalls, EDR, email gateways, MFA — all of it reduces risk. But as I’ve said before and will keep saying: the human layer is where most attacks start, and it’s the layer that technology alone cannot fully protect.
Investing in genuinely effective security awareness isn’t soft. It’s not the fluffy alternative to real security work. It’s one of the highest-return investments a security programme can make — because it changes the behaviour of every single person in the organisation, not just the ones with admin access.
Start there. Build from there. Measure relentlessly. And treat every mistake as a learning opportunity rather than a disciplinary event.
That’s how you move from a checkbox to a culture.
Majid Ahmed — CCIE #55880 | CISSP | PCNSE | Senior Network & Security Engineer Connect on LinkedIn