Awareness That Actually Changes Behaviour
- kind
- Reference
- domain
- People
- stage
- Programme design
- read
- 3 min
- assumes
- No prior programme in place
Annual training does not reduce incidents. The interventions that do are smaller, closer to the action, and less visible.
Most organisations run annual security awareness training, most people click through it, and incident rates do not move. That is a reasonably well-established outcome and it is worth designing around rather than repeating.
Why annual training fails
Timing. The gap between learning and the moment of decision is months. Nobody recalls a module while attaching a file.
Generality. Content covering phishing, passwords, physical security and data handling in forty minutes covers none of them usefully.
No consequence. Completion is the measured outcome, so completion is what people optimise.
Wrong audience model. It treats the problem as ignorance. Most data loss is not ignorance; it is a shortcut taken by someone who knew and was under pressure.
What works instead
Intervention at the moment of action. A prompt when someone is about to send a file externally: this appears to contain customer data, are you sure. Specific, timely, and it changes the decision rather than informing it months earlier.
This single mechanism outperforms every training programme, and it is a detection configuration rather than an awareness activity — which is why it usually sits in the wrong budget.
Removing the reason for the shortcut. People email files to personal accounts because remote access is slow. They use consumer file services because the corporate one cannot share externally. Fixing the tool eliminates the behaviour permanently; training asks people to tolerate the friction indefinitely.
Short, specific, repeated. Two minutes on one topic, four times a year, beats forty minutes annually.
Targeted to role. Finance, engineering and sales have different exposures and different legitimate workflows. Generic content is generic to everyone.
Named, local examples. An anonymised incident from your own organisation lands in a way that a generic scenario does not.
The departure conversation
The highest-yield awareness intervention available, and almost nobody runs it as one.
An explicit conversation at resignation about what belongs to the organisation — including work the person personally created — prevents a meaningful share of the incidents that would otherwise occur, because a substantial number of departing employees take material believing they are entitled to.
It costs fifteen minutes and it is more effective than the entire annual programme.
Tone
Do not lead with threat. Awareness material framed as warning produces defensiveness and, at scale, an adversarial relationship with the workforce.
Lead with the mistake case, which is what most people will actually experience. "Here is how to avoid sending the wrong attachment" is useful and true. "Insiders are stealing your data" is neither.
Say what the monitoring is for, plainly. Employees who understand the scope and its limits are considerably less hostile than those left to imagine it.
Measuring it
Completion rates measure nothing.
Repeat rate after intervention. Of the people who received a warning prompt, how many repeated within ninety days. This measures whether the intervention works.
Self-reporting. The number of people who report their own mistakes. A rising figure is good news, and organisations consistently misread it as deterioration.
Support requests for sanctioned alternatives. People asking how to share a file properly means the message reached them and the tool exists.
The thing to stop
Simulated phishing with punitive follow-up for people who click. It produces measurable click-rate improvement, a documented culture of blame, and employees who stop reporting genuine incidents because reporting has become risky.
The reporting rate matters more than the click rate, and the two move in opposite directions under that regime.