Select Page

An open letter to CISOs & Security Leaders

CYBSAFE-SebDB Webinar-preblog-221011MS-36

15 April 2025

The human side of cybersecurity is evolving. Fast.
But there’s a good chance you might be stuck in the past.

You probably have well-established views on security awareness, culture, and human risk.
You genuinely believe they matter.

But if we’re being honest – you mostly pay lip service to them.

And it’s not your fault. You mean well. You probably believe you’re doing what’s best.
But most of what’s being done today has little to no impact on actual people-related cyber risk.

Let’s be real.

For most organizations, security awareness training is treated as an administrative control.
Its stated purpose? Something like:

“To reduce human risk by influencing behavior, improving vigilance, and minimizing the likelihood of risky actions (e.g. falling for phishing, misconfiguring access).”

It’s embedded in frameworks like ISO 27001, NIST SP 800-53, and CIS Controls.
It shows up in every security strategy under some vague banner like “awareness, education, and training.”

So far, so predictable.

You know that tick-box training isn’t enough.
That’s why you’ve added simulated phishing – maybe to satisfy insurance requirements, maybe to feel a little more in control.

But deep down, you’ve been conditioned to believe that training + education + phishing simulations = effective security controls and human risk mitigated.

The evidence? Weak.

Your whole mental model (and approach to the human aspect of cybersecurity) is built on the unspoken dogma that “if users understand, care, or know enough – they will behave securely”.

Here’s the uncomfortable truth:
Behavior doesn’t change with knowledge alone.
And if behavior doesn’t change, your risk hasn’t either.

SAT completion rates and phishing click reports might look good on paper.
But they tell you very little about your real-world risk exposure.

You keep investing time and money into security education, believing it’s an effective control.
Because you’re busy. Because it’s familiar. Because it’s what everyone does.

But let me say this clearly:

Better awareness ≠ better behavior
Talking about culture ≠ reducing risk
Simulated phishing metrics ≠ meaningful insight

But, if knowledge != behavior change, why is the default security team response usually to subject the workforce to more learning and education? 

You’re not alone in making this mistake. It’s easy to confuse activity with impact.

Take a hard look at your current reporting:
Still relying on phishing click rates, report rates, and training stats?
Then you’re still in the old world.

Your team might say they’re focused on “security behaviors.” But chances are, they’re lumping together behaviors, attitudes, and vague notions of “culture.”
They’re trying. They care. But they’re stuck.

The good news? The world is changing.

What’s driving the shift?

  • Security leaders want proof—not intentions. Measurable impact, not effort.
  • Behavioral science and evidence-based practice are replacing assumptions.
  • Telemetry and analytics are showing us where risk actually lives.
  • Automation enables real-time, personalized intervention—at scale.
  • There’s increasing pressure to prove business value, not just run training programs.

The best teams aren’t treating people as the weakest link.
They’re treating people as dynamic, context-dependent actors in the security ecosystem.

They’re not just raising awareness.
They’re using data, automation, and behavioral science to understand, measure, and reduce human risk.

Let’s call it what it is:
A shift from security awareness training to human risk management.

Old world:
SAT programs aim to educate users. They’re compliance-driven. Centered on communication, not outcomes. Focused on knowledge, not behavior.

New world:
Human risk management starts with the belief that knowledge alone isn’t enough.
It’s a mindset shift. A strategy shift. A technology shift.

It uses data to pinpoint risky behaviors in real time.
It uses automation to deploy personalized, adaptive interventions.
It reduces incidents, lightens workloads, and frees up your team to focus on what matters.

This isn’t semantics. Despite what the pessimists, doomerists and cynics say.
It’s a fundamental evolution in how we protect our people—and our organizations.

Because in today’s world, knowing isn’t enough.
Understanding and influencing behavior is the new frontier in cybersecurity.

If you remember nothing else, remember these four things:

  1. Knowledge != behaviour change, so don’t just default to more training, education or comms. Consider more effective interventions.
  2. You must focus on and measure individual security behaviors – or accept you have no idea whether you’re being effective.
  3. Move beyond phishing simulations. Many other behaviors contribute to incidents – don’t ignore them.
  4. Your workforce needs timely, relevant support. Give it to them.

The future of cyber risk reduction isn’t more training.
It’s smarter intervention, powered by science, data, and automation.

It’s time to evolve.
Are you ready?

 

 

Want a deeper look into how the human aspect of cybersecurity is evolving? Check out these links below:

 

Behave Hub newsletter CybSafe

Do one more thing right today. Subscribe to the Behave newsletter:

You may also like

Why security awareness still isn’t taken seriously (and how to fix it)

Why security awareness still isn’t taken seriously (and how to fix it)

Let’s start with a painful truth:Security awareness, culture, and human risk professionals are often undervalued. Despite the rising threat of human-enabled cyber attacks, many organizations still treat addressing the human aspect as a checkbox. A communications initiative. A nice-to-have....

Security metrics reboot: Less input, better output, real outcomes

Security metrics reboot: Less input, better output, real outcomes

Unfortunately, most security awareness professionals don’t really understand the difference between: ✅ Inputs✅ Outputs✅ Outcomes But they don’t want to admit it. And honestly? We get it. It’s like pretending to know the plot of Inception when deep down, you’re just as confused as everyone else. No...

The dogma of security awareness: Exposing cybersecurity’s biggest blind spot

The dogma of security awareness: Exposing cybersecurity’s biggest blind spot

“Humans are the weakest link.”“Security Awareness training = better behaviour”"If we can nail engagement, we’ll nail risk reduction.""Security Awareness is *actually* about so much more than awareness.”“Security culture is the golden ticket to risk reduction.”“Good communication, messaging,...

Can BS make SA&T stick? Hot takes from the experts…

Can BS make SA&T stick? Hot takes from the experts…

Using insights from “Oh, Behave!” to strengthen security training and drive lasting behavioral change Security training. It’s as commonplace in an organization as writing “see attached” and forgetting to attach anything. It can help to tackle cybersecurity risks—but only when done well. Simply...

Maximizing security awareness engagement: How the pros do it

Maximizing security awareness engagement: How the pros do it

Ditch mandatory training, starting riiiight…now!Want to boost security awareness? Talk about something else entirelyGet serious about funThe top mic-drop insights from our Cybersecurity Awareness Month engagement webinar We know people whose organizations make a big deal of CAM are much more...