Security Awareness Training Should Change Behaviour, Not Tick a Box

Sep 8, 2026 | Education, Cybersecurity

Last week, we looked at Identity Threat Detection and Response and why a successful login cannot always be treated as a trusted login. This week, the focus shifts to Security Awareness Training and the part employees play in stopping those attacks before compromised credentials are ever used.

That raises an obvious question. If so many identity attacks begin with somebody being tricked into clicking, approving or entering something they should not, how much of the problem can technology solve on its own?

Not all of it.

Security Awareness Training, or SAT, exists because attackers know people are part of every business system. They do not need to defeat a firewall if they can persuade an employee to hand over a password, approve an MFA prompt or open the wrong attachment.

The problem is that a lot of security training has historically been treated as an administrative exercise rather than a security control.

Watch a video. Answer a few questions. Tick the box. Repeat next year.

That may satisfy a policy requirement, but it does very little if the employee cannot recognise the next convincing phishing email that arrives on a busy Tuesday morning.

Security Awareness Training Has to Resemble the Threat

Phishing has changed considerably from the badly written emails many people still associate with it.

Attackers can copy company branding, imitate Microsoft 365 login pages, register lookalike domains and build messages around real business situations. Generative AI has also made it easier to produce cleaner, more convincing language at scale.

The warning signs are not always obvious spelling mistakes.

Employees need exposure to the kinds of messages and decisions they may actually face. That could be a fake Microsoft 365 sign-in page, an unexpected QR code, a request to change banking details, a document-sharing notification or an MFA prompt they did not initiate.

The point is not to make everyone suspicious of every email.

It is to build the habit of slowing down when something feels slightly wrong.

A Simulation Is More Useful Than a Lecture

This is where phishing simulations become valuable.

A simulated phishing message gives employees the chance to encounter a realistic threat without the consequences of a real compromise. It also tells the business something a training completion report cannot.

What did people actually do?

Did they click? Did they enter credentials? More importantly, did they recognise the message and report it?

If several employees struggle with the same type of message, there is little value in simply recording that they "failed" a test. The better response is to use that moment for additional coaching while the experience is still fresh.

Security awareness should not be about catching employees out. If people feel that every simulation exists to embarrass or punish them, they will learn to resent the programme rather than learn from it.

The objective is improvement.

Training Should Follow Behaviour

Not every employee has the same level of risk.

Someone who routinely works with invoices and supplier banking information faces different threats from somebody who rarely handles financial information. An administrator with elevated access presents a different risk profile from a user with basic permissions.

Modern SAT platforms can use phishing results and other behaviour to identify where additional training is needed instead of giving every person exactly the same material indefinitely.

That is a much more sensible approach than assuming a once-a-year course has permanently solved the human side of cybersecurity.

Reporting Matters More Than Never Clicking

There is another behaviour businesses should encourage: reporting.

Even well-trained people will occasionally make mistakes. An employee may click a link before realising something is wrong, or enter information and only notice afterwards that the page looked unusual.

At that point, silence makes the situation worse.

Employees need to know that reporting a mistake immediately is far more useful than hiding it because they are worried about getting into trouble.

A quick report can give IT an opportunity to reset credentials, revoke sessions, inspect the account and contain the problem before an attacker has time to do much with it.

That connects directly back to ITDR.

Security Awareness Training helps the user recognise and report the threat. Identity Threat Detection and Response helps identify suspicious activity if the attack still succeeds.

Neither layer is perfect. Together, they make the organisation harder to exploit.

People Are Part of the Defence

There is a phrase that gets repeated constantly in cybersecurity: people are the weakest link.

It is not particularly helpful.

Employees are targeted because they have legitimate access and because their jobs require them to make decisions. Attackers take advantage of that.

The answer is not to treat users as a problem that needs to be controlled.

It is to give them enough practice to recognise when somebody is trying to manipulate the way they normally work.

Good Security Awareness Training does not turn accountants, receptionists or salespeople into security analysts. It gives them better instincts and a clear way to raise the alarm when something does not look right.

UIT helps businesses build security in layers, combining technology with practical controls that support the people using it every day. If you would like to review how security awareness fits into your organisation's wider cybersecurity strategy, get in touch through our Contact Us page.

This is the second article in our four-part September series on modern business cybersecurity.

Next week, we will move beyond individual users and identities to look at SIEM, and how bringing security information from different systems together can reveal an attack that no single alert tells you about on its own.

Explore More Insights

0 Comments