How to build a security awareness program that changes behaviour

by
Dawid Winiarski
Last update:
July 17, 2026

Security awareness training exists in almost every organization that has thought seriously about security. Most of it does not work. The evidence is straightforward: the same organizations running annual training continue to see credential phishing as the leading cause of breaches, year after year, per the Verizon DBIR.

The problem is design, not intent. Annual certification treats awareness as a compliance checkbox. Employees sit through a module, pass a multiple-choice test, and retain roughly as much as they would from any forgettable online course. When a real phishing email arrives six months later, the training is not in memory. This guide covers program architecture, phishing simulation design, the metrics that matter, how to handle repeat clickers without creating a punitive culture, and how to combine awareness with technical controls so your people are backed by the environment, not exposed by it.

  • Annual certification is the minimum, not the program. Continuous, role-relevant training is what moves behaviour.
  • Click rate is a lagging metric. Reporting rate is the leading indicator of a working program.
  • A realistic floor for phishing click rates exists regardless of training quality, so programs that aim for zero are optimizing for the wrong thing.
  • Punitive culture after failed simulations destroys the reporting behaviour you are trying to build. Just-in-time coaching works; public shaming does not.
  • Business email compromise, MFA fatigue attacks, and AI-assisted phishing are the current threat patterns. Simulations that only test obvious email forgeries are testing the wrong scenarios.
  • MFA and email security controls are partners to awareness training, not alternatives. People should not be the only line of defence.
  • Measuring program effectiveness requires tracking at least four metrics over time, not just click rates from the latest round.

why awareness training fails when it is an annual checkbox

Annual training fails for a structural reason: the gap between exposure and reinforcement is too long. Security skills, like any procedural skill, decay without practice. A module completed in January provides no useful muscle memory in October, when a well-crafted phishing email arrives during a busy product launch. The employee does not consult their notes; they act on instinct, which defaults to whatever feels most natural in the moment.

The second failure mode is relevance. Generic modules describe phishing in abstract terms, show obviously fake emails with poor grammar, and leave employees with the impression that phishing is easy to spot. Real phishing is not. Business email compromise emails are indistinguishable from legitimate communications, MFA fatigue attacks do not involve email at all, and AI-assisted voice impersonation does not look like anything on a screen. The third failure mode is the checkpoint mentality: when the goal is a completed certification, the program ends when the certificate is issued, with no follow-up and no visibility into whether the training changed any behaviour. Completion rates have no relationship to the likelihood that a real phishing attempt will be caught.

what good looks like: continuous, relevant, role-based, blame-free

A working program has four properties. Continuous: training and simulation happen throughout the year, with quarterly rounds a common starting cadence, because the goal is regular reinforcement, not volume. Relevant: content matches the threats actually in circulation and the employee's role, so finance members understand business email compromise and wire fraud, developers understand credential phishing targeting code repositories, and support staff recognize social engineering through support channels. Role-based: privileged users, administrators, finance approvers, and executives are higher-value targets facing more sophisticated attacks, and their scenarios should reflect that. Blame-free: the goal is to build reporting behaviour, and an employee who clicks and then feels embarrassed or fears consequences is less likely to report a genuine suspicious email later. Employees are not the problem; they are the detection layer. A workforce that reports fast contains incidents before they escalate, and a workforce that hides failures to avoid blame is the actual risk.

how to design a phishing simulation program

A simulation program has five components. Baseline measurement: run an unannounced simulation before any training changes, because programs that skip the baseline cannot demonstrate that training had any effect, and the click rate from a realistic, unwarned baseline is the number to compare all future rounds against. Scenario selection: the scenarios determine what you are actually testing, so effective ones use accurate sender formatting, contextually plausible content tied to a real upcoming approval cycle rather than a generic password-update email, and current attack types. Simulation frequency: quarterly is a practical and defensible cadence for most organizations, with monthly suiting higher-risk roles, set high enough to keep employees alert without creating fatigue that teaches them to ignore all email. Timing: simulations that run only during quiet periods test a different thing than real attacks, which happen at peak stress, so timing at least some to coincide with year-end, busy sales quarters, and significant organizational changes tests the actual condition. Response handling: what happens immediately after a click is critical, and the employee should receive a brief, educational, non-punitive response in the moment, called just-in-time coaching, which is the most effective moment for learning and the moment the program's culture is communicated.

scenarios to use: what attackers actually do now

Effective simulations cover the attack types in active use today, not a 2010-era picture. Credential phishing is the most common vector; Verizon DBIR consistently places stolen credentials among the leading causes of breaches, and scenarios should use realistic login page replicas for the tools employees actually use, testing whether they verify the URL and sender before entering credentials. Business email compromise impersonates executives, finance approvers, or trusted vendors with no malicious link involved, asking for a wire transfer, a payroll change, or a W-2 copy, and tests whether the employee verifies the request through a separate channel before acting, which matters most for finance, HR, and executive assistants. MFA fatigue assumes the attacker already has the password and sends repeated push notifications hoping the employee approves one; training focuses on the rule, never approve an MFA push you did not initiate yourself, and is a discussion-based exercise rather than a simulation with a landing page. AI-assisted phishing uses voice and video impersonation of known colleagues or executives, with the defence being multi-channel verification for any high-value or unusual request. Internal impersonation appears to come from IT helpdesk, HR, or internal systems, requesting password resets or access approvals, targeting employees trained to trust internal-looking communications without verification.

what to measure beyond click rate

Click rate is what most organizations report, and it is not the most important metric. Click rate, the percentage who clicked a simulated link, often falls meaningfully over the first year of consistent simulation, though a persistent floor of employees who click well-crafted scenarios exists regardless of training quality, so a realistic target is significant reduction from baseline, not zero. Report rate, the percentage who reported a suspicious email rather than ignoring or clicking it, is the leading metric, because a workforce that reports fast enables containment before damage occurs; a program that improves click rate while report rate stays flat has not built the behaviour that matters most. Repeat-clicker rate, the percentage who click across multiple consecutive rounds, signals that the training is not reaching that person effectively, and follow-up should be a separate, private conversation. Incident reduction, whether security incidents that begin with phishing are decreasing, is the hardest to measure directly but the most meaningful. Time-to-report, how quickly employees report after encountering something, matters because faster reporting means faster containment.

just-in-time coaching, not punishment

How a program responds to a failed simulation determines whether reporting behaviour increases or decreases. The punitive approach, a warning, a required remediation module, or a report to the manager, teaches employees that clicking on something suspicious has consequences, and that reporting something suspicious might draw the same scrutiny, so the logical response is to stay quiet about anything they are unsure of. The coaching approach gives the employee who clicks an immediate, brief, educational message explaining what made the email suspicious and where to report genuine ones, without assigning blame, treating the click as a learning moment. For repeat clickers, the follow-up is private, direct, and focused on understanding why the training is not working for that person, since some respond better to different formats. Leadership participation matters more than most programs acknowledge: when a failed simulation by a senior leader is handled the same way as one by a junior employee, the message reaches the organization that this is a shared responsibility.

building the awareness program around real risks

The topics should map to the actual risks facing the organization, not a generic curriculum. Credential phishing and password hygiene is the foundational, recurring topic: how attackers obtain credentials, what makes a login page suspicious, and what a password manager addresses. MFA, what it does and does not do: MFA blocks the large majority of automated account attacks (Microsoft data places this above 99.2% for account-compromise attacks), and employees should understand both why it matters and that MFA fatigue attacks bypass it because the employee approves the push. Business email compromise and wire fraud should be targeted at finance members, executives, HR staff, and anyone who processes payments, in a scenario-based format. AI-assisted social engineering training should include the verification principle: any request involving significant action is verified through a second channel regardless of how convincing the initial contact appears. Reporting culture is built across every round and every piece of content: if you see something suspicious, report it, with no consequence for reporting something that turns out legitimate.

combining awareness with technical controls

People should not be the only line of defence. MFA everywhere, deployed across email, VPN, cloud applications, and administrative consoles, reduces the impact of successful credential phishing; Microsoft data shows MFA blocks more than 99.2% of account-compromise attacks, so an employee who enters their credentials on a phishing page causes no breach if the account requires a second factor. Email security controls, DMARC, DKIM, and SPF, reduce the effectiveness of spoofed sender addresses, and anti-phishing filters and attachment sandboxing reduce the volume of successful phishing emails that reach inboxes. Privileged access management applies additional controls to administrator and privileged service accounts, separate credentials, just-in-time access, enhanced monitoring, limiting the blast radius of a successful attack on a high-value account. Incident response integration ensures employee reports route to a monitored queue and receive a consistent response, so the program has a feedback loop. The relationship is not either/or: organizations that run good technical controls and no awareness program still see incidents the controls miss, and those that run awareness with no technical controls leave employees as the primary backstop for everything.

common mistakes

Annual-only training with no simulation does not build the reflexes that matter, because the gap between the training event and the real attack is too long. Gotcha-style simulations that celebrate catch rates or share employee failure statistics publicly damage the culture they depend on. Vanity metrics, completion rates and click rates from obviously fake simulations, satisfy an audit requirement but do not tell you whether anyone can recognize good phishing. No leadership involvement signals that awareness is for individual contributors. Treating simulation as punishment gets the incentive structure backwards: employees optimize for passing simulations rather than for actually reporting. Simulating the wrong threats, testing only obvious phishing while BEC, MFA fatigue, and AI-assisted attacks are the active patterns, is training for the last war. And no technical backstop, running an awareness program without MFA and email security controls, places the entire burden on human behaviour.

how this maps to soc 2, iso 27001, nis2, and dora

Security awareness and phishing simulation appear across all four major frameworks, and the common requirement is that training is demonstrable, recurring, and effective. SOC 2's Trust Services Criteria (CC1.4, CC2.2) address security training as part of the control environment, and Type II auditors expect evidence of recurring training, simulation records, completion logs, and repeat-clicker follow-up, not just a policy. ISO 27001:2022 control 6.3 requires personnel to receive appropriate awareness education relevant to their function, with effectiveness evaluated, which a program with baseline measurement and documented metrics satisfies. NIS2 (Article 21) requires covered entities to address the human factor, including training on cybersecurity risks and practices, as part of a full risk management approach. DORA's ICT security requirements for financial entities (Article 9) include training and awareness, with emphasis on staff who access sensitive systems, making role-based training for privileged users and finance staff particularly relevant. All four treat awareness training as a program with measurable outcomes, not a certification exercise.

Subscribe to unshadowed.

Subscribe to receive the latest blog posts to your inbox and stay up to date with

By subscribing you agree to with our Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

let's start with a conversation

Most first conversations start with not quite knowing what you have or where to begin. That's normal, and it's exactly where we're useful.

Tell us what prompted this. An upcoming audit, an incident, a client's security questionnaire, or just a sense that things have gotten messy.

We'll take it from there

Julian Machowski
Head of Technical Sales
+48 783 762 997
julian@unshadowit.com
Let's connect on LinkedIn
Message received. We'll be in touch soon.
Something failed. Try again or call us directly.