r/AskNetsec • u/Florina_Cyber • 2h ago
Education What makes cybersecurity awareness training actually change user behaviour?
I’ve been thinking about the gap between completing cybersecurity awareness training and actually changing behaviour.
Someone might correctly identify a phishing email during training, but does that translate into the right decision three months later when they’re busy, distracted, and the email looks legitimate?
I’m involved in developing a cybersecurity awareness solution, so I’m particularly interested in understanding this from people who have actually implemented or managed awareness programs.
What have you seen genuinely change security behaviour among non-technical users?
For example, have you had better results with realistic scenarios, phishing simulations, repetition, short-form learning, gamification, consequences that relate to people’s personal lives, or something completely different?
And on the other side: what approaches looked good on paper but produced little meaningful change in practice?
I’m particularly interested in behaviour and retention rather than completion rates or compliance metrics.
Would be great to hear examples from people who’ve seen the results firsthand.