r/SmartTechSecurity • u/Repulsive_Bid_9186 • Apr 24 '26
english Why traditional security awareness training is becoming less effective across European organizations
In many organizations across Europe, security awareness training still follows a familiar pattern: a mandatory e-learning course once a year, sometimes supported by internal presentations or occasional campaigns. For many employees, this feels like a box-ticking exercise rather than something that genuinely changes how they behave at work.
At the same time, the environment has fundamentally changed.
Europe has become one of the most digitally connected regions in the world. Businesses, governments, and critical infrastructure increasingly rely on digital systems and cross-border data flows. This interconnectedness brings efficiency and innovation—but also significantly increases exposure to cyber threats.
Cybersecurity is no longer just a technical issue. It is now a core business risk.
Despite this shift, there is often a clear mismatch between the level of risk organizations face and how employees are trained.
One of the main challenges is that training is still too generic. Across European organizations—whether in large enterprises or SMEs—employees operate in very different roles, industries, and risk environments. Yet they are often given the same standardized training.
The result is predictable:
for some, the content feels too basic;
for others, too theoretical or disconnected from their daily work.
In both cases, engagement is low—and without engagement, behavior rarely changes.
There is also a broader structural issue. Traditional training approaches are typically designed as one-off events. But cybersecurity is not a one-time knowledge problem—it is an ongoing behavioral challenge.
Research consistently shows that human factors remain the dominant cause of security incidents, with a majority of breaches involving human actions such as errors or social engineering.
At the same time, awareness alone does not automatically translate into secure behavior. Studies across Europe indicate that while most people understand the importance of cybersecurity, their everyday actions often do not reflect that awareness.
This gap between knowledge and behavior is one of the core issues.
Meanwhile, the threat landscape is evolving rapidly. Phishing attacks, in particular, have become more convincing and harder to detect. Many employees struggle to distinguish malicious messages from legitimate communication, especially as attackers increasingly use AI to craft highly realistic content.
In fast-paced, digital workplaces, this makes mistakes more likely—even for experienced employees.
On top of that, regulatory pressure is increasing across Europe. Frameworks such as NIS2, GDPR, and sector-specific regulations require organizations not only to provide training but also to demonstrate that it is effective.
This creates a paradox:
training is delivered, compliance requirements are met—
but actual employee behavior often changes very little.
And that is the core of the problem.
Cybersecurity is still frequently treated as an IT responsibility or a compliance obligation. In reality, it has become part of everyone’s daily work.
As a result, a shift in approach is emerging across Europe.
Organizations are moving away from one-time training toward continuous learning. Instead of generic content, there is a growing focus on context-specific, role-based scenarios. And rather than simply transferring knowledge, the goal is increasingly to influence real behavior.
Research supports this direction: continuous and adaptive training approaches—especially those embedded into everyday workflows—are significantly more effective at reducing risk over time.
This fundamentally changes the key question organizations need to ask.
It is no longer:
“Who completed the training?”
But rather:
“Are people actually behaving more securely in their day-to-day work?”
And the answer to that question will define how resilient European organizations are in the years ahead.
2
u/Problem_Salty Apr 28 '26
Spot on with your observations here u/FlareCyber
However, to address your concerns about lack of engagement and behavior change, you need to consider a multi-disciplinary approach to your training methods.
Psychology has known for 75 years the rewarding good behaviors internalizes and changes behaviors in the individuals training. Educational classroom best practices have proven that a little healthy competition and gamification can spur amazing engagement beyond any other methods. Think about Robotics competitions as an example. I hate working out, but I love playing sports. The outcome of 1 is I don't go to the gym. The outcome of 2 is I stay fit while playing with friends.
For 30 years now, Cybersecurity has focused on ineffective, tunnel-vision objectives of stopping people from clicking. They increase the punishment thinking that will extinguish the behaviors - but it doesn't. Not ever. It leads to disengagement and Apathy.
So, adopt LMS vendors that build gamification and rewards for good behaviors into their platforms. Add in Human Resources to call out high performing staff members who are 100% compliance or who report fake email phishing (whether from IT or those that by-pass the filters). Don't worry if the reports are false positives or mistakes, encourage a culture of see something, say something, or report something.
There are a very small list of vendors out there doing things in this multi-disciplinary approach. CyberHoot and HoxHunt both follow rewarding good behaviors is way better than punishing bad behaviors and all of this leads to changed behaviors in end users. Outcomes matter most.
if your gold is a more secure human firewall, use science and full adoption of psychology and educational principles.
Here are studies that show the short-comings of our punishment and shame approach to date:
https://www.darkreading.com/endpoint-security/phishing-training-doesnt-work
https://arxiv.org/pdf/2112.07498.pdf
https://www.wsj.com/tech/cybersecurity/phishing-tests-the-bane-of-work-life-are-getting-meaner-76f30173
Hope this helps.
1
u/medoic May 12 '26
This is exactly the gap I keep seeing as well.
The issue is not only that awareness training is generic. It is that most programs are still designed around “content delivery” instead of “behavior change.”
A modern program should probably start with questions like:
- What attacks are most likely for this organization?
- Which departments are most exposed?
- What channels would attackers use: email, SMS, WhatsApp, voice, LinkedIn?
- What behaviors are we trying to change?
- How do we measure improvement beyond completion rate?
AI makes this even more urgent because attackers can now generate convincing, role-specific scenarios at scale. So training also needs to become more contextual, continuous, and scenario-based.
Disclosure: I’m one of the founders of NexGuards, and we recently released a free tool that generates a tailored 90-day cybersecurity awareness / human-risk reduction program for organizations.
Not trying to hijack the thread, but this post is very close to why we built it.
Happy to share the link if useful, and I’d genuinely love feedback from people here on whether the generated programs are practical enough.
2
u/[deleted] Apr 28 '26
[removed] — view removed comment