Table of Contents
- Why More Training Doesn’t Always Mean Less Risk
- Making the Most of the Moment
- Better Targeting Depends on Better Visibility
- Creating a Clearer Link Between Training and Behaviour
- Evolving Security Awareness Without Starting Again
- Right Message. Right Moment. Real Impact.
- Build a More Responsive Approach to Human Cyber Risk
- FAQs
Security awareness programmes have traditionally followed a fairly predictable calendar. There’s annual training to cover the essentials, phishing simulations at regular intervals and campaigns throughout the year to reinforce important topics or keep employees up to speed with emerging threats.
Of course, employees need regular reminders to keep cyber security front of mind and refresh what they’ve learned, but relying too heavily on a schedule can create a gap between when training happens and when employees actually need to put it into practice.

Cyber risk doesn’t wait for the next training module, it shows up in the middle of a busy working day, when someone receives a convincing phishing email while trying to get through an overflowing inbox. It might be an unexpected payment request or an urgent message that appears to have come from a senior colleague. These are the moments when employees need to recognise the risk and make the right call, often in a matter of seconds.
Someone might have covered that exact scenario in training a few months earlier, but how much of it will come to mind when they’re busy, distracted or under pressure?
For security leaders, that makes timing an important part of the conversation around training relevance. We already know that employees are more likely to engage with security education when it reflects the risks they face in their day-to-day role. The next question is whether we can make that education even more useful by delivering it closer to the moment it’s needed.
Our Rethinking Human Cyber Risk research suggests CISOs see a real opportunity here. Three-quarters say relevance matters more than frequency when it comes to driving secure behaviour through security awareness training, while 83% believe they could reduce human cyber risk faster if they had better ways to prioritise who needs which intervention, and when.
Why More Training Doesn’t Always Mean Less Risk
It’s easy to assume that more security awareness activity will lead to better security behaviours. More courses, more simulations and more communications mean employees are seeing more security messages, so surely some of that must translate into less risk?
Unfortunately, it’s not that simple. Our research found that employees now receive security awareness content an average of six to seven times a month, yet 81% of CISOs say training still fails because it’s too generic to feel personally relevant.
When you think about the different people and roles within an organisation, it’s easy to see how that happens. Someone working in finance might spend their day dealing with invoices, payment requests and emails from senior leaders, making impersonation and business email compromise particularly relevant. Someone in HR is handling sensitive employee information, while developers and employees with privileged access will face a completely different set of risks again.
Individual behaviour adds another layer. One employee might be very good at spotting suspicious emails but struggle with other areas of security, while somebody else might repeatedly fall for the same type of phishing technique. Giving both people exactly the same training at exactly the same time might be convenient, but there’s a good chance some of that education won’t feel particularly useful to either of them.
Better targeting gives security teams the chance to be much more selective. Who actually needs support? What do they need help with? And when would that support be most useful? Answering those questions can make every piece of training work harder without continually adding more content to employees’ workloads.
Making the Most of the Moment
Take a phishing simulation as an example. An employee clicks a link they shouldn’t have, giving the security team a useful signal about where they might need some additional support. This creates a really valuable learning opportunity because the scenario is still fresh in that employee’s mind.
Follow that experience up soon afterwards with relevant education and there’s a much stronger connection between the two. The employee can see the warning signs they missed, understand why the email was suspicious and learn what they could do differently next time. That context can make the learning feel far more useful than covering the same phishing technique several months later in a general training module.
This is where flow-of-work interventions come in. Behavioural and risk signals can help organisations identify opportunities to provide additional support when it’s most relevant, rather than waiting until the next activity on the awareness calendar.
A phishing simulation failure, for example, could trigger short training related to the technique the employee has just encountered. A team being targeted by a particular type of attack could receive education designed around that threat, while employees showing recurring risky behaviours might benefit from additional support or reinforcement.
Of course, nobody wants employees receiving a training notification every time they do something that generates a risk signal; that’s a quick route to even more training fatigue. The value comes from using the information you already have about your employees to make smarter choices about when an intervention would genuinely be useful and what that intervention should look like.
Better Targeting Depends on Better Visibility
For any of this to work, security teams need to know where human cyber risk is concentrated across the organisation, and that’s an area where many are still struggling.
Our research found that 76% of CISOs don’t have a clear picture of which interventions work best for different roles or risk profiles. Yet 81% agree that better targeting is the answer to improving security awareness, highlighting a significant gap between where organisations want to go and the visibility they have today.
Building that visibility means looking across the different signals already being generated by employees and security programmes. Phishing simulation results, training activity and wider behavioural or security signals can all help build a clearer picture of where risk sits, which groups might need more support and how that picture changes over time.
Once security teams have that understanding, they can be far more deliberate about what happens next. A group demonstrating higher risk around a particular threat can receive education that addresses it directly, while employees who consistently demonstrate strong security behaviours might need less intervention.
It also gives organisations a better foundation for answering a much bigger question: is the awareness programme actually reducing risk?
Creating a Clearer Link Between Training and Behaviour
Security teams certainly aren’t short of data. Training completion rates, phishing clicks, reported emails and plenty of other metrics can all be tracked and added to a dashboard. The harder part is working out what those numbers really tell you about whether people are changing their behaviour.
That challenge came through strongly in our research. Almost three-quarters (74%) of CISOs say their current human cyber risk reporting gives them dashboards without enough of a clear understanding to make better decisions. Even more strikingly, 89% can’t confidently link awareness activity to reductions in incidents or near misses.
Timely, targeted interventions can help make that connection easier to see. If a particular behaviour leads to an intervention, security teams can then look at what happens afterwards. Perhaps an employee becomes better at spotting the phishing technique they previously struggled with, a higher-risk group improves over several simulations or reporting behaviour starts to change after targeted education.
Looking at those patterns over time can tell security teams much more about whether an intervention has worked and where they might need to adjust their approach. It also makes it easier to focus time and budget on the activities that are having the greatest effect.
That’s particularly valuable when CISOs are being asked to justify what they spend. Our research found that 77% are expected to prove ROI more rigorously for human cyber risk initiatives than they are for technical controls. Being able to show how an intervention influenced behaviour gives security leaders a much stronger story to take to the board than completion rates alone.
Evolving Security Awareness Without Starting Again
All of this might sound like a big change, but organisations don’t need to rebuild their security awareness programmes from scratch. In fact, our research suggests that most CISOs would rather evolve what they already have through pilots and incremental improvements.
Phishing simulations can provide a practical place to begin. Organisations might start by connecting simulation outcomes with relevant follow-up education and looking at whether employee behaviour improves afterwards. From there, they can introduce more role-specific education, use group-level risk scoring to help prioritise interventions and bring in a wider range of behavioural signals as their approach matures.
These changes can happen gradually, building on the training and awareness activity already in place. Over time, the programme becomes more responsive to what employees are experiencing and where risk is appearing across the organisation.
Right Message. Right Moment. Real Impact.
Security awareness still needs consistency. Employees need regular opportunities to refresh their knowledge, learn about emerging threats and keep security front of mind. But there’s much more organisations can do with the moments in between those scheduled activities.
When someone demonstrates a risky behaviour or a particular group starts to show signs of increased risk, there’s an opportunity to respond while that support is relevant. With better visibility, security teams can understand where those opportunities are and make much more informed decisions about the education they provide.
It also creates a much tighter connection between awareness activity and the wider management of human cyber risk. Security teams can identify where risk is concentrated, decide where to focus their efforts, see how behaviour changes and use those results to shape what happens next.
Ultimately, every organisation has a limited amount of time, budget and employee attention to work with. Making security education more relevant and better timed gives security teams a chance to use all three more effectively, while giving employees support that makes sense in the context of their working day.
Build a More Responsive Approach to Human Cyber Risk
MetaCompliance helps organisations build security awareness programmes around the risks their employees really face. Personalised security awareness training, advanced phishing simulations, real-time risk intelligence and automated interventions help security teams understand where support is needed and deliver relevant education based on employee risk and behaviour.
This gives organisations greater visibility into human cyber risk and more control over how they respond, helping them make better use of behavioural signals, target interventions more effectively and measure how risk changes over time.
This is just one part of a much bigger shift in how organisations are thinking about human cyber risk. Our research explores the wider challenges security leaders are facing, from making training more relevant and understanding which interventions work, to measuring behaviour change and demonstrating the value of security awareness at board level.
Download our full Rethinking Human Cyber Risk report for all the insights from 200 CISOs across France, Germany, Sweden and the UK, along with practical guidance on how organisations can evolve their approach and build a more targeted, measurable and effective human risk management strategy.
FAQs
What Are Flow-of-Work Interventions in Security Awareness?
Flow-of-work interventions are targeted security education or guidance delivered in response to an employee’s behaviour, risk profile or a relevant security signal. For example, an employee who interacts with a phishing simulation could receive immediate training related to the technique they encountered. This helps connect security education to a real and relevant moment rather than relying solely on scheduled training.
Why Is Relevance Important in Security Awareness Training?
Relevant security awareness training reflects the risks employees are likely to encounter based on factors such as their role, responsibilities and behaviour. MetaCompliance research found that 81% of CISOs believe security awareness training fails because it’s too generic to feel personally relevant, while three-quarters say relevance matters more than frequency in driving secure behaviour.
What Is Behaviour-Triggered Security Awareness Training?
Behaviour-triggered security awareness training uses an employee’s actions or security signals to determine when additional education may be useful. Rather than giving every employee identical training, organisations can respond to specific behaviours with relevant learning designed to address the risk demonstrated.
How Can Organisations Measure the Effectiveness of Security Awareness Training?
Organisations can look beyond completion rates and individual phishing click rates to examine whether behaviour and risk change over time. This could include monitoring repeat risky behaviours, phishing susceptibility, reporting behaviour and changes across different risk groups following targeted interventions. This is particularly important given that 89% of CISOs surveyed by MetaCompliance couldn’t confidently link awareness activity to reductions in incidents or near misses.
How Can Organisations Make Security Awareness Training More Effective?
Security awareness training can become more effective by making education relevant to employees’ roles and risks, using behavioural signals to identify where additional support is needed and delivering interventions at appropriate moments. Rather than simply increasing training frequency, organisations can use a more targeted approach to focus resources where they’re most likely to influence behaviour. MetaCompliance research found that 83% of CISOs believe they could reduce human cyber risk faster if they had better ways to prioritise who needs which intervention, and when.