Table of Contents
- Why More Training Becomes the Default
- The Cost of Over-Training Employees
- Why More Activity Doesn’t Guarantee Less Risk
- What Targeted Security Awareness Looks Like
- Six Ways to Make Security Awareness More Relevant
- How MetaCompliance Helps Make Security Awareness More Targeted
- FAQs
Security teams have spent years trying to solve a difficult problem: how do you keep cyber security front of mind when employees already have countless other priorities competing for their attention?
For many organisations, the answer has been frequency. More training, more reminders, more phishing simulations and more awareness campaigns create more opportunities to reinforce secure behaviour.
Our latest research suggests organisations may already be reaching the limits of that approach. Employees now receive security awareness content an average of six to seven times per month, yet 75% of CISOs still believe employees don’t fully understand their role in preventing security incidents. At the same time, three-quarters of CISOs say relevance matters more than frequency when it comes to influencing secure behaviour through training.

When every employee receives broadly the same training regardless of their role, behaviour or level of risk, increasing the volume can quickly become counterproductive. Employees tune out, security teams spend time delivering activity that may have little impact, and organisations struggle to understand whether their investment is really reducing risk.
A mature security awareness programme is therefore not about doing more training, but making training more relevant to the people, behaviours and risks that matter most.
Why More Training Becomes the Default
Most security teams don’t deliberately set out to overwhelm employees. High-volume programmes are often the result of sensible individual decisions that gradually accumulate.
A new threat emerges, so another piece of training is added to the programme. A phishing campaign identifies a weakness, so another simulation is scheduled. A regulatory requirement needs addressing, so another mandatory module appears. Cyber Security Awareness Month arrives and another campaign joins the calendar.
Each activity has a valid purpose, but collectively they create a programme focused heavily on delivery.
Our Rethinking Human Cyber Risk research found that despite employees receiving security awareness content six to seven times per month, no organisations surveyed reported delivering content dynamically based on live threats or real-time risk signals. In many cases, programmes remain broad and generic, designed around coverage rather than individual risk.
That makes frequency an easy lever to pull. If an organisation isn’t confident that employees are changing their behaviour, adding another campaign feels like action. The problem is that the employee who consistently demonstrates secure behaviour may receive the same intervention as someone repeatedly showing signs of higher risk.
The Cost of Over-Training Employees
The most obvious consequence of excessive security communication is training fatigue. Employees have finite attention, which means when awareness messages repeatedly feel generic or irrelevant to their work, they become easier to dismiss. A training notification becomes another task to complete, while a security message becomes another email competing for space in an already crowded inbox.
Our research helps explain why. 81% of CISOs say security awareness training fails because it’s too generic to feel personally relevant.
There’s also a cost for the organisation. Creating, managing and delivering awareness campaigns requires budget and security team capacity. In addition, 77% of CISOs say they’re expected to prove ROI more rigorously for human cyber risk initiatives than for technical controls. Yet only 39% feel completely confident explaining the value of security awareness initiatives to their board or C-suite.
When resources are being used to repeatedly train low-risk employees alongside those who genuinely need intervention, demonstrating that value becomes harder. A more targeted approach gives security leaders an opportunity to make better use of both employee attention and security investment.
Why More Activity Doesn’t Guarantee Less Risk
One reason training volume persists is that awareness activity is relatively easy to measure. Training completion rates can show that 98% of employees completed a module, phishing simulations can produce a click rate, and campaign dashboards can demonstrate how many people received an awareness communication.
Our research found that 70% of CISOs say their systems rely on activity metrics like these. However, 74% say their current human cyber risk reporting produces dashboards without enough understanding to make better decisions, while 89% can’t confidently link their awareness activity to reductions in incidents or near misses.
That creates a difficult cycle. Organisations can see that training happened, but have less visibility into whether it changed behaviour or reduced risk. Without that insight, increasing awareness activity can become the default response.
To break this cycle, security teams need to look beyond how much training they’re delivering and develop a clearer picture of where intervention will have the greatest impact.
What Targeted Security Awareness Looks Like
A more targeted approach begins by recognising that employees don’t present identical levels or types of cyber risk.
Consider two employees. One works in Finance, has access to payment systems and has recently interacted with a simulated invoice phishing email. Another works in a role with limited access to sensitive systems and consistently reports simulated phishing attempts.
Sending both employees another generic phishing module may satisfy a training requirement, but it doesn’t make particularly efficient use of either employee’s time.
Relevant interventions could look very different. The Finance employee might benefit from immediate learning based on invoice fraud, alongside phishing simulations that reflect the payment requests they regularly encounter. The second employee may need little additional intervention beyond the organisation’s core awareness programme.
Role, department, access, previous behaviour and other risk signals can all help organisations make those decisions more intelligently.
Our research found that 83% of CISOs believe they could reduce human cyber risk faster if they had better ways to prioritise who needs which intervention and when. Yet 76% say it’s currently unclear which interventions work best for different roles or risk profiles.
The challenge, then, is turning that principle into a security awareness programme that can respond to differences in risk without creating more work for security teams.
Six Ways to Make Security Awareness More Relevant
Moving away from blanket security awareness doesn’t mean abandoning regular training or rebuilding an entire programme from scratch. Organisations still need baseline awareness activity to communicate policies, meet regulatory requirements and establish shared security expectations.
The opportunity is to build greater intelligence and relevance around that foundation.
- Start With Role and Exposure: The risks an employee encounters are heavily influenced by what they do. Finance teams may be targeted with invoice fraud and business email compromise. IT administrators may have privileged access that makes compromised credentials particularly valuable, while senior leaders are attractive targets for impersonation and sophisticated social engineering. Security training can reflect those differences. Rather than giving every employee identical scenarios, organisations can use role, department and access to determine which threats deserve more attention.
- Use Behaviour to Identify Who Needs More Support: An individual’s role can tell security teams something about their exposure, but behaviour can provide another layer of context. Phishing simulation results, reporting behaviour, previous training activity and other risk indicators can help identify where additional intervention may be useful. An employee who repeatedly interacts with simulated phishing attempts may require different support from someone who consistently identifies and reports them. This helps organisationsfocus training where it has the most potential to reduce risk, while avoiding unnecessary additional training for employees already demonstrating secure behaviour.
- Make Phishing Simulations Reflect Real Environments: A generic phishing email can test whether an employee recognises familiar warning signs, but relevance becomes much stronger when a simulation reflects the requests that person could realistically receive. For a Finance employee, that might mean a payment request or invoice. For HR, it could involve a CV or benefits communication. Senior leaders may encounter scenarios involving urgent requests or impersonation. Making simulations more representative of real situations helps employees practise making secure decisions in a context they recognise, rather than treating phishing exercises as separate from their day-to-day responsibilities.
- Intervene Closer to the Point of Risk: Timing can be just as important as content. If an employee demonstrates risky behaviour today, waiting weeks for the next scheduled awareness campaign can remove much of the context that made the learning relevant in the first place. Where possible, organisations can use behavioural and risk signals to trigger learning closer to the moment it’s needed. That might mean additional support following a phishing simulation, targeted content in response to an emerging threat or an intervention when a particular risk pattern appears. This makes it easier for employees to connect training with the situation it’s designed to address.
- Keep Baseline Training, Then Build Targeting Around It: Not every piece of training needs to be individually personalised. Organisations still need a core programme covering policies, fundamental security behaviours, regulatory requirements and threats that affect the wider workforce. That creates a baseline. Targeted interventions can sit around that foundation, giving additional support to employees, roles or departments where risk signals indicate it will have the most value. This creates a more proportionate model: everyone receives the security awareness education they need, without assuming everyone requires the same interventions.
- Measure Behaviour, Not Just Activity: Organisations need to understand whether targeting is making a difference. Completion rates, campaign delivery and phishing click rates are useful, but they provide only part of the picture. Security teams also need to know how behaviour changes over time, where risk is concentrated and whether specific interventions are producing better outcomes. That means connecting awareness activity with risk data rather than viewing each campaign in isolation. There’s appetite for this shift. 81% of CISOs agree that better targeting is the answer, while 80% would invest more in awareness content designed for specific roles and risk profiles. The goal isn’t necessarily to send employees less security awareness content. It’s to make sure the interventions they receive have a reason for being there.
How MetaCompliance Helps Make Security Awareness More Targeted
Moving towards a more targeted approach requires more than creating additional variations of the same training content. Security teams need visibility into human cyber risk, the ability to understand where that risk is concentrated and practical ways to respond.
Our Human Risk Management platform brings those capabilities together, combining adaptive and personalised cyber security learning, advanced phishing simulations, behavioural insights, real-time risk intelligence and automated interventions. This helps organisations identify who’s most at risk, understand why and deliver targeted support before risky behaviour becomes an incident.
Rather than relying on blanket campaigns as the primary way to manage human risk, security teams can use role and risk information to personalise learning, run more relevant phishing simulations and automate interventions based on the behaviours that matter. They can also build a clearer picture of human risk across the organisation, helping them prioritise resources and demonstrate how their programme is evolving over time.
With more than 20 years of cyber security awareness expertise and over nine million users worldwide, we’re here to help organisations build on the awareness programmes they already have and develop a more targeted, measurable approach to human risk management.
Want to understand where your current approach could evolve? Download our Rethinking Human Cyber Risk report to discover what 200 CISOs across the UK, France, Germany and Sweden told us about the future of security awareness and human risk management.
Or book a demo to see how personalised learning, phishing simulations, behavioural insights, real-time risk intelligence and automated interventions can help you target the right people with the right support at the right time.
FAQs
What Is Targeted Security Awareness Training?
Targeted security awareness training uses information such as an employee’s role, department, access, behaviour and exposure to particular threats to determine which security interventions are most relevant. Instead of relying entirely on blanket training for the whole workforce, organisations can provide additional support where risk indicates it is needed.
Can Employees Receive Too Much Security Awareness Training?
Regular security awareness is important, but repeatedly delivering generic or irrelevant content can contribute to training fatigue. Employees may begin treating security communications as routine tasks rather than information that deserves their attention. The focus should therefore be on making interventions relevant and useful rather than simply increasing frequency.
Does Targeted Training Replace Organisation-Wide Security Awareness?
No. Organisation-wide training remains important for communicating policies, meeting regulatory requirements and establishing baseline security knowledge. Targeting adds another layer, allowing organisations to provide additional or more specific interventions according to role, behaviour and risk.
How Can Organisations Make Phishing Simulations More Relevant?
Phishing simulations can be adapted to reflect the threats different employees are likely to encounter. Finance teams, for example, may receive scenarios involving invoices or payment requests, while HR teams could encounter recruitment-related phishing. Behaviour from previous simulations can also help determine where additional support is required.
How Do You Measure Whether Security Awareness Training Is Working?
Completion rates and phishing simulation results provide useful information, but organisations should also look at behavioural and risk signals over time. This can help security teams understand whether interventions are changing behaviour, where risk remains concentrated and which approaches are producing the strongest outcomes.