Because if it’s not personal, it’s unlikely to work
The Human Perimeter is still critically important in the security mix, made even more urgent by the surge in AI aided crime.
But in spite of billions of dollars in spending every year, employee security awareness training seems to be making little difference in improving either security or awareness, an assertion supported by one of the biggest experiments of its kind.
- The main culprit could be the false notion that the way to change habits, which is the goal of awareness training, is through frequent training and testing.
- One leading behaviorist labels the failure as “the information action fallacy,” that training can’t change habits (it can only change things like skills, perception, and opinions), and that the only way to make employees change their habits is to give them a strong, personal, and emotional motivation to do so.
- Things like policies, compliance, and phishing tests are not motivational.
- If we want to make security awareness work, or just work better, we have to take some lessons from the personal motivation we commonly see in consumer security.
The best and perhaps only way to make security awareness work, to change user security habits, is to make it personal. We have to bring in the grandparents.
The Information Action Fallacy
Most security awareness training could be flawed and failing because of one fundamental reason. The focus on training. The leading behaviorist and habit expert BJ Fogg describes it as the “information action fallacy” – the false notion that pushing any amount of training information on employees is going to change their behavior and habits, make them more security aware and vigilant.
Training has only been shown to improve things like knowledge, opinions, perspective, and skills, but not habits.
Fogg is Director of Stanford University’s Behavior Design Lab, an expert on human behavior and habits, and author of the New York Times bestseller “Tiny Habits.”
For decades, maybe longer, people have assumed that if you just give people information it will change their behavior. And this doesn’t work very well.
The Limitations of Training
The information action fallacy could be the reason why employee security awareness training is one of the most frustrating of all security disciplines and for numerous different reasons. And while some organizations seem happy with the effectiveness of their training, most seem to agree that its effectiveness is questionable at best.
One of the biggest and most recent studies of its kind, a 2025 study by UC San Diego Health that included a series of phishing campaigns that involved nearly 20,000 students over eight months found that:
- 75% of users engaged with the embedded training materials for a minute or less.
- One-third immediately closed the embedded training page without engaging with the material at all.
- Embedded phishing training only reduced the likelihood of clicking on a phishing link by 2%.
Overall, the study found that the difference in failure rates between employees who had completed the training and those who did not was extremely low.
Taken together, our results suggest that anti-phishing training programs, in their current and commonly deployed forms, are unlikely to offer significant practical value in reducing phishing risks
Grant Ho, co-author of the study.
Harnessing the Personal
There is hope and it’s in abundance in another security discipline – consumer security. I spent more than two decades teaching consumers about how to protect themselves from cybercrimes and scams, and as head of the Identity Theft Council I helped to support thousands of victims of these scams.
I also served as advisor to consumer security companies that between them protected more than 30 million customers around the world.
And I was always amazed at how quickly and permanently consumers would change their behavior, choices, and habits when they or a family member fell victim to a crime, or even experienced a near miss.
For example:
- I’ve seen countless cases when a relatively mild instance of something like credit card misuse, even where the victim wasn’t out any money, triggered an instant raft of often permanent changes.
- Victims would power through the checklist I gave them – checking credit reports and credit card statements, placing fraud alerts or more permanent credit freezes, changing passwords, enabling MFA where they had previously shunned it and overall embracing a much more heightened sense of awareness and vigilance.
- And not just doing it for themselves but making sure immediate and especially older family members were doing the same, and even evangelizing their newfound awareness to friends and neighbors.
In many of those cases, the changes were driven less by the fraud and much more by the anger that some stranger would even attempt such a thing. And especially if they were targeting their elderly parents or grandparents.
We can ignite that same passion and motivation in the workplace simply by reminding employees that the threats are the same. That the criminal ecosystem targeting their workplace with phishing and ransomware attacks is the same ecosystem targeting their parents, the kids, their schools, and even their democracy.

An Emotional Call To Action
There’s no stronger emotional trigger for permanent habit change than talking to your employees about the threats to their family – parents, grandparents, kids, nieces and nephews.
It has nothing to do with security, it’s just a basic human instinct. We want to protect what and who we treasure most.
What if your employees were persuaded that the dark cloud, that global criminal ecosystem that’s targeting their workplace is made up of the same kinds of people, sometimes even the very same people, who are:
- Targeting their grandparents with scams that are costing more than $80 billion every year and in many cases disrupting and destroying health and life.
- Targeting their kids and grandkids with heartbreaking sextortion scams that have resulted in dozens of teen suicides.
- Targeting their schools and hospitals and disrupting their elections and democracies.
These are the kinds of threats that are most likely to fire up most humans to action, to motivation. We have to do better at connecting the dots. It’s one universal threat, and we’re all in the crosshairs.
Taking/Giving Some Power Back
The times that are in it might be our best advantage yet.
We’re living in an era of global disruption, uncertainty, and even fear. And one of the greatest emotional impacts on most humans is the frustration of feeling powerless.
What if security awareness in the workplace presented an easy way for all of us, all of your employees, to take some of that power back?
- A single click is at the core of many cyber attacks. If you make the click, and that click is bait for a scam, it could end up costing your organization millions.
- If you pause and take the time to decide that a click doesn’t feel appropriate, somehow doesn’t feel right, then you’re costing the criminals money. You’re denying then a win, depriving them of a profit, deciding and determining their fate in this attack. You’ve become the disrupter.
- By viewing workplace security habits as a way to fight back against that dark cloud, that criminal ecosystem that’s also targeting your family and community, you’re no longer powerless.
It’s empowering, even enjoyable, but most of all, it’s motivational. And that’s the core of habit changing.
More On Feelings vs. Information
Leading behaviorists seem to agree that habit changing is not about being presented with information that makes you think something but with information that makes you feel something.
Kotter & Cohen’s theory of behavioral change suggests that analysis and data rarely move people but emotional evidence does. The sequence isn’t analyze-think-change, but see-feel-change.
Similarly, Fogg’s behavior model holds that a behavior happens only when motivation, ability, and a prompt converge at the same moment. If any of these are missing, the behavior doesn’t happen (information alone typically only targets attitude, which has an unreliable link to actual behavior change.)
In security, the ability and prompt are always there. When receiving a suspicious email or asked to choose a new password (the prompt), the employee has the ability to choose their reaction. However, if they don’t have any motivation to, they’re just as likely to make a wrong decision, choose the wrong behavior.
Habit formation isn’t a product of simply doing something over and over again. It’s not a function of repetition, it’s a function of emotion. It’s not the repetition that’s creating the habit, it’s the emotion that you feel.
BJ Fogg, Stanford Behavioral Design Lab
Conclusion
In the realm of security awareness, training only tells employees how to behave, which choices to make, and why they should make the right choices.
But it doesn’t motivate them to. If employees feel little emotional connection to the request or the preferred behavior, their behavior is likely to resort back to the default once the message has been forgotten. Which is usually a matter of minutes in any busy workplace.
And as employees become more worried, cynical, and exhausted, minutes become seconds.
The sequence of message-emotion-motivation-change might be our best chance of improving the stickiness and reducing the gap between the training moment and the return to the default.
But bigger than that, reframing all awareness training as less about a corporate mandate and more of an urgent global challenge that’s personal to us all should help employees view security awareness as less of a bore and a chore and more of an opportunity and imperative.
Maybe our biggest advantage is that we humans are already naturally creatures of habit. Not only do we realize that they make life so much easier to manage, we can’t get through a single sunrise without them.
Understanding how to turn security awareness into default habits is a tool we shouldn’t ignore.
About Neal O’Farrell
Neal is widely regarded as one of the world’s longest-serving cybersecurity and fraud experts, more than 40 years globally. He has spent more than 25 years focused on the human element in security – building employee security awareness programs, teaching consumers, and supporting victims. CHECK OUT HIS FULL BIO HERE
Looking for something different for National Cybersecurity Awareness Month?
Introduce your audience to the Irishman for a compelling chat about why security awareness is a superpower none of us should waste.
