Enough With All The Awareness Training?
The Human Perimeter is still critically important in the security mix, made even more urgent by the surge in AI aided crime.
But in spite of billions of dollars in spending every year, employee security awareness training seems to be making little difference in improving either security or awareness, an assertion supported by one of the biggest experiments of its kind.
- The main culprit could be the false notion that the way to change habits, which is the goal of awareness training, is through frequent training and testing.
- One leading behaviorist labels the failure as “the information action fallacy,” that training can’t change habits (it can only change things like skills, perception, and opinions), and that the only way to make employees change their habits is to give them a strong, personal, and emotional motivation to do so.
- If we want to make security awareness work we only have to look at consumer security.
- I spent two decades working with consumers and victims of scams and saw first hand how quickly and permanently they adopted a whole armory full of new habits when they felt the threat was personal.
The best and perhaps only way to make security awareness work, to change user security habits, is to make it personal. We have to bring in the grandparents.
The Information Action Fallacy
Most security awareness training fails because of one fundamental and very obvious reason. Training. One leading behaviorist describes it as the “information action fallacy” – the false notion that pushing an endless amount of training information on employees is going to change their behavior and habits, make them more security aware and vigilant.
Training has only been shown to improve things like knowledge, opinions, and skills, but not habits.
The term Information Action Fallacy was coined by BJ Fogg, Director of Stanford University’s Behavior Design Lab, an expert on human behavior and habits, and author of the New York Times bestseller “Tiny Habits.”
For decades, maybe longer, people have assumed that if you just give people information it will change their behavior. And this doesn’t work very well. Habit formation isn’t a product of simply doing something over and over again. It’s not a function of repetition, it’s a function of emotion. It’s not the repetition that’s creating the habit, it’s the emotion that you feel.
BJ Fogg, Stanford Behavioral Design Lab
Recent Research
The impact of security awareness training: A 2025 study by UC San Diego Health that included a series of phishing campaigns that involved nearly 20,000 students over eight months found that:
- 75% of users engaged with the embedded training materials for a minute or less.
- One-third immediately closed the embedded training page without engaging with the material at all.
- Embedded phishing training only reduced the likelihood of clicking on a phishing link by 2%.
The amount of money we spend on awareness training: According to Cybersecurity Ventures, the global security awareness training market will exceed $10 billion annually by 2027 and nearly twice what was spent in 2023.
According to research firm Mordor the global spend on security awareness will rise to more than $14 billion by 2031.

About Neal O’Farrell
- Neal is widely regarded as one of the world’s longest-serving cybersecurity and fraud experts, more than 40 years globally.
- He has spent more than 25 years focused on the human element in security – building employee security awareness programs, teaching consumers, and supporting victims.
- As head of the award-winning Identity Theft Council he has counselled thousands of victims of scams and fraud and trained hundreds of police departments in fraud and identity theft.
- He currently offers a webinar called “The Big Security Talk” that helps to personally motivate employees to care more about security, and delivers the talk from a centuries-old thatched cottage in the Irish countryside.
FUN FACTS
- Neal is one of the few people, and only Irishman, to be blacklisted by the US government for his work in advanced speech encryption.
- In the mid 1990s he worked on one of the first telephone banking security systems based on voice verification.
- While still in his 20s he won the first contract to encrypt Ireland’s entire national ATM network.
- In the true tradition of the Irish immigrant, Neal came to America by boat, sailing the Atlantic in the middle of winter.
- He was supposed to be a dressmaker and not a codemaker, and the third generation to take over a famous Irish weaving business whose clients included Coco Chanel, the Duchess of Westminster, the Queen of Siam, and Nancy Reagan.
