Security culture
Awareness is not behaviour.
What the largest workplace studies say about changing security behaviour, and how to build a culture where people verify, report and speak up.
of breaches involved the human element in Verizon's 2026 analysis of more than 22,000 confirmed breaches.6
in business email compromise losses reported to the FBI in 2025, up from $2.77 billion the year before.7,8
was the whole reduction in failure rate from training shown after a mistake, in a trial with 19,789 employees.3
In January 2024, a finance worker in Arup's Hong Kong office received a message asking for a confidential transaction. He suspected it was a phishing email. He was right. Then he joined a video conference with people who looked and sounded like senior colleagues, and his doubt went away. Over fifteen transactions he sent HK$200 million to five bank accounts.9,10 Every other person on that call was a deepfake. Arup later said none of its internal systems were compromised.
It is tempting to read this as a story about a person who needed more training. The record says the opposite. His awareness worked: he spotted the lure. What failed was what came next. Nothing in his day told him that a familiar face on a call does not override a payment rule, and no habit sent him to a phone number he already trusted.
That gap, between knowing and doing under pressure, is where most security programmes still spend the least. And the best research of the last four years explains why the usual tools barely close it.
The evidenceWhat the largest studies actually found
Three independent field studies, covering more than 47,000 employees between them, tested security training the way organisations really deliver it. Their findings are uncomfortable, and consistent.
ETH Zurich, 14,733 employees over 15 months. Lain, Kostiainen and Capkun sent 117,864 simulated phishing emails inside a large organisation.1A third of staff clicked at least once. The training page shown after a click did not help: people who received it clicked more, not less. Asked about it later, 43% of those who remembered the page said it "made me feel safe". A follow-up study concluded that "phishing is an attention problem, rather than a knowledge one".2
UC San Diego Health, 19,789 employees.In an eight-month randomised trial, Ho and colleagues found "no significant relationship" between recently completing annual awareness training and failing a phishing test.3 Training shown after a mistake cut the failure rate by just 2%. More than half of training sessions ended within 10 seconds, and fewer than 24% of people finished the material.
A US fintech, 12,511 employees.Rozema and Davis found training had no significant effect on clicks or on reporting, with "negligible effect sizes".4 The difficulty of the lure, on the other hand, doubled the click rate.
Figure 1
A lecture after the click did less than a warning before it
ETH Zurich field study, 14,733 employees. Counts of people who clicked or took a dangerous action (such as entering credentials), by condition.
Clicks: training after a click
Dangerous actions: warning before opening
Source: Lain, Kostiainen and Capkun, "Phishing in Organizations", IEEE Symposium on Security and Privacy 2022.1 Bars within each panel share one scale.
None of this says people cannot learn. Smaller controlled studies show real gains, especially when practice is repeated: a German public-sector study of 409 employees found people got better at spotting phishing for four months, and the gain had faded by six, while reminders using videos and interactive examples held for at least another six months.5 The lesson is narrower and more useful. Content delivered once a year, or as a lecture after a mistake, does not reliably change what people do. The same studies point to what does.
Figure 2
Click rates measure the lure as much as the people
Share of employees who clicked, by how hard the simulated message was to spot. A falling click rate can mean easier tests, not safer staff.
Sources: Rozema and Davis, ACM Web Conference 2026, lure difficulty rated on the NIST Phish Scale;4Ho et al., IEEE Symposium on Security and Privacy 2025, which reports "upwards of 30%" for the strongest lures.3
The threatThe attack moved off the inbox. Most programmes did not.
Verizon's 2026 Data Breach Investigations Report found the human element present in 62% of breaches, up from 60% the year before.6That is not the same as "human error": the category includes social engineering and the misuse of stolen credentials. The more telling finding sits beside it. In simulations, people fell for voice and text lures at a rate 40% higher than email, though Verizon's sample for this was small. Pretexting, an invented scenario built to get someone to act, now often arrives by voice.
The money follows. Business email compromise losses reported to the FBI rose to $3.05 billion in 2025, and the FBI now defines the crime to include compromised phone numbers and virtual meeting apps.8Complaints mentioning AI passed 22,000, with adjusted losses above $893 million. FinCEN has warned banks about a rise in suspicious activity reports describing deepfake media used to impersonate "an executive or other trusted employee" and instruct large transfers.12In Australia, "social engineering / impersonation" was behind 115 of the 404 malicious or criminal data breaches notified in the second half of 2024.38
Figure 3
Business email compromise reported to the FBI
Losses and complaints in the FBI Internet Crime Complaint Center's two most recent annual reports.
Reported losses
Complaints
Sources: FBI IC3 Internet Crime Report 2024 and 2025.7,8 Reported figures only; many incidents are never reported. Some secondary sources quote a higher 2024 figure for the FBI; the IC3 report itself shows $2,770,151,146.
Fraudsters impersonated WPP's chief executive using a WhatsApp account, a Teams meeting, a voice clone and YouTube footage.11
It failed. WPP's explanation is the point of this article: "Thanks to the vigilance of our people, including the executive concerned, the incident was prevented."
The scienceKnowing is not doing
Behavioural science has a name for the Arup problem: the intention-behaviour gap. A meta-analysis of 47 experiments found that a medium-to-large shift in what people intend to do produced only a small-to-medium shift in what they did.14 Awareness campaigns work on intention. Attackers work on the moment of action, when people are busy, rushed and talking to someone who sounds senior.
Figure 4
Changing minds moves behaviour about half as much
Average effect of interventions on intention, and on the behaviour that followed. Standardised effect size (Cohen's d) across 47 experimental tests.
Source: Webb and Sheeran, "Does changing behavioral intentions engender behavior change?", Psychological Bulletin 2006.14 General behaviour-change research, not security-specific.
The same literature is clear about what closes the gap, and much of it runs against how training is usually built.
Plans beat intentions
If-then plans ("If a supplier emails new bank details, then I call them on the number already in our system") had an effect of medium-to-large size on whether people reached their goals across 94 tests.17No trial has tested this on payment fraud yet, but it is the format the FBI's own advice takes: hang up, look up the number yourself, call back.13For business email compromise, its first tip is to "use secondary channels" to verify any change to account details.37
Fear works only with a way out
Across 248 samples and more than 27,000 people, fear appeals did change behaviour, and the effect grew when the message included a specific, doable action.18"Deepfakes are dangerous" is a fear appeal. "Every payment change gets a call to a known number, whoever asks" is a fear appeal with a way out.
Feedback can make people worse
A landmark review of 607 effects found feedback improved performance on average, but more than a third of feedback interventions made it worse, especially when feedback was about the person rather than the task.16"You failed the test" is about the person. "The sender's domain was one letter off" is about the task.
Spacing and recall beat one long session
Hundreds of experiments show that practice spread over time, and practice that makes people recall rather than reread, outperforms a single block of study.19,20,21 In one classic study, students who reread material felt more confident but remembered less a week later than those who had been tested. Annual training is the format this research predicts will fade.
Habits take months, not 21 days
In the study most often misquoted on this, the time for a new behaviour to become automatic ranged from 18 to 254 days. Missing a single day did not derail it.15 A verification reflex is built by many repetitions in the real setting, not by one memorable module.
Change the structure, not just the message
Nudges, small changes to how choices are presented, looked powerful in a meta-analysis of more than 200 studies. After correcting for publication bias, another team found "no evidence for the effectiveness of nudges remains", with structural changes the only category left undecided.22,23 In security terms: a mandatory callback step, dual approval and a well-placed warning will outlast any poster.
Figure 5
How long a new habit takes to become automatic
Days for participants to reach 95% of their peak automaticity for a new daily behaviour. The popular "21 days" sits at the very bottom of the range.
Source: Lally et al., "How are habits formed", European Journal of Social Psychology, 82 participants analysed.15 Axis shortened to 240 days; the bar extends to 254.
The behaviour that compoundsReporting is the metric that holds up
The most hopeful findings in the research are not about avoiding clicks at all. They are about people raising their hand.
In the 15-month ETH Zurich study, employees reported 18,476 suspicious emails and showed "no significant 'reporting fatigue'". 1 Reports arrived fast: about 10% within five minutes and 30% to 40% within half an hour. In the final five months, staff reports exposed 252 real phishing campaigns comprising 28,830 emails. And one cheap change worked: people who received positive feedback on a report went on to report more. Rewards did not help.2Interviews suggest why. People report mainly out of "the desire to protect and help the organization and coworkers".36
Figure 6
Speed is the whole game
Left: how fast staff reports arrived after a phishing campaign landed. Right: money recovered when fraudulent transfers were reported quickly through the FBI's Financial Fraud Kill Chain in 2025.
Share of reports received
Lain, Kostiainen and Capkun, 2022.1 The shaded band shows the reported 30 to 40% range.
Attempted theft frozen
FBI IC3 Internet Crime Report 2025.8The FBI's advice: "time is of the essence".
The first report often comes before the first click: in the fintech study, reports preceded clicks in 36% to 55% of campaigns.4
A strong security culture is one where the first report beats the first click.Vigil Security
The cultureCulture is what people do when the attacker sounds like the boss
ENISA defines security culture as the knowledge, beliefs, attitudes, norms and values of people about security, and "how they manifest in people's behaviour". 28It also names a poor metric directly: "the number of employees who undertook the training".
The UK's National Cyber Security Centre went further in its 2025 culture principles.24"People need to feel safe from negative repercussions before they will speak up." Incidents are to be "investigated with a view to learn and improve, not to blame", with "no punishment for innocent mistakes", and reporters followed up "to thank them and provide feedback". Its phishing guidance is blunter: "Blaming users for clicking on links doesn't work" and "Employees who are afraid for their jobs will not report mistakes." 25
Aviation learned this decades ago and wrote it into law. European regulation defines a just culture as one where people "are not punished for actions, omissions or decisions taken by them that are commensurate with their experience and training", while "gross negligence, wilful violations and destructive acts are not tolerated".26 That balance matters in finance too: no blame for honest mistakes, no tolerance for skipping a control.
Two more findings anchor the leadership case. Edmondson's study of 51 teams found that psychological safety, not confidence, was what predicted learning behaviour.27And research on security compliance found that top management's participation in security initiatives shaped employees' attitudes, their sense of what peers expect, and their belief that they could comply.29 When the CFO is seen calling a supplier back on a known number, every analyst learns it is allowed to slow a payment down.
The modelFive shifts from awareness to behaviour
Put the evidence together and a different programme emerges. Not more content, but a different design.
The regulatorsYour regulator is already asking for behaviour
Across the markets we work in, the wording has moved from attendance towards effectiveness, social engineering and testing understanding.
periodic, but at a minimum annual, cybersecurity awareness training that includes social engineering for all personnelSource 30
security awareness training that is updated as necessary to reflect risks identified by the risk assessmentSource 31
tracking training undertaken and testing the understanding of relevant information security policies, both on commencement and periodicallySource 32
The training programme should be conducted at least annually for all staff, contractors and service providersSource 33
The cyber security awareness program should target cyber security behaviorsSource 34
conducted periodically through multiple channels ... to build a positive cybersecurity awareness cultureSource 35
The scorecardWhat to put in front of the board instead
| Measure | What it tells you |
|---|---|
| Report rate | Whether people raise their hand, on real and simulated attempts, by team. The behaviour that showed no fatigue over 15 months. |
| Time to first report | How quickly your organisation learns it is under attack. In the research, a tenth of reports landed within five minutes. |
| Verification under pressure | On payment-change and executive-request tests by phone or video, the share who stopped and called back on a known number. |
| Repeat behaviour after feedback | Whether people who got task-focused feedback behave differently next time. |
| Understanding, tested before and after | What ENISA calls a good metric, and what APRA and SAMA ask for in their own words. |
| Leaders taking part | Whether executives are tested and seen to verify. The norm everyone else copies. |
| Completion rate alone | Keep it for audit, but never as evidence of behaviour. ENISA names it a poor metric. |
| Click rate as the headline | Moves with how hard the test was. Report it beside lure difficulty, or not at all. |
Where Vigil fitsPractice for the attacks that work now, and proof of what people did
We built Vigil for regulated firms that need to change behaviour and show it. It supports the shifts above in four practical ways.
Rehearse every channel
Simulations by email, SMS, QR code, phone call and video, including calls in a cloned executive's voice and deepfake video, used only after you record that executive's consent.
Teach the cue, not the person
Short, story-driven training films that show the cue in a real attack and the action that defeats it, instead of a lecture.
Measure behaviour
A dated record for every person of what they were tested on and what they did, and a risk score for each employee with trends across the organisation.
Evidence that stands up
A one-click compliance report for auditors and cyber insurers, which shows "Not available" rather than a false zero, and a tamper-evident audit trail.
What no platform can do for you is the culture work in this article: the no-blame policy, the thank-you on every report, and the executive who calls back first. That part is leadership. We help you practise it and prove it.
Sources
Every source was opened on 2 October 2026. Figures are quoted as published. Secondary reporting is marked.
- Lain, Kostiainen, Capkun. Phishing in Organizations: Findings from a Large-Scale and Long-Term Study. IEEE S&P 2022. arxiv.org/abs/2112.07498
- Lain et al. Content, Nudges and Incentives: A Study on the Effectiveness and Perception of Embedded Phishing Training. ACM CCS 2024. arxiv.org/abs/2409.01378
- Ho et al. Understanding the Efficacy of Phishing Training in Practice. IEEE S&P 2025. doi.org/10.1109/SP61157.2025.00076
- Rozema, Davis. Anti-Phishing Training (Still) Does Not Work. ACM Web Conference 2026. arxiv.org/abs/2506.19899
- Reinheimer et al. An investigation of phishing awareness and education over time. SOUPS 2020. usenix.org
- Verizon. 2026 Data Breach Investigations Report, Executive Summary. verizon.com
- FBI IC3. 2024 Internet Crime Report. ic3.gov
- FBI IC3. 2025 Internet Crime Report. ic3.gov
- CNN, 4 February 2024, reporting the Hong Kong police briefing (secondary). cnn.com
- The Guardian, 17 May 2024, Arup confirms it was the company (secondary). theguardian.com
- The Guardian, 10 May 2024, WPP (secondary). theguardian.com
- FinCEN. FIN-2024-Alert004, Fraud Schemes Involving Deepfake Media. fincen.gov
- FBI. Public Service Announcement I-120324-PSA. ic3.gov
- Webb, Sheeran. Psychological Bulletin, 2006. doi.org/10.1037/0033-2909.132.2.249
- Lally et al. How are habits formed. European Journal of Social Psychology. doi.org/10.1002/ejsp.674
- Kluger, DeNisi. The effects of feedback interventions on performance. Psychological Bulletin, 1996. doi.org/10.1037/0033-2909.119.2.254
- Gollwitzer, Sheeran. Implementation intentions and goal achievement. Advances in Experimental Social Psychology, 2006. doi.org/10.1016/S0065-2601(06)38002-1
- Tannenbaum et al. Appealing to fear. Psychological Bulletin, 2015. doi.org/10.1037/a0039729
- Cepeda et al. Distributed practice in verbal recall tasks. Psychological Bulletin, 2006. doi.org/10.1037/0033-2909.132.3.354
- Roediger, Karpicke. Test-enhanced learning. Psychological Science, 2006. doi.org/10.1111/j.1467-9280.2006.01693.x
- Dunlosky et al. Improving students' learning with effective learning techniques. Psychological Science in the Public Interest, 2013. doi.org/10.1177/1529100612453266
- Mertens et al. The effectiveness of nudging. PNAS, 2022. doi.org/10.1073/pnas.2107346118
- Maier et al. No evidence for nudging after adjusting for publication bias. PNAS, 2022. doi.org/10.1073/pnas.2200300119
- NCSC. Cyber security culture principles, 2025. ncsc.gov.uk
- NCSC. Phishing attacks: defending your organisation. ncsc.gov.uk
- Regulation (EU) No 376/2014, Article 2(12). legislation.gov.uk
- Edmondson. Psychological safety and learning behavior in work teams. Administrative Science Quarterly, 1999. doi.org/10.2307/2666999
- ENISA. Cyber Security Culture in Organisations, 2017. enisa.europa.eu
- Hu et al. Managing employee compliance with information security policies. Decision Sciences, 2012. doi.org/10.1111/j.1540-5915.2012.00361.x
- 23 NYCRR 500.14. law.cornell.edu
- 16 CFR 314.4. ecfr.gov
- APRA. Prudential Practice Guide CPG 234, June 2019. apra.gov.au
- MAS. Technology Risk Management Guidelines, January 2021. mas.gov.sg
- SAMA. Cyber Security Framework 3.1.6. rulebook.sama.gov.sa
- NCA. Essential Cybersecurity Controls ECC-1:2018 (archived copy; the official site was unreachable). web.archive.org
- Burda et al. Phishing reporting in organizations. Information & Computer Security, 2025. doi.org/10.1108/ICS-02-2025-0037
- FBI. I-091124-PSA, Business Email Compromise: The $55 Billion Scam. ic3.gov
- OAIC. Notifiable Data Breaches Report, July to December 2024. oaic.gov.au
