Skip to content
Vigil

Security culture

Awareness is not behaviour.

What the largest workplace studies say about changing security behaviour, and how to build a culture where people verify, report and speak up.

62%

of breaches involved the human element in Verizon's 2026 analysis of more than 22,000 confirmed breaches.6

$3.05B

in business email compromise losses reported to the FBI in 2025, up from $2.77 billion the year before.7,8

2%

was the whole reduction in failure rate from training shown after a mistake, in a trial with 19,789 employees.3

In January 2024, a finance worker in Arup's Hong Kong office received a message asking for a confidential transaction. He suspected it was a phishing email. He was right. Then he joined a video conference with people who looked and sounded like senior colleagues, and his doubt went away. Over fifteen transactions he sent HK$200 million to five bank accounts.9,10 Every other person on that call was a deepfake. Arup later said none of its internal systems were compromised.

It is tempting to read this as a story about a person who needed more training. The record says the opposite. His awareness worked: he spotted the lure. What failed was what came next. Nothing in his day told him that a familiar face on a call does not override a payment rule, and no habit sent him to a phone number he already trusted.

That gap, between knowing and doing under pressure, is where most security programmes still spend the least. And the best research of the last four years explains why the usual tools barely close it.

The evidenceWhat the largest studies actually found

Three independent field studies, covering more than 47,000 employees between them, tested security training the way organisations really deliver it. Their findings are uncomfortable, and consistent.

ETH Zurich, 14,733 employees over 15 months. Lain, Kostiainen and Capkun sent 117,864 simulated phishing emails inside a large organisation.1A third of staff clicked at least once. The training page shown after a click did not help: people who received it clicked more, not less. Asked about it later, 43% of those who remembered the page said it "made me feel safe". A follow-up study concluded that "phishing is an attention problem, rather than a knowledge one".2

UC San Diego Health, 19,789 employees.In an eight-month randomised trial, Ho and colleagues found "no significant relationship" between recently completing annual awareness training and failing a phishing test.3 Training shown after a mistake cut the failure rate by just 2%. More than half of training sessions ended within 10 seconds, and fewer than 24% of people finished the material.

A US fintech, 12,511 employees.Rozema and Davis found training had no significant effect on clicks or on reporting, with "negligible effect sizes".4 The difficulty of the lure, on the other hand, doubled the click rate.

Figure 1

A lecture after the click did less than a warning before it

ETH Zurich field study, 14,733 employees. Counts of people who clicked or took a dangerous action (such as entering credentials), by condition.

Clicks: training after a click

No training3,087With training3,593More clicks with training, not fewer

Dangerous actions: warning before opening

No warning2,994Short warning998Detailed warning893Two thirds fewer, and short worked as well as long

Source: Lain, Kostiainen and Capkun, "Phishing in Organizations", IEEE Symposium on Security and Privacy 2022.1 Bars within each panel share one scale.

None of this says people cannot learn. Smaller controlled studies show real gains, especially when practice is repeated: a German public-sector study of 409 employees found people got better at spotting phishing for four months, and the gain had faded by six, while reminders using videos and interactive examples held for at least another six months.5 The lesson is narrower and more useful. Content delivered once a year, or as a lecture after a mistake, does not reliably change what people do. The same studies point to what does.

Figure 2

Click rates measure the lure as much as the people

Share of employees who clicked, by how hard the simulated message was to spot. A falling click rate can mean easier tests, not safer staff.

0%10%20%30%40%US fintech, 12,511 staffEasy lures7%Hard lures15%UC San Diego Health, 19,789 staffPlainest lures1 to 2%Strongest luresover 30%

Sources: Rozema and Davis, ACM Web Conference 2026, lure difficulty rated on the NIST Phish Scale;4Ho et al., IEEE Symposium on Security and Privacy 2025, which reports "upwards of 30%" for the strongest lures.3

For your programmeStop reporting click rate as the headline number. It moves with test difficulty, and the large studies show it barely moves with training.

The threatThe attack moved off the inbox. Most programmes did not.

Verizon's 2026 Data Breach Investigations Report found the human element present in 62% of breaches, up from 60% the year before.6That is not the same as "human error": the category includes social engineering and the misuse of stolen credentials. The more telling finding sits beside it. In simulations, people fell for voice and text lures at a rate 40% higher than email, though Verizon's sample for this was small. Pretexting, an invented scenario built to get someone to act, now often arrives by voice.

The money follows. Business email compromise losses reported to the FBI rose to $3.05 billion in 2025, and the FBI now defines the crime to include compromised phone numbers and virtual meeting apps.8Complaints mentioning AI passed 22,000, with adjusted losses above $893 million. FinCEN has warned banks about a rise in suspicious activity reports describing deepfake media used to impersonate "an executive or other trusted employee" and instruct large transfers.12In Australia, "social engineering / impersonation" was behind 115 of the 404 malicious or criminal data breaches notified in the second half of 2024.38

Figure 3

Business email compromise reported to the FBI

Losses and complaints in the FBI Internet Crime Complaint Center's two most recent annual reports.

Reported losses

$0$1.5B$3.0B$2.77B2024$3.05B2025

Complaints

012.5k25k21,442202424,7682025

Sources: FBI IC3 Internet Crime Report 2024 and 2025.7,8 Reported figures only; many incidents are never reported. Some secondary sources quote a higher 2024 figure for the FBI; the IC3 report itself shows $2,770,151,146.

WPP, May 2024Attempt stopped

Fraudsters impersonated WPP's chief executive using a WhatsApp account, a Teams meeting, a voice clone and YouTube footage.11

It failed. WPP's explanation is the point of this article: "Thanks to the vigilance of our people, including the executive concerned, the incident was prevented."

For your programmeIf your people only ever practise on email, they have never rehearsed the channel that is now most likely to fool them.

The scienceKnowing is not doing

Behavioural science has a name for the Arup problem: the intention-behaviour gap. A meta-analysis of 47 experiments found that a medium-to-large shift in what people intend to do produced only a small-to-medium shift in what they did.14 Awareness campaigns work on intention. Attackers work on the moment of action, when people are busy, rushed and talking to someone who sounds senior.

Figure 4

Changing minds moves behaviour about half as much

Average effect of interventions on intention, and on the behaviour that followed. Standardised effect size (Cohen's d) across 47 experimental tests.

00.20.40.6Effect on intentiond = 0.66Effect on behaviourd = 0.36

Source: Webb and Sheeran, "Does changing behavioral intentions engender behavior change?", Psychological Bulletin 2006.14 General behaviour-change research, not security-specific.

The same literature is clear about what closes the gap, and much of it runs against how training is usually built.

Plans beat intentions

If-then plans ("If a supplier emails new bank details, then I call them on the number already in our system") had an effect of medium-to-large size on whether people reached their goals across 94 tests.17No trial has tested this on payment fraud yet, but it is the format the FBI's own advice takes: hang up, look up the number yourself, call back.13For business email compromise, its first tip is to "use secondary channels" to verify any change to account details.37

Fear works only with a way out

Across 248 samples and more than 27,000 people, fear appeals did change behaviour, and the effect grew when the message included a specific, doable action.18"Deepfakes are dangerous" is a fear appeal. "Every payment change gets a call to a known number, whoever asks" is a fear appeal with a way out.

Feedback can make people worse

A landmark review of 607 effects found feedback improved performance on average, but more than a third of feedback interventions made it worse, especially when feedback was about the person rather than the task.16"You failed the test" is about the person. "The sender's domain was one letter off" is about the task.

Spacing and recall beat one long session

Hundreds of experiments show that practice spread over time, and practice that makes people recall rather than reread, outperforms a single block of study.19,20,21 In one classic study, students who reread material felt more confident but remembered less a week later than those who had been tested. Annual training is the format this research predicts will fade.

Habits take months, not 21 days

In the study most often misquoted on this, the time for a new behaviour to become automatic ranged from 18 to 254 days. Missing a single day did not derail it.15 A verification reflex is built by many repetitions in the real setting, not by one memorable module.

Change the structure, not just the message

Nudges, small changes to how choices are presented, looked powerful in a meta-analysis of more than 200 studies. After correcting for publication bias, another team found "no evidence for the effectiveness of nudges remains", with structural changes the only category left undecided.22,23 In security terms: a mandatory callback step, dual approval and a well-placed warning will outlast any poster.

Figure 5

How long a new habit takes to become automatic

Days for participants to reach 95% of their peak automaticity for a new daily behaviour. The popular "21 days" sits at the very bottom of the range.

060 days120 days180 days240 days18 days254 days"21 days" myth

Source: Lally et al., "How are habits formed", European Journal of Social Psychology, 82 participants analysed.15 Axis shortened to 240 days; the bar extends to 254.

For your programmeWrite the one or two if-then rules that would have saved Arup, rehearse them often in the real channels, and give feedback on the cue, never on the person.

The behaviour that compoundsReporting is the metric that holds up

The most hopeful findings in the research are not about avoiding clicks at all. They are about people raising their hand.

In the 15-month ETH Zurich study, employees reported 18,476 suspicious emails and showed "no significant 'reporting fatigue'". 1 Reports arrived fast: about 10% within five minutes and 30% to 40% within half an hour. In the final five months, staff reports exposed 252 real phishing campaigns comprising 28,830 emails. And one cheap change worked: people who received positive feedback on a report went on to report more. Rewards did not help.2Interviews suggest why. People report mainly out of "the desire to protect and help the organization and coworkers".36

Figure 6

Speed is the whole game

Left: how fast staff reports arrived after a phishing campaign landed. Right: money recovered when fraudulent transfers were reported quickly through the FBI's Financial Fraud Kill Chain in 2025.

Share of reports received

0%10%20%30%40%5 min15 min30 min10%20%30 to 40%

Lain, Kostiainen and Capkun, 2022.1 The shaded band shows the reported 30 to 40% range.

Attempted theft frozen

58%frozen$679M frozen$485M notof $1.164B attemptedacross 3,900 incidents

FBI IC3 Internet Crime Report 2025.8The FBI's advice: "time is of the essence".

The first report often comes before the first click: in the fintech study, reports preceded clicks in 36% to 55% of campaigns.4

A strong security culture is one where the first report beats the first click.
Vigil Security

The cultureCulture is what people do when the attacker sounds like the boss

ENISA defines security culture as the knowledge, beliefs, attitudes, norms and values of people about security, and "how they manifest in people's behaviour". 28It also names a poor metric directly: "the number of employees who undertook the training".

The UK's National Cyber Security Centre went further in its 2025 culture principles.24"People need to feel safe from negative repercussions before they will speak up." Incidents are to be "investigated with a view to learn and improve, not to blame", with "no punishment for innocent mistakes", and reporters followed up "to thank them and provide feedback". Its phishing guidance is blunter: "Blaming users for clicking on links doesn't work" and "Employees who are afraid for their jobs will not report mistakes." 25

Aviation learned this decades ago and wrote it into law. European regulation defines a just culture as one where people "are not punished for actions, omissions or decisions taken by them that are commensurate with their experience and training", while "gross negligence, wilful violations and destructive acts are not tolerated".26 That balance matters in finance too: no blame for honest mistakes, no tolerance for skipping a control.

Two more findings anchor the leadership case. Edmondson's study of 51 teams found that psychological safety, not confidence, was what predicted learning behaviour.27And research on security compliance found that top management's participation in security initiatives shaped employees' attitudes, their sense of what peers expect, and their belief that they could comply.29 When the CFO is seen calling a supplier back on a known number, every analyst learns it is allowed to slow a payment down.

For your programmeRetire punishment for clicks, thank every report within a day, and ask your executives to be the first people tested on a voice or video call.

The modelFive shifts from awareness to behaviour

Put the evidence together and a different programme emerges. Not more content, but a different design.

1
FromOne annual course, or a lecture after a mistake
ToShort, spaced practice that makes people recall and decideSpacing and retrieval research; awareness fades by six months without reminders
2
FromEmail-only tests
ToRehearsal in the channels attackers use now: phone, text, videoVoice and text lures 40% more successful; Arup and WPP
3
From"Be careful"
ToIf-then rules and built-in checkpoints: callback, dual approval, warnings at the moment of riskImplementation intentions; warnings cut dangerous actions by two thirds
4
FromPunishing clicks
ToRewarding reports, with leaders going firstNCSC culture principles; feedback raised reporting; just culture
5
FromCompletion rates and click rates
ToBehaviour measures: report rate, time to report, verification under pressureENISA on metrics; SAMA asks programmes to "measure the effectiveness"

The regulatorsYour regulator is already asking for behaviour

Across the markets we work in, the wording has moved from attendance towards effectiveness, social engineering and testing understanding.

NYDFS23 NYCRR 500.14(a)(3) · United States
periodic, but at a minimum annual, cybersecurity awareness training that includes social engineering for all personnelSource 30
FTC Safeguards Rule16 CFR 314.4(e)(1) · United States
security awareness training that is updated as necessary to reflect risks identified by the risk assessmentSource 31
APRACPG 234, Attachment B · Australia
tracking training undertaken and testing the understanding of relevant information security policies, both on commencement and periodicallySource 32
MASTRM Guidelines 3.6.2 · Singapore
The training programme should be conducted at least annually for all staff, contractors and service providersSource 33
SAMACyber Security Framework 3.1.6 · Saudi Arabia
The cyber security awareness program should target cyber security behaviorsSource 34
NCAEssential Cybersecurity Controls 1-10 · Saudi Arabia
conducted periodically through multiple channels ... to build a positive cybersecurity awareness cultureSource 35

The scorecardWhat to put in front of the board instead

MeasureWhat it tells you
Report rateWhether people raise their hand, on real and simulated attempts, by team. The behaviour that showed no fatigue over 15 months.
Time to first reportHow quickly your organisation learns it is under attack. In the research, a tenth of reports landed within five minutes.
Verification under pressureOn payment-change and executive-request tests by phone or video, the share who stopped and called back on a known number.
Repeat behaviour after feedbackWhether people who got task-focused feedback behave differently next time.
Understanding, tested before and afterWhat ENISA calls a good metric, and what APRA and SAMA ask for in their own words.
Leaders taking partWhether executives are tested and seen to verify. The norm everyone else copies.
Completion rate aloneKeep it for audit, but never as evidence of behaviour. ENISA names it a poor metric.
Click rate as the headlineMoves with how hard the test was. Report it beside lure difficulty, or not at all.

Where Vigil fitsPractice for the attacks that work now, and proof of what people did

We built Vigil for regulated firms that need to change behaviour and show it. It supports the shifts above in four practical ways.

Shift 2

Rehearse every channel

Simulations by email, SMS, QR code, phone call and video, including calls in a cloned executive's voice and deepfake video, used only after you record that executive's consent.

Shift 1

Teach the cue, not the person

Short, story-driven training films that show the cue in a real attack and the action that defeats it, instead of a lecture.

Shift 5

Measure behaviour

A dated record for every person of what they were tested on and what they did, and a risk score for each employee with trends across the organisation.

For your regulator

Evidence that stands up

A one-click compliance report for auditors and cyber insurers, which shows "Not available" rather than a false zero, and a tamper-evident audit trail.

What no platform can do for you is the culture work in this article: the no-blame policy, the thank-you on every report, and the executive who calls back first. That part is leadership. We help you practise it and prove it.

Book a 30-minute programme reviewWe read your current programme against your regulator's own words and send you a one-page list of gaps, whether or not you work with us.

Sources

Every source was opened on 2 October 2026. Figures are quoted as published. Secondary reporting is marked.

  1. Lain, Kostiainen, Capkun. Phishing in Organizations: Findings from a Large-Scale and Long-Term Study. IEEE S&P 2022. arxiv.org/abs/2112.07498
  2. Lain et al. Content, Nudges and Incentives: A Study on the Effectiveness and Perception of Embedded Phishing Training. ACM CCS 2024. arxiv.org/abs/2409.01378
  3. Ho et al. Understanding the Efficacy of Phishing Training in Practice. IEEE S&P 2025. doi.org/10.1109/SP61157.2025.00076
  4. Rozema, Davis. Anti-Phishing Training (Still) Does Not Work. ACM Web Conference 2026. arxiv.org/abs/2506.19899
  5. Reinheimer et al. An investigation of phishing awareness and education over time. SOUPS 2020. usenix.org
  6. Verizon. 2026 Data Breach Investigations Report, Executive Summary. verizon.com
  7. FBI IC3. 2024 Internet Crime Report. ic3.gov
  8. FBI IC3. 2025 Internet Crime Report. ic3.gov
  9. CNN, 4 February 2024, reporting the Hong Kong police briefing (secondary). cnn.com
  10. The Guardian, 17 May 2024, Arup confirms it was the company (secondary). theguardian.com
  11. The Guardian, 10 May 2024, WPP (secondary). theguardian.com
  12. FinCEN. FIN-2024-Alert004, Fraud Schemes Involving Deepfake Media. fincen.gov
  13. FBI. Public Service Announcement I-120324-PSA. ic3.gov
  14. Webb, Sheeran. Psychological Bulletin, 2006. doi.org/10.1037/0033-2909.132.2.249
  15. Lally et al. How are habits formed. European Journal of Social Psychology. doi.org/10.1002/ejsp.674
  16. Kluger, DeNisi. The effects of feedback interventions on performance. Psychological Bulletin, 1996. doi.org/10.1037/0033-2909.119.2.254
  17. Gollwitzer, Sheeran. Implementation intentions and goal achievement. Advances in Experimental Social Psychology, 2006. doi.org/10.1016/S0065-2601(06)38002-1
  18. Tannenbaum et al. Appealing to fear. Psychological Bulletin, 2015. doi.org/10.1037/a0039729
  19. Cepeda et al. Distributed practice in verbal recall tasks. Psychological Bulletin, 2006. doi.org/10.1037/0033-2909.132.3.354
  20. Roediger, Karpicke. Test-enhanced learning. Psychological Science, 2006. doi.org/10.1111/j.1467-9280.2006.01693.x
  21. Dunlosky et al. Improving students' learning with effective learning techniques. Psychological Science in the Public Interest, 2013. doi.org/10.1177/1529100612453266
  22. Mertens et al. The effectiveness of nudging. PNAS, 2022. doi.org/10.1073/pnas.2107346118
  23. Maier et al. No evidence for nudging after adjusting for publication bias. PNAS, 2022. doi.org/10.1073/pnas.2200300119
  24. NCSC. Cyber security culture principles, 2025. ncsc.gov.uk
  25. NCSC. Phishing attacks: defending your organisation. ncsc.gov.uk
  26. Regulation (EU) No 376/2014, Article 2(12). legislation.gov.uk
  27. Edmondson. Psychological safety and learning behavior in work teams. Administrative Science Quarterly, 1999. doi.org/10.2307/2666999
  28. ENISA. Cyber Security Culture in Organisations, 2017. enisa.europa.eu
  29. Hu et al. Managing employee compliance with information security policies. Decision Sciences, 2012. doi.org/10.1111/j.1540-5915.2012.00361.x
  30. 23 NYCRR 500.14. law.cornell.edu
  31. 16 CFR 314.4. ecfr.gov
  32. APRA. Prudential Practice Guide CPG 234, June 2019. apra.gov.au
  33. MAS. Technology Risk Management Guidelines, January 2021. mas.gov.sg
  34. SAMA. Cyber Security Framework 3.1.6. rulebook.sama.gov.sa
  35. NCA. Essential Cybersecurity Controls ECC-1:2018 (archived copy; the official site was unreachable). web.archive.org
  36. Burda et al. Phishing reporting in organizations. Information & Computer Security, 2025. doi.org/10.1108/ICS-02-2025-0037
  37. FBI. I-091124-PSA, Business Email Compromise: The $55 Billion Scam. ic3.gov
  38. OAIC. Notifiable Data Breaches Report, July to December 2024. oaic.gov.au