















Many organizations still rely on one-size-fits-all security awareness training, in which employees complete a course, acknowledge the organization's policies, and move on. While that approach establishes a baseline, it rarely changes how people make security decisions in their daily tasks.
Cyber risk is not evenly distributed across the workforce. Certain employees are more frequently targeted due to their role, access level, or visibility. Some regularly approve financial transactions, manage customer data, oversee critical systems, or use AI tools that pose unique risks. Similarly, some employees consistently display good security practices, while others need further guidance.
That reality is reshaping how organizations approach security awareness. Instead of providing identical content to everyone, organizations are increasingly building behavior-based security programs that tailor training to real risk, promote secure behaviors over time, and assess whether employees are making better security decisions so organizations can provide additional reinforcement where it's needed.
According to the 2025 Security Awareness and Training Global Research Report, 88% of organizations now tailor security awareness training to specific employee groups. Sixty-four percent provide additional training to users who are targeted more frequently. And 58% provide additional training for employees who demonstrate lower levels of security awareness or knowledge.
These findings reflect an important shift. Security awareness is evolving from a compliance exercise into an operational capability that improves workforce readiness by helping employees make better security decisions in the situations they encounter daily.
Awareness of security risks alone doesn't ensure safe behavior. Employees who understand phishing may still click on convincing messages. Finance teams may still approve fraudulent payment requests. Customer-facing staff might share sensitive information through incorrect channels. And developers sometimes paste proprietary code into public AI tools for convenience. These issues are seldom due to a lack of awareness. Rather, they stem from failing to translate knowledge into secure actions when necessary.
Behavior-based security programs are designed to close that gap. Rather than treating every employee the same, organizations can tailor education to each role, exposure level, prior behavior, and the specific threats certain employees are most likely to encounter.
For example, finance teams benefit from guidance on invoice fraud, payment redirection, and executive impersonation. Developers require training in secure coding practices, AI-assisted development, and the risks of exposing proprietary code via public AI services. Sales and customer success teams need practical guidance on protecting customer information, handling meeting summaries, and responding to unusual requests. And executive assistants often need additional preparation for highly targeted social engineering attempts aimed at senior leadership.
This tailored approach does not make awareness programs more complicated. It makes them more relevant. When employees recognize that security training applies directly to the decisions they make every day, they are far more likely to change their behavior.
Changing behavior requires more than a single annual training session. While annual awareness training may satisfy a compliance requirement, it cannot keep pace with evolving attack techniques, emerging technologies, shifting business processes, or the growing use of AI across the workplace.
The research indicates that organizations are increasingly acknowledging this trend. Currently, 94% of respondents regularly carry out security awareness and training activities. About half of them conduct training quarterly, nearly one-third do so monthly, and just 16% depend only on annual sessions.
This change highlights a key learning principle: nearly every employee needs guidance when new tools like AI are introduced, as attack techniques evolve, and after risky behaviors occur. Furthermore, training is most effective when provided close to the decision point rather than months beforehand.
Phishing simulations effectively demonstrate this method. They expose employees to realistic scenarios, such as phishing campaigns, business email compromise, executive impersonation, and other social engineering tactics, in a controlled setting. This allows employees to practice identifying threats before facing them in actual situations. Regardless of whether employees click, report, verify, or ignore a simulated attack, security teams gather important information on areas where further training could be beneficial.
The same principle applies across other areas of security. Employees benefit from brief, targeted reinforcement around approved AI tools, data classification, password hygiene, remote work, secure collaboration, and incident reporting. Short, relevant interventions delivered throughout the year are more likely to become lasting habits than a single comprehensive training session.
Organizations are also changing how they evaluate security awareness. Rather than measuring success by course completion alone, they are asking a more important question: Are employees making better security decisions, and is organizational risk actually decreasing?
The research suggests the answer is increasingly yes. After implementing security awareness training, 67% of organizations reported a decrease in intrusions, security incidents, or breaches. That finding is significant because it connects awareness efforts to measurable improvements in security outcomes rather than simple participation metrics.
Organizations are also broadening how they measure effectiveness. The most common indicator is a reduction in security incidents, cited by 53% of respondents. Other commonly used measures include employee feedback (52%), security audits (50%), participation rates (47%), knowledge assessments (46%), training completion rates (42%), phishing simulation results (40%), and observed behavioral improvements (38%).
This broader approach offers a more accurate picture of workforce readiness. An employee may complete all required training modules yet still make poor security decisions when confronted with a convincing phishing email or an urgent payment request. Behavioral indicators, phishing simulations, and incident data provide stronger evidence that employees are applying what they have learned in real-world conditions.
Treating security awareness as an ongoing improvement effort rather than a compliance exercise also helps organizations pinpoint where additional support is needed. By combining incident data, simulation results, knowledge assessments, audit findings, participation metrics, and employee feedback, security teams can identify higher-risk users, departments, and workflows, enabling them to deliver reinforcement where it will have the greatest impact.
The move toward behavior-based security highlights a wider shift in organizations' perceptions of the human role in cybersecurity. Employees are no longer just passive recipients of awareness training. They are now seen as active contributors to reducing organizational risk.
Modern security awareness programs train employees to identify threats, safeguard sensitive data, use AI responsibly, report suspicious activity, and make wise security choices in daily work. These skills are crucial because employees are often the first line of defense against an incident becoming a breach.
Every day, employees face numerous security decisions. They decide whether to click a link, verify a wire transfer, approve access to shared documents, report suspicious emails, download attachments, use an approved AI assistant rather than a public one, or share customer information through the proper channel. They assess if a request seems routine or suspicious, whether information should stay in a secure portal rather than an email, and if something needs a second review before taking action. These small, routine decisions collectively influence an organization's overall security stance.
That's why awareness needs to be integrated into daily operations. Successful programs go beyond just outlining threats; they provide employees with the context, hands-on experience, and confidence to make secure decisions, especially when the best option isn't immediately clear. Security should become a routine part of daily work, rather than just an annual training exercise.
Behavior-focused programs build workforce resilience by supporting employees in making consistently better decisions amid the fast-changing landscape of cloud, collaboration, and AI-enabled environments.
Building workforce readiness requires more than just annual awareness sessions. Companies must offer ongoing reinforcement, practical exercises, tailored guidance for different roles, and clear metrics to track whether employee behavior enhances over time.
FortiSAT, Fortinet’s security awareness and training program, enables organizations to go beyond mere compliance by combining training, phishing simulations, user risk assessments, role-specific education, and focused reinforcement into a comprehensive program. These features assist security teams in pinpointing behaviors most associated with workforce risk, such as susceptibility to phishing, data management practices, ethical AI use, credential security, and incident reporting.
Realistic phishing simulations allow employees to practice detecting suspicious emails, executive impersonation, business email compromise, and other social engineering attacks in a safe setting before facing them in real situations. User risk insights help security teams pinpoint employees or departments that may need extra reinforcement, allowing organizations to direct resources most effectively.
Role-based learning enhances effectiveness by customizing training to match employees' daily tasks. Those involved in financial approvals, handling customer data, system administration, software development, customer support, or frequently using AI tools encounter distinct risks. Personalizing training for these roles makes security training more relevant and easier to integrate into their routine.
This integrated approach helps organizations build workforce readiness over time rather than treating awareness as a one-time compliance task. Through a blend of education, simulation, assessment, and ongoing reinforcement, Fortinet Training Institute programs help reduce workforce risk and empower employees to make improved security choices in cloud, collaboration, and AI-enabled contexts.
Learn More about FortiSAT, Fortinet’s security awareness and training program, and read the full 2025 Security Awareness and Training Global Research Report to see how organizations are building more resilient workforces through behavior-based security programs.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。