惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
Visual Studio Blog
量子位
大猫的无限游戏
大猫的无限游戏
Hugging Face - Blog
Hugging Face - Blog
S
SegmentFault 最新的问题
Blog — PlanetScale
Blog — PlanetScale
月光博客
月光博客
Google DeepMind News
Google DeepMind News
小众软件
小众软件
WordPress大学
WordPress大学
宝玉的分享
宝玉的分享
MongoDB | Blog
MongoDB | Blog
B
Blog RSS Feed
博客园 - Franky
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
B
Blog
博客园 - 聂微东
The GitHub Blog
The GitHub Blog
Recent Announcements
Recent Announcements
Y
Y Combinator Blog
Microsoft Security Blog
Microsoft Security Blog
雷峰网
雷峰网
Jina AI
Jina AI
酷 壳 – CoolShell
酷 壳 – CoolShell

Fortinet All Blogs

The Cybersecurity Hiring Challenge | Fortinet Blog Casbaneiro: A Banking Trojan with Distributed Data-Receiving Servers | FortiGuard Labs FortiManagement Cloud: Centralized Network and Security Control for Distributed SMB Operations | Fortinet Blog Fortinet Joins Project Watershed 250 to Strengthen National Water Cybersecurity Infrastructure | Fortinet Blog Fortinet and FIRST: Strengthening Cyber Resilience through Global Collaboration | Fortinet Blog Someone Else Is Using Your AI | FortiGuard Labs The Industrialization of Cybercrime in Africa | Fortinet Blog Join the 2026 SASE Summit: Building Autonomous Trust for the AI Era | Fortinet Blog Defending Critical Infrastructure in the Age of Internet-Connected Facilities | Fortinet Blog Black Hat and DEF CON 2026: When Autonomous AI Became Operational | Fortinet Blog Public-Private Partnership Must Move at the Speed of Cyber Risk | Fortinet Blog Secure by Design: Fortinet’s Continued Commitment and the Work Ahead | CISO Collective Multi-Functional Linux Botnet “Evooo1Bot” | FortiGuard Labs Cybersecurity Skills Gap: More Than Just a Workforce Challenge | Fortinet Blog Fortinet Achieves IEC 62443-4-2 Security Level 4 Certification for FortiOS 7.6 | Fortinet Blog QuickFox Supply Chain Attack Used to Deploy FDMTP Implant | FortiGuard Labs From Threat Intelligence to Action: The First Cybercrime Bounty Is Now Live | Fortinet Blog While External Threats Are Driving Security Awareness, Internal Risks Are Growing | Fortinet Blog Canada Signs the UN Cybercrime Convention: Turning Global Agreement into Coordinated Action | Fortinet Blog Expert Density as Strategy: How 2F-IT Built One of Germany’s Deepest Fortinet Practices | Fortinet Blog From Awareness to Action: Helping Organizations Prepare for Post-Quantum Cryptography | Fortinet Blog A Conversation with Crime Stoppers International About Our Shared Cybercrime Bounty Initiative | Fortinet Blog Inside a TrickBot Variant Using DNS Tunneling for C2 | FortiGuard Labs Meeting the European Central Bank’s AI Cybersecurity Mandate | Fortinet Blog The TTF Trap: A Global Campaign of a Low-Detection Lua Loader | FortiGuard Labs Helping Law Enforcement Keep Pace with the Future of Cybercrime | Fortinet Blog FortiEndpoint Expands Security for the AI Era | Fortinet Blog Cyber Attacks Leveraging AI Require Behavior-First Security Training, Not Simply Better Awareness | Fortinet Blog The AI Era Needs a New SASE. Here’s What That Actually Looks Like. | Fortinet Blog Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula | FortiGuard Labs
From Awareness to Action: Building A Behavior-Based Secur...
Melonia da Gama · 2026-08-22 · via Fortinet All Blogs

Many organizations still rely on one-size-fits-all security awareness training, in which employees complete a course, acknowledge the organization's policies, and move on. While that approach establishes a baseline, it rarely changes how people make security decisions in their daily tasks.

Cyber risk is not evenly distributed across the workforce. Certain employees are more frequently targeted due to their role, access level, or visibility. Some regularly approve financial transactions, manage customer data, oversee critical systems, or use AI tools that pose unique risks. Similarly, some employees consistently display good security practices, while others need further guidance.

That reality is reshaping how organizations approach security awareness. Instead of providing identical content to everyone, organizations are increasingly building behavior-based security programs that tailor training to real risk, promote secure behaviors over time, and assess whether employees are making better security decisions so organizations can provide additional reinforcement where it's needed.

According to the 2025 Security Awareness and Training Global Research Report, 88% of organizations now tailor security awareness training to specific employee groups. Sixty-four percent provide additional training to users who are targeted more frequently. And 58% provide additional training for employees who demonstrate lower levels of security awareness or knowledge.

These findings reflect an important shift. Security awareness is evolving from a compliance exercise into an operational capability that improves workforce readiness by helping employees make better security decisions in the situations they encounter daily.

Awareness Alone Is Not Enough

Awareness of security risks alone doesn't ensure safe behavior. Employees who understand phishing may still click on convincing messages. Finance teams may still approve fraudulent payment requests. Customer-facing staff might share sensitive information through incorrect channels. And developers sometimes paste proprietary code into public AI tools for convenience. These issues are seldom due to a lack of awareness. Rather, they stem from failing to translate knowledge into secure actions when necessary.

Behavior-based security programs are designed to close that gap. Rather than treating every employee the same, organizations can tailor education to each role, exposure level, prior behavior, and the specific threats certain employees are most likely to encounter.

For example, finance teams benefit from guidance on invoice fraud, payment redirection, and executive impersonation. Developers require training in secure coding practices, AI-assisted development, and the risks of exposing proprietary code via public AI services. Sales and customer success teams need practical guidance on protecting customer information, handling meeting summaries, and responding to unusual requests. And executive assistants often need additional preparation for highly targeted social engineering attempts aimed at senior leadership.

This tailored approach does not make awareness programs more complicated. It makes them more relevant. When employees recognize that security training applies directly to the decisions they make every day, they are far more likely to change their behavior.

Continuous Reinforcement Changes Behavior

Changing behavior requires more than a single annual training session. While annual awareness training may satisfy a compliance requirement, it cannot keep pace with evolving attack techniques, emerging technologies, shifting business processes, or the growing use of AI across the workplace.

The research indicates that organizations are increasingly acknowledging this trend. Currently, 94% of respondents regularly carry out security awareness and training activities. About half of them conduct training quarterly, nearly one-third do so monthly, and just 16% depend only on annual sessions.

This change highlights a key learning principle: nearly every employee needs guidance when new tools like AI are introduced, as attack techniques evolve, and after risky behaviors occur. Furthermore, training is most effective when provided close to the decision point rather than months beforehand.

Phishing simulations effectively demonstrate this method. They expose employees to realistic scenarios, such as phishing campaigns, business email compromise, executive impersonation, and other social engineering tactics, in a controlled setting. This allows employees to practice identifying threats before facing them in actual situations. Regardless of whether employees click, report, verify, or ignore a simulated attack, security teams gather important information on areas where further training could be beneficial.

The same principle applies across other areas of security. Employees benefit from brief, targeted reinforcement around approved AI tools, data classification, password hygiene, remote work, secure collaboration, and incident reporting. Short, relevant interventions delivered throughout the year are more likely to become lasting habits than a single comprehensive training session.

Organizations Are Measuring What Works

Organizations are also changing how they evaluate security awareness. Rather than measuring success by course completion alone, they are asking a more important question: Are employees making better security decisions, and is organizational risk actually decreasing?

The research suggests the answer is increasingly yes. After implementing security awareness training, 67% of organizations reported a decrease in intrusions, security incidents, or breaches. That finding is significant because it connects awareness efforts to measurable improvements in security outcomes rather than simple participation metrics.

Organizations are also broadening how they measure effectiveness. The most common indicator is a reduction in security incidents, cited by 53% of respondents. Other commonly used measures include employee feedback (52%), security audits (50%), participation rates (47%), knowledge assessments (46%), training completion rates (42%), phishing simulation results (40%), and observed behavioral improvements (38%).

This broader approach offers a more accurate picture of workforce readiness. An employee may complete all required training modules yet still make poor security decisions when confronted with a convincing phishing email or an urgent payment request. Behavioral indicators, phishing simulations, and incident data provide stronger evidence that employees are applying what they have learned in real-world conditions.

Treating security awareness as an ongoing improvement effort rather than a compliance exercise also helps organizations pinpoint where additional support is needed. By combining incident data, simulation results, knowledge assessments, audit findings, participation metrics, and employee feedback, security teams can identify higher-risk users, departments, and workflows, enabling them to deliver reinforcement where it will have the greatest impact.

From Awareness to Resilience

The move toward behavior-based security highlights a wider shift in organizations' perceptions of the human role in cybersecurity. Employees are no longer just passive recipients of awareness training. They are now seen as active contributors to reducing organizational risk.

Modern security awareness programs train employees to identify threats, safeguard sensitive data, use AI responsibly, report suspicious activity, and make wise security choices in daily work. These skills are crucial because employees are often the first line of defense against an incident becoming a breach.

Every day, employees face numerous security decisions. They decide whether to click a link, verify a wire transfer, approve access to shared documents, report suspicious emails, download attachments, use an approved AI assistant rather than a public one, or share customer information through the proper channel. They assess if a request seems routine or suspicious, whether information should stay in a secure portal rather than an email, and if something needs a second review before taking action. These small, routine decisions collectively influence an organization's overall security stance.

That's why awareness needs to be integrated into daily operations. Successful programs go beyond just outlining threats; they provide employees with the context, hands-on experience, and confidence to make secure decisions, especially when the best option isn't immediately clear. Security should become a routine part of daily work, rather than just an annual training exercise.

Behavior-focused programs build workforce resilience by supporting employees in making consistently better decisions amid the fast-changing landscape of cloud, collaboration, and AI-enabled environments.

Build Workforce Readiness with Fortinet Training

Building workforce readiness requires more than just annual awareness sessions. Companies must offer ongoing reinforcement, practical exercises, tailored guidance for different roles, and clear metrics to track whether employee behavior enhances over time.

FortiSAT, Fortinet’s security awareness and training program, enables organizations to go beyond mere compliance by combining training, phishing simulations, user risk assessments, role-specific education, and focused reinforcement into a comprehensive program. These features assist security teams in pinpointing behaviors most associated with workforce risk, such as susceptibility to phishing, data management practices, ethical AI use, credential security, and incident reporting.

Realistic phishing simulations allow employees to practice detecting suspicious emails, executive impersonation, business email compromise, and other social engineering attacks in a safe setting before facing them in real situations. User risk insights help security teams pinpoint employees or departments that may need extra reinforcement, allowing organizations to direct resources most effectively.

Role-based learning enhances effectiveness by customizing training to match employees' daily tasks. Those involved in financial approvals, handling customer data, system administration, software development, customer support, or frequently using AI tools encounter distinct risks. Personalizing training for these roles makes security training more relevant and easier to integrate into their routine.

This integrated approach helps organizations build workforce readiness over time rather than treating awareness as a one-time compliance task. Through a blend of education, simulation, assessment, and ongoing reinforcement, Fortinet Training Institute programs help reduce workforce risk and empower employees to make improved security choices in cloud, collaboration, and AI-enabled contexts.

Learn More about FortiSAT, Fortinet’s security awareness and training program, and read the full 2025 Security Awareness and Training Global Research Report to see how organizations are building more resilient workforces through behavior-based security programs.