惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

腾讯CDC
The Cloudflare Blog
IT之家
IT之家
V
V2EX
雷峰网
雷峰网
MyScale Blog
MyScale Blog
P
Proofpoint News Feed
Stack Overflow Blog
Stack Overflow Blog
博客园 - Franky
Engineering at Meta
Engineering at Meta
S
SegmentFault 最新的问题
GbyAI
GbyAI
Microsoft Azure Blog
Microsoft Azure Blog
博客园 - 司徒正美
云风的 BLOG
云风的 BLOG
小众软件
小众软件
博客园 - 叶小钗
Blog — PlanetScale
Blog — PlanetScale
C
Check Point Blog
A
About on SuperTechFans
B
Blog
月光博客
月光博客
宝玉的分享
宝玉的分享
Last Week in AI
Last Week in AI

Fortinet All Blogs

FortiSOAR 8.0 Unites Agentic AI and Automation to Revolutionize Security Operations | Fortinet Blog The Cybersecurity Hiring Challenge | Fortinet Blog Casbaneiro: A Banking Trojan with Distributed Data-Receiving Servers | FortiGuard Labs FortiManagement Cloud: Centralized Network and Security Control for Distributed SMB Operations | Fortinet Blog Fortinet Joins Project Watershed 250 to Strengthen National Water Cybersecurity Infrastructure | Fortinet Blog Fortinet and FIRST: Strengthening Cyber Resilience through Global Collaboration | Fortinet Blog Someone Else Is Using Your AI | FortiGuard Labs The Industrialization of Cybercrime in Africa | Fortinet Blog Join the 2026 SASE Summit: Building Autonomous Trust for the AI Era | Fortinet Blog Defending Critical Infrastructure in the Age of Internet-Connected Facilities | Fortinet Blog Black Hat and DEF CON 2026: When Autonomous AI Became Operational | Fortinet Blog Public-Private Partnership Must Move at the Speed of Cyber Risk | Fortinet Blog Secure by Design: Fortinet’s Continued Commitment and the Work Ahead | CISO Collective From Awareness to Action: Building A Behavior-Based Security Program | Fortinet Blog Multi-Functional Linux Botnet “Evooo1Bot” | FortiGuard Labs Cybersecurity Skills Gap: More Than Just a Workforce Challenge | Fortinet Blog Fortinet Achieves IEC 62443-4-2 Security Level 4 Certification for FortiOS 7.6 | Fortinet Blog QuickFox Supply Chain Attack Used to Deploy FDMTP Implant | FortiGuard Labs From Threat Intelligence to Action: The First Cybercrime Bounty Is Now Live | Fortinet Blog Canada Signs the UN Cybercrime Convention: Turning Global Agreement into Coordinated Action | Fortinet Blog Expert Density as Strategy: How 2F-IT Built One of Germany’s Deepest Fortinet Practices | Fortinet Blog From Awareness to Action: Helping Organizations Prepare for Post-Quantum Cryptography | Fortinet Blog A Conversation with Crime Stoppers International About Our Shared Cybercrime Bounty Initiative | Fortinet Blog Inside a TrickBot Variant Using DNS Tunneling for C2 | FortiGuard Labs Meeting the European Central Bank’s AI Cybersecurity Mandate | Fortinet Blog The TTF Trap: A Global Campaign of a Low-Detection Lua Loader | FortiGuard Labs Helping Law Enforcement Keep Pace with the Future of Cybercrime | Fortinet Blog FortiEndpoint Expands Security for the AI Era | Fortinet Blog Cyber Attacks Leveraging AI Require Behavior-First Security Training, Not Simply Better Awareness | Fortinet Blog The AI Era Needs a New SASE. Here’s What That Actually Looks Like. | Fortinet Blog
While External Threats Are Driving Security Awareness, In...
Melonia da Gama · 2026-07-28 · via Fortinet All Blogs

External threats remain among the primary reasons organizations invest in security awareness and training. Phishing, ransomware, credential theft, social engineering, and attacks on peer organizations all reinforce the same point: Employee behavior directly affects an organization’s cyber risk.

According to the Fortinet Training Institute 2025 Security Awareness and Training Global Research Report, 41% of respondents cite external threats as the primary driver for implementing security awareness and training programs. Organizations face a threat landscape shaped by organized cybercrime, ongoing reconnaissance, shorter time-to-exploit, and the growing use of stolen credentials and access paths. These pressures help explain why external threats remain the top motivator for cybersecurity training in 2025.

But organizations increasingly recognize that workforce risk no longer begins and ends with external attackers.

Cyber risk now moves through everyday employee workflows, data-handling practices, cloud applications, collaboration platforms, and AI tools. As digital environments become more interconnected, organizations are shifting their focus to the operational behaviors that can unintentionally expose sensitive information or create exploitable gaps. The result is a broader understanding of workforce risk, one that extends beyond phishing awareness.

Internal Risk Is Becoming Harder to Ignore

The 2025 findings show that 27% of survey respondents have adopted security awareness and training to protect against insider risks, up from 4% in 2024. The addition of new insider risk options in the 2025 survey may account for some of that increase, but the shift also reflects a growing recognition that internal exposure now accounts for a larger share of organizational cyber risk.

Most insider-related incidents are not driven by malicious intent. They often stem from routine workplace actions: mishandling sensitive data, using unapproved applications, sharing information via unauthorized tools, reusing credentials, or falling for increasingly sophisticated social engineering attempts.

This concern aligns with findings from Fortinet’s 2026 Cybersecurity Skills Gap Global Research Report, which found that more than half of respondents reported breaches caused by insufficient cybersecurity awareness. That finding underscores why internal risk is receiving more attention. Many breaches still stem from human decisions, such as clicking malicious links, mishandling data, reusing credentials, or using unapproved tools.

The issue is not employee intent but the growing complexity of modern digital workflows. Employees frequently switch between systems, data, and external services. Cloud apps, remote work, collaboration platforms, personal devices, and generative AI have increased the number of points at which sensitive information can be mishandled or exposed. As digital workflows expand, the risk of accidental exposure rises.

Security awareness programs can no longer focus solely on identifying obvious scams or suspicious emails. Training must equip employees to navigate risk in their everyday work activities.

Data Security Has Become the Behavioral Battleground

This heightened emphasis on internal risk is reflected in the topics organizations consider most important. In 2025, data security was the top focus for awareness and training, cited by 51% of respondents. Data privacy ranked second at 43%, and AI-based tools and threats ranked third at 41%.

Training activity largely reflects those priorities. In the past year, 50% of organizations provided employee training on data security, 43% on data privacy, and 42% on AI tools and threats.

This alignment is important because data security is where security policy translates into employee behavior. Data security and privacy shape daily decisions about where information is stored, who has access, which applications are approved, and what information can be shared externally. Employees therefore need practical guidance for moments when risk arises, not just reminders to protect sensitive information.

Practical guidance matters in everyday workplace situations: uploading a document, approving access, using a collaboration tool, responding to a request, or deciding whether to enter information into an AI prompt. These are the moments when employees can reduce risk, but only if they understand what secure action looks like.

AI Accelerates Internal Exposure Risk

AI adds another layer of complexity to internal exposure. Employees use AI tools to summarize documents, generate content, analyze data, write code, and support customer interactions. These tools can boost productivity, but they also create new pathways for sensitive information to leave approved workflows.

An employee may use an unapproved AI tool because it seems convenient. Another may paste internal data into a prompt without recognizing the risk of exposure. Still others may assume that AI-generated summaries, recommendations, or code are reliable without sufficient review. As AI becomes more integrated into everyday work, these risks become increasingly difficult to manage through policy alone.

Organizations need training that helps employees understand both how to use AI safely and how attackers may exploit AI to enhance phishing, impersonation, and social engineering attacks. Employees should know which tools are approved, what data can be shared, when outputs require human review, and when additional guidance is needed.

As AI adoption grows, security awareness programs must address both sides of the challenge: enabling employees to use AI responsibly while helping them recognize AI-enabled threats that are increasingly difficult to detect.

Training Must Evolve from Awareness to Operational Decision-Making

Security awareness training is often framed as a compliance requirement, but the 2025 findings point to a more practical role. Training helps organizations reduce risk across the workforce by equipping employees with the knowledge and habits to make safer decisions.

Employees still need to understand external threats, but they also need guidance on internal actions that increase risk. That includes safeguarding sensitive data, reporting suspicious activity, using AI tools responsibly, adhering to access policies, and recognizing when a routine request may be unusual.

The research also shows that employee and leadership support remain strong. Eighty-eight percent of employees view security awareness and training positively, while 95% of corporate leaders support it to some degree. This support provides organizations with a strong foundation to build on. The next step is to ensure that training keeps pace with the risks employees face.

Organizations Need Scalable Behavior-First Readiness

Even when organizations recognize the value of security awareness training, implementation can be challenging. According to the 2025 report, personnel limitations were the primary barrier to earlier adoption, with 34% of respondents citing them as the reason for delayed implementation. Budget constraints were the next most common obstacle at 19%, followed by competing security priorities at 18%.

These obstacles are understandable. Security teams already manage incident response, compliance, cloud security, vulnerability management, identity controls, and digital transformation initiatives. When teams are short-staffed or pressed for time by urgent operational demands, training can be deprioritized.

But delaying awareness training can leave an important risk-reduction opportunity untapped. Employees continue to face phishing attempts, suspicious requests, credential theft, unsafe data practices, and emerging AI risks, even when formal training is in place. The key question is whether they are prepared to identify and handle these risks when they arise.

Organizations need scalable training that reinforces secure behavior over time. That means shorter, more frequent learning experiences; role-specific guidance; practical scenarios; and regular updates as threats, tools, and policies evolve. The goal is to build readiness into how employees work, rather than treating security awareness as a once-a-year exercise.

The challenge for organizations is no longer simply teaching employees to recognize threats. It is enabling them to make secure decisions across increasingly complex digital workflows. As AI, cloud applications, and collaboration platforms become more deeply embedded in everyday work, security awareness programs must evolve from information delivery to workforce risk management.

Security Awareness Training Must Address Both External Attacks and Internal Risk

External threats will continue to drive investment in security awareness and training. At the same time, organizations recognize that cyber risks often stem from routine employee interactions with data, applications, collaboration tools, and AI systems. Consequently, security awareness initiatives need to do more than just teach employees how to recognize attacks. They need to enable employees to make safer decisions in their everyday tasks.

Fortinet Security Awareness and Training helps organizations address this challenge from both sides. Employees are trained to identify phishing, impersonation, business email compromise, and other common attack methods. They also learn to manage sensitive information properly, use approved tools, adhere to security policies, and respond appropriately to security risks.

By integrating awareness, simulation, assessment, and role-specific training, organizations can reinforce secure behaviors where they matter most: within everyday workflows. The result is a more educated and resilient workforce that helps reduce risk across users, data, applications, and AI-enabled environments.

Explore Fortinet’s security awareness and training program (FortiSAT), and read the full 2025 Security Awareness and Training Global Research Report to learn how organizations are preparing employees to reduce risk across today’s evolving threat landscape.