Cyber security training should not work like a podcast. It must offer concrete actions that reduce exposure, limit impact, and lead to measurable real-life changes.
Cyber Security = Technology + People
I find cybersecurity absolutely fascinating because it brings together two defining parts of our reality: technology and human behavior. Like in a thriller, the bad guys are constantly trying to outsmart the good guys, creating a never-ending cat-and-mouse chase.
Throughout my career, I have seen companies place most, if not all, of their focus on the technology designed to protect digital assets. Yet the statistics consistently show that many cyber attacks begin by exploiting predictable human behavior through social engineering.
For more than a decade, the world has increasingly recognized the need for cybersecurity awareness at both personal and organizational levels. But let me be blunt: awareness alone has no value if it does not lead to a change in knowledge or behavior. So here is the real question:
what does it take for awareness to lead to change?
The awareness problem
During my most recent holiday, I visited a beautiful Catholic church. I was so drawn in by the music that I stayed for the entire ceremony. Soon, I found myself captivated by the priest’s message. I felt genuinely inspired to change my life for the better. But an hour later, I was simply following the crowd outside, with no action items and no clear next step. Just like after listening to a podcast, the desire to change was already starting to fade away.

A week later, I could barely remember what had felt so meaningful in that moment. And that is exactly why the Church expects people to come back the following week.
Religion is built around the reality that people forget. So it creates systems that repeat the essentials until they stick. Hearing something once rarely changes how you live. And when an entire community remembers the same lesson together, at the same time, the message becomes emotionally stronger and easier to retain.
Many cybersecurity awareness programs still assume that the right information will somehow come back to people at exactly the right moment. It will not. And relying on that assumption is both wasteful and dangerous.
The 3 must-have components of a successful cyber attack
The National Institute of Standards and Technology (NIST) has long distinguished between awareness and training: awareness helps shape attitudes, while training is meant to build practical capability. More recent NIST guidance also suggests that many organizations still measure awareness by completion rates rather than by actual behavior change.
I have seen this firsthand: cybersecurity organizations often measure success by the amount of training delivered, not by the change it creates.
The purpose of cybersecurity training should be to reduce the impact of human vulnerability. To understand what that means in practice, it helps to step back and look at cyber attacks more broadly.
For any cyber attack to be successful, 3 key components must be in place:
- Threat (person or organization with a malicious intent).
- Vulnerability (could be in software, hardware, supply chain or people)
- Impact (a consequence serious enough to benefit the attacker, whether through ransomware payment, access, disruption, or other gain)

If even one of these three elements is missing, the attack does not succeed.
Now look at this model through the lens of people. In that case, the threat is almost always present. Human vulnerability is not only present too, but often the most heavily exploited:
Industry and academic research consistently identify human error as the leading cybersecurity risk (IBM 2024; Verizon 2023; Jeong 2024; IT Europa 2024).
We can reduce human vulnerability through awareness and training, but we cannot remove it entirely unless we remove humans from the system. That leaves one realistic lever: minimizing the impact a cyber attack can have.
Vigilance is a weak strategy
Many companies assume that if people spend enough hours in cybersecurity training and learn the key terms — phishing, MitM, MFA, OTP, and so on — they will be able to spot an attack and stop it in time. These programs often frame cybersecurity as a test of attentiveness: stay sharp, be careful, notice more, click less. Those are not bad lessons. They are just weak protection on their own.
Attacks that target human error are specifically designed to override critical thinking, vigilance, and logic. Even a quick look through McRaney’s You Are Not So Smart (2012) book will face with 48 distinct cognitive biases, fallacies, and self-delusions. Our brains are built to optimize, simplify, and extrapolate. That also makes us highly susceptible to well-designed social engineering.
With enough knowledge in behavioral psychology and social engineering I can confidently say:
Do not count on personal vigilance to prevent a cyber attack!
The goal should be to minimize impact so that constant vigilance is not required.
Minimize the impact
This is the mindset I wish more cybersecurity programs started with:
What can we put in place now to minimize the impact of a compromised moment?
In other words, the most useful protection is not better intuition, but proper preparation done in time. Put yourself in the shoes of an attacker for a second: would you spend days and weeks putting together an attack that will get you nowhere? Criminal hacking is a business. And like any business, it is only worth it when the reward is greater than the effort.
A friend of mine recently told me a story that had nothing to do with cybersecurity, yet it captured this point perfectly. He lives in a house and was working in front of his garage with the gate open. Then one thing led to another: the garage malfunctioned and closed with his house keys still inside. He started thinking about how to get back into the house while causing the least possible damage. When he had installed the front door, he had chosen the cheapest lock available. Suddenly, breaking the front door was not only the simplest option, it also meant there would finally be an upgrade. And yet, it still took two men an hour to break what looked like a very basic lock.
If it had been a real intruder, they likely would not have spent that much time forcing the lock. They would have looked for an easier way in, maybe a window. Or more likely, they would have convinced you to unlock the door yourself. And no amount of general awareness about break-ins would fully protect you from a prepared thief. The right circumstances would be created to exploit normal human instincts: a crying baby, a car crash, a new neighbor stopping by. The possibilities for manipulation are endless. So what can you do?

Once an intruder gets into the house, what can they actually take? If all your valuables are sitting in the living room, ready to grab, you become a very attractive target. But if someone looks through the window and sees nothing worth taking, if your assets are spread out, and if your valuables are locked away in different places, the effort starts to outweigh the reward. The house becomes less attractive.
The same applies in the digital world. If your digital environment is cleaned up, your assets are isolated, and important accounts are uniquely protected, you become a far less appealing target. If compromising one account does not create real damage and does not open the door to something bigger, you become much less worth the effort. That is what real protection looks like.
And with that mindset, cybersecurity awareness training can move beyond generic advice. It can focus on clear action items, practical checklists, and meaningful follow-up that leads to real change in everyday life.
Leave scary stories for Halloween and start mapping
There are many real-life examples of the consequences people and organizations face once they become targets of a cyber attack. That is awareness. But awareness alone does not lead to action—unless you understand how it applies to you, specifically.
Most people do not operate with a clear view of their own digital landscape. They think in isolated pieces: my email, my bank app, my Wi-Fi, my child’s tablet, my Netflix, my social media, my work laptop.
But attackers do not think in isolated pieces. They think in paths. If one account falls, what else can be reset through it? If your phone number is taken over, which accounts can be recovered through SMS? If your main email is compromised, how much of your digital life unravels behind it? If your smart devices sit quietly on the same network, what have you connected without realizing it?

That is why identification comes first. NIST’s Cybersecurity Framework 2.0 puts asset understanding at the center of risk management:
Identify what matters, understand relative impact, and prioritize action accordingly.
First map the digital landscape you operate in. Then identify dependencies, associated risks, and mitigation options. Finally, take action one step at a time. That is how real cybersecurity improves.
Build habits
Both religion and cybersecurity awareness rely on repetition. But in cybersecurity, repetition is not about hearing the same message again and again. It is about repeating the right behavior until it becomes an unquestioned habit.
Behavior doesn’t change because people intend to act. It changes when actions are repeated in the same context until they become automatic (Gardner, 2022; Singh et al., 2024)
If an organization wants employees to follow cybersecurity rules at work, it must recognize that those habits rarely begin at work. They begin in personal life, where people manage passwords, approve logins, click links, recover accounts, and respond to urgency without thinking twice.
That is why cybersecurity awareness should not stop at information. It should give people simple, repeatable actions they can practice in their own digital lives first: enabling MFA, creating a unique passsword-strategy, verifying requests before reacting, separating critical accounts, and noticing which account unlocks everything else. Once these behaviors become normal at home, they become far more natural at work too. That is how awareness turns into habit, and habit turns into real security.
Cyber security must respect reality
Like with most good things, too much of it can backfire quickly.
I have seen this throughout my career: when security controls create too much friction, people get creative and build workarounds. Not because they are reckless by nature, but because poorly designed security often pushes them to bypass it just to maintain their normal routines.

The goal is not to demand superhuman discipline. The goal is to design protection that works with people, not against them. Otherwise, the control itself becomes a cybersecurity risk.
Summary
Cybersecurity does not improve because people listen to scarry stories. It improves when people take action to minimize the potential impact of a cyber attack.
The real goal is not perfect vigilance. It is better preparation. That means making risks visible and building cyber security habits that can be sustained.
Be prepared, just in case
Cybersecurity training should not rely on the hope that people will remember the right lesson at exactly the right second, under pressure, while facing an attacker who has prepared to seem trustworthy.
Cyber security training must be specific, personal and measurable.
I want to remove the pressure to stay permanently vigilant. And provide practical solutions that limit the damage when life inevitably gets messy.
Visit EchionSecurity.com to see how actionable cybersecurity can work in practice.
Resources
National Institute of Standards and Technology. (2024). Building a Cybersecurity and Privacy Learning Program (NIST SP 800-50r1).
National Institute of Standards and Technology. (2024). The NIST Cybersecurity Framework (CSF) 2.0 (NIST CSWP 29).
Haney, J., et al. (2025). Workshop Summary Report for ConnectCon 2024: “Minding the Gaps in Human-Centered Cybersecurity” (NIST SP 1332).
Verizon. (2023). 2023 Data Breach Investigations Report (DBIR).
IBM. (2024). CISOs list human error as their top cybersecurity risk.
McRaney, D. (2012). You Are Not So Smart: Why You Have Too Many Friends on Facebook, Why Your Memory Is Mostly Fiction, and 46 Other Ways You’re Deluding Yourself. Penguin Publishing Group.
Gardner, B., Rebar, A. L., & Lally, P. (2022). How does habit form? Guidelines for tracking real-world habit formation. Cogent Psychology.
Singh, B., et al. (2024). Time to Form a Habit: A Systematic Review and Meta-Analysis of Health Behaviour Habit Formation and Its Determinants.


Leave a Reply