5 reasons users hate cybersecurity awareness training, and how to make them love it (2024)

If you want your security awareness training program to be effective, address these common user complaints.

It’s no exaggeration to say that most employees hate taking cybersecurity awareness training. It doesn’t have to be that way. I know of many security awareness training managers that do it so well that their employees not only enjoy it but ask for more of it. I know you think I’m lying, but I’m not. Here are some common complaints of security awareness training and how to make your users love it.

1. Cybersecurity awareness training is boring

It can be boring, at least the way most organizations do it. Make it more exciting, vary it, and make it a game. The average security awareness training involves a video presentation done by someone who could be explaining how babies are born or explaining the periodic table of the elements. It’s staid and unemotional. You’re lucky if it has some graphic elements or music in it.

I’m not saying that your security awareness training video has to be done with the shock jock energy of Robin Williams in the movie Good Morning, Vietnam, but you want your training to err on the side of too much energy.

The best training videos I’ve seen are from energetic presenters who know how to vary their voice and emotional pitches. They bring us along for the ride. Some of the most impressive videos I’ve seen use professional actors, cool backgrounds, background music, have storylines, and are shot by Hollywood-style production teams. It isn’t just one-camera shots from an iPhone with someone standing in front of a screen or chalkboard.

Security awareness training videos that look like professional, Netflix-style episodes are the ones I’ve seen employees ask for more of. Security awareness training companies do this sort of thing, or professional production companies will customize videos for your company. (Full disclosure: I work for a security awareness training company.)

Vary the training. If all you’re doing is showing videos, no matter how exciting they are, it’s going to get boring, especially if it’s the same style all the time. Instead, switch training content up. Use some videos that are entirely comics. Gamify the training. I’m not a gamer but turning education into a game appeals to a lot of people.

One of the most common games I’ve seen in security awareness training is where simulated, fake, phishing emails are sent to end-users, and the end-users are given a “button” in their email client that they can click to report any suspected phishing email. If the end-users of a group report 100% of the fake phishing emails in a given time period, they receive a reward. It can be special recognition in a company newsletter, gift cards, or a pizza party, for instance. The great part of this is that the users will be more likely to report real phishing emails having been part of the game.

2. Employees don’t understand the importance of security awareness training

Most end-users don’t understand the importance of security awareness training. When I was at Microsoft, every year I had to take training on the “Foreign Corrupt Practices Act” so I wouldn’t accidentally bribe a foreigner to buy Microsoft products or be bribed by a foreigner. My job in no way could ever be stretched to put me in a situation where that was going to be a possibility. I hated wasting my time on that training.

Most employees feel that way about all training, or at least training on something that hasn’t impacted their lives yet. Make sure that employees know how important security awareness training is to their own success and to the organization’s.

If the organization has been hacked, don’t hide the details. Let all employees know how it happened, what the hacker did, and how it could have been avoided. The best security awareness training videos I saw included the organization’s own employees relating how they got phished into clicking on something they shouldn’t have. They could see a coworker sharing how it happened, what mistakes they made, and what they could have done better.

Share the real-life stories of organizations like yours that have been hurt by cybersecurity incidents. With ransomware rampant, there are plenty of stories of companies and even entire cities shutdown for days to weeks, or that never recovered from a single cybersecurity event and shut down.

3. Security awareness training isn’t personal

If you want to make someone care, make it personal. Don’t just train them for protecting your business. Let employees know you care about them and their families. Give them training and tools to help them be more cybersecurity aware at home. Employees who train their spouses, parents, and children in cybersecurity awareness will be one of your best defenders at work.

4. Security awareness training isn’t timely

Make sure your security awareness training program is personalized, targeted to the user’s role, and appropriate for the time of the season. I didn’t like taking Foreign Corruption Practices Act training when it didn’t apply to me. No one would.

For example, don’t give training on how to avoid fake invoices and malicious wiring transfers to employees who don’t pay bills. When tax season rolls around, however, make sure all employees are trained on how to avoid fake W-2 information request schemes for their personal tax identification information, and that HR/payroll department employees receive training in how to avoid fake W-2 information requests from someone claiming to be their organization’s tax processor. Give instructions on how to avoid fake gift card scams around Christmas. Instruct people on how to appropriately patch their systems and how to appropriately recognize their installed anti-malware programs so they can’t be fooled by a fake version of either.

5. Security awareness training feels punitive

A lot of employees have told me how security awareness training seems one-sided and punitive. They have to take the training in a certain amount of time or they’ll get in trouble. You’ve got to motivate people to take the training, but if you make it fun and different, you can motivate people to want to learn more. The gamification I talked about earlier is a good way to do it.

For example, tell every employee who reports 100% of all real and simulated phishing emails for a year, that they will get an Amazon gift card. Make the amount enough so that they will care. Then tell them to watch a few videos to learn about what to be on the lookout for. Tell them every month they’ll get a different topic and that they’ll be tested on that topic and others in the following month. One month the topic is W-2 phishing and the next it’s a “clean desk” or screensaver lock audit. The gift card might cost your company $25, $50 or $100, but the return of a well-trained employee will be far more than that.

On a related note, I’m often asked if an employee should be fired or disciplined for failing a test or a real threat event. I know of companies, often in the financial industry, that will fire employees for one failed phishing email. I (and a thousand others) can phish anyone. If you signed off on that policy, know that someone can easily phish you.

You might think you can’t be phished, but you can. It has nothing to do with intelligence or street smarts. Everyone can be tricked. Everyone can make a mistake. I don’t understand unforgiving or overly harsh penalties, especially for first-time offenses. You will get far more productivity from an employee who feels valued and who has been given the appropriate training.

This is not to say that someone who always clicks on everything and does nothing to help strengthen your organization’s cybersecurity shouldn’t face consequences. Maybe those consequences are locking down their browser and email system so they can only communicate with pre-approved places and people, at least until they prove on successive future tests that they are responsible citizens who care about the organization. Having a locked down workstation is a pain, but at least they will understand the penalty and be given a chance to grow and improve.

Mastering Cybersecurity Awareness Training

If you are in charge of your organization’s computer security awareness program and you haven’t already read Transformational Security Awareness: What Neuroscientists, Storytellers, and Marketers Can Teach Us About Driving Secure Behavior, you should. It’s written by my friend and co-worker, Perry Carpenter. Perry ran security awareness training for a big company and then monitored the industry as a Gartner analyst. The book is far more about human psychology and what really motivates people to listen and learn than computer security education. It gets to the root of the issue.

I know many companies whose cybersecurity awareness training programs use all these tactics. They and their employees are better, happier, and safer because of them.

Related content

  • PODCASTS
  • VIDEOS
  • RESOURCES
  • EVENTS

SUBSCRIBE TO OUR NEWSLETTER

From our editors straight to your inbox

Get started by entering your email address below.

5 reasons users hate cybersecurity awareness training, and how to make them love it (2024)

FAQs

5 reasons users hate cybersecurity awareness training, and how to make them love it? ›

Without consistent reinforcement, employees gradually lose the knowledge, and 90% of it is gone within a week. The effectiveness of a training program hinges on its ability to engage. Unfortunately, many cyber security training materials fail to capture the attention of employees. They're bored with it.

What are the reasons for lack of cyber security awareness? ›

9 Reasons Why Most Cybersecurity Awareness Training Fails
  • Lack of Employee Engagement. Employee engagement is key to security awareness training effectiveness. ...
  • Outdated or Irrelevant Content and Training Methods. ...
  • One-Size-Fits-All Approach. ...
  • Failure to Connect Training with Real-World Scenarios. ...
  • Inadequate Metrics.
Apr 11, 2024

Why cybersecurity training fails? ›

Without consistent reinforcement, employees gradually lose the knowledge, and 90% of it is gone within a week. The effectiveness of a training program hinges on its ability to engage. Unfortunately, many cyber security training materials fail to capture the attention of employees. They're bored with it.

How does training impact cybersecurity awareness? ›

In a recent study, 80% of organisations said that security awareness training had reduced their staffs' susceptibility to phishing attacks. That reduction doesn't happen overnight, but it can happen fast — with regular training being shown to reduce risk from 60% to 10% within the first 12 months.

What are the factors affecting cybersecurity awareness? ›

Factors that influence cyber security awareness and practice among ICT strand students include knowledge of password security, browser security, and social media activities. Age and level of study also play a role in cybercrime awareness among university students.

What is the biggest problem in cybersecurity? ›

Top 10 Cybersecurity Threats:
  • Configuration Mistakes. ...
  • Poor Cyber Hygiene. ...
  • Cloud Vulnerabilities. ...
  • Mobile Device Vulnerabilities. ...
  • Internet of Things. ...
  • Ransomware. ...
  • Poor Data Management. ...
  • Inadequate Post-Attack Procedures. Holes in security must be patched immediately following a cybersecurity attack.
Jan 4, 2024

What is the biggest weakness in cyber security? ›

Top Cybersecurity Vulnerabilities
  • Zero-Day Vulnerabilities. ...
  • Unpatched Software. ...
  • Application Misconfiguration. ...
  • Remote Code Execution. ...
  • Credential Theft. ...
  • Security-Based Software. ...
  • Wi-Fi Security. ...
  • Firewalls.
Jan 22, 2024

What is the downside of cybersecurity? ›

High Cost of Implementation

Implementing advanced cyber security measures can be expensive, particularly for small businesses with limited resources. This includes the cost of hardware and software, and hiring skilled professionals to maintain and manage the security infrastructure.

What is the hardest part about cybersecurity? ›

One of the hardest things with cyber security is deciding which area to specialize in, as there are many career paths. From penetration testing to audit and compliance, blue teaming to malware analysis, there is something related to cyber security that will appeal to many different types of people.

Is cybersecurity a dying industry? ›

Cyber Security Job Market and Career Gap

There is currently a high demand for skilled cyber professionals in the job market. It is expected that by 2025 there will be 3.5 million unfilled cyber security jobs due to a lack of skilled professionals and a growing need to secure more and more systems.

How does cybersecurity affect people? ›

Cyberattacks are malicious attempts to access or damage a computer or network system. Cyberattacks can lead to the loss of money or the theft of personal, financial and medical information. These attacks can damage your reputation and safety.

What is the value of cybersecurity awareness training? ›

One of the primary benefits of cybersecurity awareness training is the ability to mitigate cyber risks through education. Organizations can create a more secure environment by providing employees with the knowledge and skills to identify and respond to potential threats.

What is the purpose of cyber awareness training? ›

Cyber security awareness training is important because it helps employees understand the risks and threats associated with cyber-attacks. By providing them with the knowledge and skills to identify potential cyber threats, organizations can significantly reduce the likelihood of falling victim to an attack.

What are the 5 threats to cyber security? ›

Defending against cyberthreats is a critical and ongoing process that requires a proactive and multifaceted approach. Social engineering, third-party exposure, cloud vulnerabilities, ransomware, and IoT are the top threats that organizations should focus on to protect their data, systems, and reputations.

What is the biggest risk in cyber security? ›

1) Phishing And Social Engineering. For several years now, phishing and social engineering have been one of the most widespread and most effective cyberattacks facing small businesses. Phishing, and its associated variants such as spear-phishing and business email compromise, is the most prevalent cyberthreat in the US ...

What are three key threats to cybersecurity programs? ›

Types of cyber threats your institution should be aware of include:
  • Malware.
  • Ransomware.
  • Distributed denial of service (DDoS) attacks.
  • Spam and Phishing.
  • Corporate Account Takeover (CATO)
  • Automated Teller Machine (ATM) Cash Out.

Which is the common reason of poor cyber security? ›

Poor credential management and authentication practices across organizations put everyone at risk. Often people use the same passwords, easy-to-guess passwords, or use unauthorized websites that put the company at risk. Hackers use these vulnerabilities to break into the company's network or system.

Why is there a cybersecurity shortage? ›

An inability to find people with the right skills, the struggle to keep employees who have those skills, and a shrinking hiring budget are the biggest causes cited for these skills gaps. Indeed, 54% of respondents said that the cybersecurity skills shortage situation has been getting worse in recent years.

What is poor cyber security awareness? ›

Poor cybersecurity management can allow systems to be infected by ransomware, a type of malware that encrypts files and prevents the original owner from accessing data. Perpetrators usually threaten to delete important data, publish sensitive information, or block access unless a ransom is paid.

What are the key challenges of cyber security? ›

10 Cyber security challenges and innovations
  • Advanced cyber attacks such as ransomware are on the rise. ...
  • Attacks on industrial IT systems are increasing. ...
  • Cyber criminals now operate internationally. ...
  • Supply chain attacks are increasing. ...
  • Cyber attack techniques are constantly evolving.

References

Top Articles
Latest Posts
Article information

Author: Duane Harber

Last Updated:

Views: 5611

Rating: 4 / 5 (71 voted)

Reviews: 94% of readers found this page helpful

Author information

Name: Duane Harber

Birthday: 1999-10-17

Address: Apt. 404 9899 Magnolia Roads, Port Royceville, ID 78186

Phone: +186911129794335

Job: Human Hospitality Planner

Hobby: Listening to music, Orienteering, Knapping, Dance, Mountain biking, Fishing, Pottery

Introduction: My name is Duane Harber, I am a modern, clever, handsome, fair, agreeable, inexpensive, beautiful person who loves writing and wants to share my knowledge and understanding with you.