Cybersecurity Awareness Month

Security Culture as a Business Resilience Capability

For years, organizations have invested in strengthening the technical foundations of cybersecurity while building employee awareness through training and phishing simulations. Both remain essential, but the environment in which employees make security decisions is changing. Social engineering is becoming faster, more scalable, and more convincing, with AI giving attackers new capabilities to research targets, create credible communications, and personalize attacks. At the same time, employees are no longer being approached primarily through email. The same techniques of urgency, authority, and trust now appear through SMS, voice calls, collaboration platforms, QR codes, and authentication workflows.

If we are to look at recent data, Microsoft’s 2025 Digital Defense Report found that 28% of breaches investigated by Microsoft Incident Response began with phishing or social engineering, while Verizon’s 2026 Data Breach Investigations Report found that the human element was involved in 62% of breaches. In addition, Verizon also found that mobile-centric social engineering simulations using channels such as voice and text achieved a 40% higher median success rate than email. The challenge is therefore not simply that employees need to recognize more threats; they increasingly need to make sound security decisions in situations where the attack may look and feel legitimate. 

This changes the conversation around security awareness. Knowing what phishing is, completing annual training, or recognizing the indicators of a familiar attack remains valuable, but knowledge alone does not guarantee the right action when an employee is under time pressure, responding to someone they trust, or dealing with a situation they have not seen before. The business objective must therefore extend beyond awareness toward behavior: creating an environment in which employees verify, question, report, and make security-conscious decisions as a natural part of their work. 

That is where security culture becomes important. Security culture is not a replacement for awareness or technical controls, but the connection between them. It is what turns security knowledge, leadership expectations, and technical investment into consistent behavior across the organization. For security leaders, the question is no longer only whether employees have been trained, but whether the organization has created the conditions in which secure behavior can be sustained. 

From Security Roadmap to Security Culture 

How technology, leadership, and employee engagement create shared responsibility. 

Technology strengthens the foundation. Awareness builds capability. Culture turns both into consistent action. 

Technology Alone Does Not Change Behavior 

The limitations of a technology-first approach become clearer when we look at how security transformation works in practice. In one case handled by Truesec, an organization was adopting a broader Security Roadmap that included implementing the Microsoft security stack, including the Microsoft Defender suite, to strengthen its ability to prevent, detect, and respond to cyber threats. These controls were essential, but they could not make every decision for every employee. People still open messages, approve requests, share information, use digital tools, work remotely, and interact with visitors. Each of these moments can strengthen resilience or introduce risk. 

As the roadmap progressed, the focus therefore expanded beyond technical controls to the role employees play in the organization’s security. The question was not simply whether employees had received security information, but whether they were equipped and supported to make secure decisions as part of their everyday work. 

This is why security awareness cannot be treated only as a requirement. Employees may complete a module, recognize an obvious simulation, and still hesitate when faced with a convincing request in the flow of work. The leadership question is therefore not simply whether training has been delivered. It is whether secure thinking has become part of everyday decision-making. 

This distinction becomes particularly relevant in situations where there is no obvious warning sign. An employee may understand the risks associated with unexpected authentication requests but still approve one while distracted or under pressure. Another may know that unusual payment instructions should be verified but hesitate to challenge a request that appears to come from senior management. In these situations, knowledge is important, but the outcome ultimately depends on behavior. 

Truesec has seen this challenge emerge from different starting points. Some organizations already have an awareness platform in place, but struggle to achieve meaningful employee engagement. Others are further ahead in their technical security transformation, while structured awareness activities and phishing exercises are still developing. Despite these differences, the issue is often similar: cybersecurity continues to be perceived primarily as an IT or security responsibility rather than something shared across the organization. 

This is where the connection between the technical and human sides of security becomes important. Strengthening controls can reduce exposure and improve detection and response, but building resilience also requires employees to understand their role and feel confident acting when something does not look right. The objective is not to turn employees into security specialists, but to make secure decision-making a natural part of how the organization operates. 

Technology can strengthen protection, and security awareness can build knowledge. Security Culture determines whether secure behavior is sustained in everyday work. 

Why Awareness Programs Often Struggle

  • Training is experienced as a compliance exercise rather than practical support. 
  • Security messages appear periodically instead of in the moments that matter. 
  • Guidance feels disconnected from employees’ roles and daily decisions. 
  • Ownership remains concentrated in Security or IT rather than across the business. 
  • Success is measured mainly through completion rates, leaving behavior and engagement less visible. 

 

The Path From Awareness to Culture

Security culture develops through repeated experiences. Organizations do not move from annual training to shared ownership in a single step. A simple maturity model can help leaders assess where their current program is strong and where additional attention is needed. 

Turn Awareness Into Practical Security Capability

Effective security training should go beyond telling employees what secure behavior looks like and show them how to perform it in practice. Role-based, hands-on guidance can teach employees how to create and send an encrypted email, configure a service securely, design a secure architectural foundation, and write secure code. This helps translate security principles into repeatable skills that employees can apply confidently in their daily work. 

Moreover, an awareness program is defined by what the organization delivers. A security culture is reflected in how people behave when no campaign is running. Employees ask questions, report uncertainty, challenge suspicious situations, and discuss risk openly. Leaders reinforce these behaviors by making security visible in decisions and communications. 

The objective is therefore not simply to expose employees to more security content, but to create the conditions in which secure behaviors becomes part of normal business practice. This includes making it easy to verify unusual requests, report suspicious activity, ask questions, and challenge situations that do not align with established processes. 

Leadership reflection: If the platform were switched off tomorrow, which secure behaviors would continue because they are already part of how the organization works? 

The Seven Dimensions of Human Behavior 

Lasting security culture depends on more than knowledge. The seven dimensions below provide a practical diagnostic for understanding why secure behavior succeeds or breaks down in everyday work. 

1. Attitudes. Whether people believe security is important, worthwhile, and relevant to their work. 

2. Behavior. What people actually do in real situations, especially when they are under time, workload, or authority pressure. 

3. Cognition. Whether people understand the risk, recognize warning signs, and know what secure action to take. 

4. Compliance. Whether policies and procedures are clear, practical, and followed consistently rather than bypassed for convenience. 

5. Communication. Whether employees can ask questions, report concerns, and speak up early without fear of blame. 

6. Norms. The unwritten expectations created by what leaders and colleagues repeatedly model, reward, and accept. 

7. Responsibilities. Whether individuals understand their role, take ownership, and act instead of assuming that Security or IT will handle the issue. 

Used together, the dimensions help leaders move beyond completion rates. They reveal whether a program is changing understanding, decisions, dialogue, shared expectations, and ownership across the organization. 

They also help explain why knowledge alone does not consistently translate into secure action. Employee decisions are influenced not only by what people know, but also by workload, leadership expectations, established processes, peer behavior, and whether speaking up is encouraged and supported. Looking at these dimensions together gives leaders a broader view of the organizational conditions that influence human risk. 

Building a Program Around People 

Another important component of building security culture, reflected across the 7 dimensions and the cases above, is that the program needs to be built around people and how they actually work. Awareness activities are more likely to influence behavior when they reflect employees’ starting point, the situations they encounter, and the decisions they are expected to make. This means moving beyond simply delivering training and instead creating a program that can develop over time as employee understanding and engagement grow. 

A good example of how this can be approached comes from another case handled by Truesec, where the organization wanted to make cybersecurity a topic employees actively engaged with rather than something they encountered only through mandatory training. 

Regular phishing campaigns and awareness training created structure and a basis for measurement, but they were treated as the starting point rather than the complete program. Where employees had no previous baseline, the program began gradually with general cybersecurity knowledge before moving toward more realistic scenarios. This helped employees build confidence while giving management better insight into progress and areas requiring attention. 

Security technology and awareness platforms can provide a foundation. Culture grows when leadership, training, communication, onboarding, reporting processes, and practical experiences reinforce one another. 

The approach worked because technical safeguards, management involvement, and employee learning reinforced one another. Employees encountered security repeatedly, through different channels and in ways that connected to daily work. Structured learning provided consistency. Communication built relevance. Practical experience made the subject memorable. Onboarding and accessible guidance helped turn expectations into everyday support. 

From Participation to Shared Responsibility 

In these examples, the most meaningful result was not the number of modules completed or campaigns delivered. It was the change in employee mindset and behavior. As the programs matured, employees became more aware of the cybersecurity landscape and more confident in identifying suspicious activity. Cybersecurity became less abstract and more closely connected to daily work. 

Phishing results indicated that employees were becoming better equipped to recognize threats, while increasingly realistic scenarios challenged employees to apply what they had learned. Equally important, employees began talking more about cyber risk. Security became a subject of conversation rather than a topic owned only by Security or IT. That shift matters because discussion, questions, and shared observations are signs that awareness is moving from individual learning into collective behavior. Employees also began raising questions about suspicious SMS messages, private phones, and apps, showing that cybersecurity thinking was extending beyond mandatory workplace training. 

What Changed for the Organizations?

  • Employees gained a central place to find cybersecurity information and practical guidance. 
  • New employees were introduced to security basics and internal policies through onboarding. 
  • Policies and procedures became easier to access and more connected to everyday work. 
  • Training and phishing campaigns provided structure and measurement. 
  • Events, articles, and physical security initiatives made cybersecurity more visible and relevant. 
  • Employees became more involved and more willing to discuss cyber risks, including concerns that extended beyond the workplace. 

Business value: A stronger security culture can support reduced human-related risks, clearer incident reporting, greater employee confidence, stronger organizational resilience, and better alignment between technical security investment and employee behavior. 

The cases also demonstrate that there is no single starting point for building security culture. Some organizations begin with mature technical controls but limited employee engagement; others already have awareness tools but need to increase participation and business ownership. The practical starting point is to understand the organization’s current maturity, identify the behaviors that matter most to its risk profile, and build a program that connects technology, communication, leadership, and the employee experience around those behaviors. 

Five Lessons for Security Leaders

  1. Treat awareness as a continuous program 
    Annual training may establish a baseline, but lasting change requires regular reinforcement. Build a rhythm that keeps security visible without overwhelming employees. 
  2. Meet employees where they are 
    Use channels employees already engage with. Combine training with onboarding, internal communication, accessible guidance, events, and team-level conversations. 
  3. Make security relevant 
    Explain why a behavior matters and connect guidance to realistic decisions. Relevance helps employees apply knowledge when a situation is unfamiliar or ambiguous. 
  4. Create participation, not only consumption 
    Practical exercises and collaborative experience can make security more tangible. Employees should have opportunities to ask, practice, report, and discuss. 
  5. Measure more than completion 
    Use completion and simulation results as inputs, not as the whole picture. Share relevant insights with leadership and look for reporting behavior, engagement, questions, recurring uncertainties, and visible management support. 

The goal is not simply to create employees who pass phishing test. The goal is to create an environment where secure behavior becomes a natural and sustainable part of how people work. 

Building Long-Term Cyber Resilience

A mature security roadmap should improve technology, controls, people, and processes together. Awareness training is necessary, but it is not enough on its own. Stronger outcomes emerge when security becomes part of employee experience: introduced during onboarding, reinforced through communication, supported by accessible policies and guidance, made tangible through practical activities, and discussed openly across the organization. 

The organizations that create lasting improvement understand an important truth: cybersecurity is not only a technology challenge. It is also a people and culture challenge. When employees understand their role, feel supported, and make security-conscious decisions as part of daily work, the organization develops a stronger and more sustainable foundation for resilience. 

As AI increases the speed and scale of social engineering and attackers continue to expand across communication channels, that foundation becomes more important. Awareness remains necessary, but the strategic objective is broader: translating knowledge into behavior and embedding secure decision-making into everyday work. 

Technology builds the foundation. Awareness provides knowledge. Leadership creates credibility. Shared ownership creates culture. 

Stay ahead with cyber insights

Newsletter

Stay ahead in cybersecurity! Sign up for Truesec’s newsletter to receive the latest insights, expert tips, and industry news directly to your inbox. Join our community of professionals and stay informed about emerging threats, best practices, and exclusive updates from Truesec.

Latest Insights