Skip to main content

Security Awareness Training Has Been Polished Into Irrelevance

Disclaimer: The views and opinions expressed are my own and do not reflect the views, policies, or positions of my employer or any organization with which I am affiliated.

--- 

(Cyber)security awareness training (SAT) has long focused on recognizing threats inside the enterprise, but anyone who has dealt with a real compromise knows attacks rarely respect those boundaries. Real breaches are messy. They’re personal. 

They involve bad timing, strange messages, compromised friends, personal accounts, social media, reused credentials, AI-generated likenesses, family members, phone calls, desperation, embarrassment, deception, and sometimes outright threats or blackmail.

Yet we teach security awareness with polished graphics, spotless templates, friendly AI-generated illustrations, and scenarios where the suspicious answer is practically given.

What are we actually teaching people to recognize?

The problem is that training today focuses too heavily on...

  • Recognizing specific examples

  • Generalized content polished for quick consumption

Those approaches make training easier to produce and measure, but they're not designed to help people make better decisions when something unfamiliar happens outside the training environment.

So how do we design training that develops judgment instead of simply delivering content?

--- 

The Problem

Most awareness programs are built around presenting information.

Here’s what phishing looks like. Here’s our password policy. Here’s how to report an incident. Here’s what to do if someone asks for your MFA code.

Those topics matter, but presenting information is not the same as teaching, let alone teaching someone how to think.

If every phish is obviously suspicious, what happens when it isn’t? If every fake website looks obviously fake, what happens when an attacker clones Microsoft perfectly, or imperfectly but convincingly enough? If every social-engineering exercise begins with an obviously fraudulent request from the CEO, what happens when an attacker compromises a vendor account and continues an existing conversation?

We risk teaching employees to recognize security-awareness content instead of teaching them to recognize security problems.

That is fundamentally a pedagogical problem.

--- 

Breaches Aren't Brand Compliant

Attackers don't care about an organization’s visual standards. They don't care what font was approved, whether the logo is positioned correctly, or whether the interface follows the corporate design system. They don't care whether the experience looks polished enough for the LMS.

They care whether somebody clicks.

Sometimes an attack is beautifully designed. Sometimes it looks like garbage. Sometimes it arrives through a polished login portal. Sometimes it's a text message with misspelled words. Sometimes it comes through LinkedIn, Discord, or a personal email. Sometimes it's a phone call from someone pretending to be your bank, a coworker, a dead family member, the help desk, an executive, or law enforcement.

Attackers live off the land. They use whatever works. Security awareness training should prepare people for that reality.

Tangent, but can we stop calling attackers “hackers” in security training? If someone is breaching your organization, they're an attacker. If they're doing it for criminal purposes, they're a criminal.

“Hacker” isn't a synonym for either. Not all hackers are criminals, and not all criminals are hackers. Using the terms interchangeably is imprecise and reinforces an outdated stereotype that security education should have moved past by now. 

Stop co-opting our culture for your Security Awareness Month flyer.

--- 

Training to Recognize Training

Consider traditional phishing exercises. An employee receives a fake email containing a handful of deliberately inserted warning signs. Maybe the sender domain is slightly wrong. There's an urgent request. The grammar is bad. Someone wants gift cards.

The learner identifies the phishing email. Great. What, exactly, did they learn?

  • Bad grammar means phishing.

  • Urgency means phishing.

  • A strange domain means phishing.

Those can be useful signals, but none of them are universal.

Midnight Blizzard demonstrates the problem. Their phishing campaigns use legitimate, previously compromised accounts and infrastructure, meaning the sender domain may be correct and the message may come from an organization the recipient already knows or trusts. The language can be polished, grammatically correct, and tailored to the target, without obvious pressure or an obviously unusual request. 

In other words, the attack can remove many of the very cues employees are trained to look for. 

Generative AI can produce perfectly grammatical messages. A legitimate emergency can be urgent. An attacker may know exactly how an organization communicates because they have spent weeks observing it. Detecting these attacks requires more than spotting mistakes. It requires evaluating context, expectations, relationships, behavior, and whether a request actually makes sense for the situation.

Judgment comes from understanding patterns and inconsistencies, not from memorizing a checklist of visual mistakes.

Training has to reflect that.

--- 

You Cannot Teach Judgment Without Practice

Security awareness has become afraid of making learners think.

Everything needs to be easy. Everything needs to be obvious. Nobody should fail. Every exit ticket quiz needs an unmistakably correct answer. Every scenario needs a clearly suspicious choice. Every learner should complete the training as quickly as possible.

If we remove ambiguity, uncertainty, and the possibility of getting something wrong, we remove the conditions in which critical thinking develops.

That might produce fantastic completion statistics, but completion is not comprehension. If the goal is to build critical thinking, learners need opportunities to work through ambiguity, examine incomplete information, weigh competing signals, and make decisions without being handed an obvious answer.

    1. Does this request make sense?

    2. Is this normal behavior for this person?

    3. Was I expecting this request or message?

    4. How could I verify this independently?

    5. What information does this person already know about me?

    6. What could happen if the account sending this message has already been compromised?

Those are transferable skills.

Showing someone a giant banner that says, “THIS EMAIL MAY BE PHISHING,” and then asking whether the email is suspicious is not.

--- 

Breaches Start With People

Another problem is the artificial boundary security awareness programs create between personal and professional security. 

Employees do not exist only inside Microsoft 365.

They have personal email accounts, phones, social networks, spouses, children, parents, hobbies, financial accounts, cloud storage, old passwords, online identities, and enormous amounts of publicly available information.

Attackers know this. 

A personal email account may reveal information about someone’s workplace. LinkedIn can establish who they report to and who they work with. Social media may reveal that they are traveling. A compromised personal account can expose contacts, documents, recovery information, private conversations, or details that make a later attack more convincing.

A criminal might impersonate a family member, compromise someone the employee trusts, or use personal information to deceive, pressure, embarrass, threaten, or blackmail them.

The initial compromise doesn't have to happen inside the enterprise. The attacker pivots. The employee becomes the bridge between their personal life and the organization.

Security awareness training that teaches people what suspicious activity looks like inside the corporate environment ignores a huge portion of the actual threat landscape.

--- 

Protect the Person, Not Just the Account

Security awareness skills should work at home, too.

Verification: If someone makes an unexpected request, verify it through another trusted channel, such as a known phone number, email address, or another established means of contact.

Enterprise-only framing: Check the sender in Outlook, inspect the email banner, or contact the person through enterprise-approved communication methods.

Authentication: Understand MFA, recovery methods, credential reuse, password managers, and what authentication requests actually mean across both personal and work accounts.

Enterprise-only framing: Follow the organization’s sign-in requirements, password policy, and account-recovery process, and contact the help desk when access fails.

Impersonation & Manipulation: Recognize when someone may be pretending to be a friend, executive, vendor, bank, family member, coworker, or another trusted contact.

Enterprise-only framing: Recognize fraudulent messages pretending to come from an executive, coworker, vendor, the help desk, or another trusted business contact.

Context: Notice when an otherwise plausible request doesn't fit the situation, relationship, or circumstances.

Enterprise-only framing: Look for requests that don't match normal company processes, policies, roles, or communication patterns.

Reporting: Know when something is strange enough to ask for help instead of waiting for certainty that may never come.

Enterprise-only framing: Use the phishing-report button or contact the security team when something suspicious appears in a company account, system, or communication channel. Stop there and let someone else investigate.

These aren't blue-team skills. They aren't red-team skills. We're not turning every employee into a SOC analyst or penetration tester.

We're teaching security awareness.

The learner doesn't need to become a security practitioner. They need to become a more security-aware version of the person they already are.

--- 

AI Isn't Pedagogy

Generative AI made producing content incredibly easy.

Need fifty phishing emails? Generate them. Need an illustration? Generate it. Need another quiz? Generate it. Need a Finance version? Replace Human Resources with Finance and hit regenerate.

Generating instructional content is not the same as designing instruction.

AI is useful. It can brainstorm ideas, prototype scenarios, produce variations, create fictional artifacts, support learners, and reduce repetitive production work. Used thoughtfully, it can make instructional design faster and give designers more room to experiment.

AI can produce fifty examples without understanding why learners need fifty examples. It can generate a multiple-choice question without determining whether the question measures recall, recognition, judgment, or anything meaningful. It can make a scenario look polished without asking whether the learner actually has to think.

The danger is not that AI creates bad content. The danger is that it makes creating a lot of content so easy that volume, polish, and speed begin to look like instructional quality.

Pedagogy requires someone to decide what the learner should understand, what they should be able to do afterward, how they will practice, where they should struggle, and how we will know whether anything was actually learned.

AI can help build the training, but it cannot be the reason the training works.

Someone needs to ask why the lesson exists.

  • What behavior are we trying to change?
  • What misconception is this scenario meant to expose?
  • Could a learner solve this without actually thinking?
  • Does the artifact resemble something they might encounter outside the training environment?
  • What might a learner incorrectly take away from this example?
  • Is the difficulty appropriate?
  • Will anyone remember this next month?

A thousand AI-generated scenarios built without pedagogy are still a thousand poorly designed scenarios. Volume does not fix that. Neither does visual polish.

--- 

Security Training (Might) Need to Be Ugly

I've become convinced that security awareness training should sometimes be ugly.

Not inaccessible. Not confusing. Not broken. Ugly with intent.

The Internet's inconsistent. Criminal infrastructure's inconsistent. Real email's inconsistent. Scam pages can look terrible. Legitimate websites can look terrible. Malicious websites can look fantastic. People make typos. Software breaks. Messages arrive without context. Old interfaces linger for years. Employees are going to encounter all of it.

If every training experience looks like it passed through seventeen rounds of review before anyone was allowed to see it, we're creating a sterile environment that barely resembles what we claim to be preparing people for.

Security training should be polished enough to function and messy enough to require judgment.

That doesn't mean abandoning design. It means designing with intent.

Sometimes a deliberately ugly interface, strange email, broken-looking website, compressed screenshot, awkward message, or clumsy form can teach more than another immaculate AI-generated illustration of an employee standing next to a floating shield.

The goal isn't ugliness for its own sake. The goal is to expose learners to enough variation, ambiguity, and imperfection that they learn to evaluate what something is doing, not just what it looks like.

--- 

Criminals don't care whether the experience is aesthetically pleasing, and neither should our pedagogy.

The answer isn't to make everything harder or uglier. It's to design around skills instead of consumption.

Scenario-based exercises, simulations, storytelling, Capture the Flag mechanics, workshops, role-based training, and National Cybersecurity Awareness Month programming can all work well when they require learners to investigate, recognize patterns, make decisions, and receive meaningful feedback.

The format matters less than the learning objective.

A good exercise should require learners to practice what we expect them to do later.

  • If we want people to verify identity, make them verify.
  • If we want them to recognize manipulation, expose them to manipulation.
  • If we want them to recognize compromise, give them imperfect evidence and ask them to reason through what may have happened.
  • If we want them to report suspicious behavior, teach them how to decide when uncertainty itself is enough reason to report.

Security awareness shouldn’t exist just to make somebody finish training. It should make them better at navigating a hostile world.

--- 

Security Awareness Has to Evolve With Reality

Our industry has spent enormous amounts of time worrying about whether employees completed their annual training and nowhere near enough time asking whether that training made them better decision-makers.

The threat environment has changed. AI has made impersonation easier. Personal and professional identities overlap. Attackers operate through technical compromise, social manipulation, public information, compromised relationships, and channels completely outside organizational control.

If you are building security awareness training, stop asking whether the content looks professional. Ask whether someone had to think. Ask whether they practiced a useful skill. Ask whether the scenario reflects the uncertainty they will encounter in the real world. Ask whether the lesson would still help them if the attacker contacted their personal phone instead of their corporate email.

Perhaps most importantly, ask:

Would this training help someone make a better decision on the worst possible day to get it wrong?

That's the point...

Not the completion percentage. Not the visual standards. Not the AI-generated illustration. Not another green check mark. 

The decision.

Comments