Security Culture Is Not an Awareness Campaign: Why the Distinction Matters
Annual training modules produce tick-box compliance. Building real security culture requires a different model, one grounded in how behaviour actually changes, not how it is measured.
The security awareness industry is built on a category error. It conflates awareness with behaviour. Awareness is the state of knowing that something exists. Behaviour is what a person does when they encounter it. The gap between the two is wide, empirically consistent, and almost never addressed in standard security awareness programmes. Employees who have completed phishing awareness training continue to click phishing links. Employees who can describe password best practice continue to reuse passwords. Awareness is necessary but it is not sufficient, and treating it as sufficient is the root cause of the awareness industry's persistent failure to produce measurable risk reduction.
Building genuine security culture requires a model grounded in the behavioural science of how practices become habitual and how norms are established and maintained within organisations. Behaviour change is not produced by information delivery. It is produced by a combination of: clear institutional norms that define expected behaviour; social reinforcement from peers and managers; systems design that makes the desired behaviour the path of least resistance; and consequences, both positive and negative, that are applied consistently and visibly.
The annual compliance module is structurally incapable of producing any of these conditions. It is delivered once, in an environment of low attention and low stakes, with a pass/fail threshold calibrated to produce high completion rates rather than genuine comprehension. Its social context is zero: employees complete it alone, on a screen, without the social reinforcement that drives durable behaviour change. Its systems design implication is nil: it has no effect on the friction or ease of the behaviours it asks employees to change.
Organisations that have achieved measurable reductions in human-layer security incidents share a set of characteristics that are distinct from those with mature awareness programmes. Security is a visible and consistent management priority, modelled by senior leaders in their own behaviour. Security decisions are integrated into normal business processes rather than treated as separate compliance activities. Security failures are treated as learning events rather than disciplinary matters. And the physical and digital environment is designed to make secure behaviour natural rather than arduous.
Custodia One's security culture advisory starts with a diagnostic assessment of an organisation's current behavioural environment: what norms actually operate, what systems create friction, and where the gap between stated policy and actual practice is widest. Interventions are then designed to address specific gaps rather than deliver generic content.
"If your security programme is measured by completion rates, you are measuring the wrong thing. The relevant metric is whether employees behave differently after the programme than they did before it."
Custodia One Advisory Perspective
What Your Organisation Should Do
Audit the gap between your stated security policies and the actual behaviour they produce: this gap is your real risk
Redesign your security training around behavioural outcomes, not informational content
Invest in manager and senior leader behaviours: security culture is set at the top and migrates downward, not the reverse
Build consequence systems that are applied consistently and visibly: both positive recognition and clear corrective action
Advisory Enquiries
Facing this issue in your organisation?
Custodia One advises on all of the issues covered in our Intelligence Library. Contact us to discuss your specific situation in confidence.
