# How Is a Corporate Security Awareness Programme Built? Training, Simulation, Measurement and Culture

**URL:** https://securesys.com.tr/en/learning/end-user-security/building-a-security-awareness-programme

![How Is a Corporate Security Awareness Programme Built? Training, Simulation, Measurement and Culture](/images/bilgi-merkezi/covers/cover-sonkullanici-12.webp)

Corporate cyber security programmes were for years designed predominantly through technology. Firewall, antivirus, EDR, SIEM, DLP, MFA and network security investments became the fundamental defense layers of organizations.

However, many attacks still start directly through user behaviour.

A phishing e-mail is opened.

Credentials are entered on a fake login page.

An unexpected MFA request is approved.

A confidential document is shared with the wrong person.

A personal cloud service is used.

A fake IT support request is trusted.

**For this reason for modern organizations a Security Awareness Programme does not mean only annual training being given.**

The real security awareness approach:

**Education + Simulation + Measurement + Behavior Change + Culture**

requires these components to work together.

The essential target is not only to give employees information.

The target is:

**to enable the user to make a safer decision at the critical moment and to make it easier for them to report the event quickly when a mistake takes place.**

For this reason the modern Security Awareness approach is increasingly evaluated together with the concept:

#### Human Risk Management

this concept.

The fundamental principle is this:

**Manage the human factor not as the source of the security problem but as a measurable and improvable risk area.**

### What Is Security Awareness?

Security Awareness is the awareness approach that aims for employees to recognize cyber threats, develop safe behaviour and report suspicious events through the correct channels.

Within the scope of Security Awareness Training the subjects generally covered are:

Phishing,

Social Engineering,

Password Security,

MFA,

Data Security,

Safe Browsing,

Remote Work Security,

USB Security,

Ransomware

subjects such as these.

However, only giving training is not sufficient.

Whether the employee really shows a behavior change should be measured.

### What Is a Security Awareness Program?

A Security Awareness Program is a planned and measurable security awareness programme that continues throughout the year instead of one-off training.

The programme can include these components:

Awareness Training

Phishing Simulation

Role-Based Training

Microlearning

Security Communications

Measurement

Risk-Based Follow-Up

Management Reporting

In this way security awareness becomes a continuous process.

### What Is Security Awareness Training?

Security Awareness Training is users being educated on the subject of cyber risks and safe behaviors.

The aim is not only to teach technical jargon.

The employee should know the answers to these questions:

How is a suspicious e-mail recognized?

What is done if an unexpected MFA request comes?

Who is informed if a confidential file is sent to the wrong person?

Which process works in the case of a lost device?

Security awareness is valuable only if these behaviours can be applied in practice.

### Is Giving Training Once a Year Sufficient?

Generally no.

Human behaviour may not change permanently with a single annual training.

In addition cyber threats develop continuously.

For this reason:

short,

frequent,

scenario-based

learning can be more effective.

**This approach can be evaluated as Continuous Security Awareness.**

### What Is Continuous Security Awareness?

Continuous Security Awareness is security education continuing regularly throughout the year.

For example:

Quarterly Training

Monthly Security Tips

Phishing Simulations

Microlearning

Incident-Based Awareness

can be applied together.

The aim is for security not to be a subject remembered only when the compliance period arrives.

### What Is Human Risk Management?

Human Risk Management can be defined as the approach used for the measurement, evaluation and reduction of user-sourced security risks.

Traditional awareness asks the question:

**"Have we given training to the employees?"**

this question.

Human Risk Management, on the other hand:

**"Which user behaviours create real risk and is this risk decreasing over time?"**

focuses on this question.

This is a more measurable approach.

### What Is Human Risk?

Human Risk is the probability of a security incident arising as the result of the actions people take or do not take.

Examples:

clicking a phishing link,

approving an MFA request,

sharing sensitive data wrongly,

installing unapproved software,

reporting a security incident late.

These behaviors can have different risk levels.

### Why Is the Human Factor Important in Cyber Security?

Because instead of finding a technological vulnerability the attacker can target human behaviour.

The user can be manipulated through:

authority,

urgency,

fear,

curiosity,

trust

these.

For this reason Social Engineering is one of the fundamental subjects of a security awareness programme.

### What Is a Human Firewall?

Human Firewall expresses the idea of users who are conscious on the subject of security being one of the organization's defense layers.

However, this concept should be used carefully.

The user should never be the single line of defense.

The more correct approach:

#### Human Firewall + Technical Controls

these should be used together.

### Is the User the Last Line of Defense?

No.

The user is an important security layer but the system design must be resilient to human error.

The user can click the phishing.

The Secure Email Gateway can block it.

The user can enter credentials.

Phishing-resistant MFA can prevent the account takeover.

The user can send a sensitive file.

DLP can block it.

For this reason Security Awareness must work within Defense in Depth.

### What Is Security Culture?

Security Culture is the level at which the people inside the organization see security as a natural part of daily work.

In a strong security culture the employee:

reports the suspicious situation,

is not hesitant with the security team,

knows the reason for the policy,

does not hide their mistake.

This culture is not created with training alone.

Management behavior and organizational trust are also important.

### How Is a Security Culture Created?

For a security culture:

management support,

consistent communication,

easy reporting,

positive reinforcement,

practical training

are important.

The employee should not see the security team only as:

"the team that puts bans in place"

this.

The security team should be positioned as a business partner.

### Why Is a Blame Culture Harmful?

If the user is blamed heavily when they click a phishing they can hide the next incident.

This situation increases the Mean Time to Report.

Yet one of the most valuable behaviours for the security team is:

**fast reporting.**

For this reason the awareness programme should create a learning culture instead of punishment.

### Why Is Security Incident Reporting Important?

Security tools may not detect every attack.

The user:

a strange e-mail,

an unexpected login,

a fake call,

a suspicious pop-up

can notice these.

In this case quick reporting provides early detection for the SOC.

### What Is Mean Time to Report?

Mean Time to Report can be used to measure the time between the user noticing suspicious activity and informing the security team.

For example after a phishing simulation in how much time does the user report?

This metric can be more meaningful than the click rate alone.

### What Is a Phishing Simulation?

A Phishing Simulation is awareness behavior being measured by sending controlled and authorized phishing e-mails to employees.

The simulation does not carry the aim of real malware or credential theft.

The aim is to measure employees recognizing phishing indicators and their report behavior.

### Why Is a Phishing Simulation Carried Out?

Only carrying out a quiz after training does not measure real-world behavior.

The user may know the correct answer in the training but can make a wrong decision when a real e-mail comes.

A phishing simulation helps to measure this difference.

### What Is Click Rate?

Click Rate is the proportion of users who click the link in a phishing simulation.

For example if 100 out of 1,000 users click the Click Rate is 10%.

This metric is useful but does not show the success of the programme on its own.

### If the Click Rate Falls Is the Security Culture Considered Stronger?

Not always.

The answer to this question is important.

The Click Rate can fall because the simulation may have become easier.

Users may have recognized the same template.

There may have been an e-mail delivery problem.

For a real security culture:

Reporting Rate,

Credential Submission Rate,

Mean Time to Report,

Repeated Failure Rate

additional metrics such as these should also be evaluated.

### What Is Reporting Rate?

Reporting Rate is the proportion of users who correctly report the phishing simulation message to the security team.

This is generally valuable as a positive behavior metric.

Not only:

**"Who made a mistake?"**

but also,

**"Who took the correct security action?"**

this question should be asked.

### What Is Credential Submission Rate?

If the simulation contains a fake login page the proportion of users who try to enter credentials can be measured.

Real passwords must definitely not be captured.

The aim is only to measure the user's credential submission behavior.

This can be a higher risk indicator than the Click Rate.

### What Is a Repeat Offender?

It is the general expression used for users who continuously show high-risk behaviour in repeated simulations.

However, instead of putting a label on the user:

targeted training,

coaching,

role-based support

applying these is more correct.

### What Is Risk-Based Training?

Risk-Based Training is different content being offered according to the risk profile instead of the same training for every user.

For example a user who shares credentials in a phishing simulation can receive additional training.

This personalized approach can increase training effectiveness.

### What Is Role-Based Security Awareness?

Role-Based Training is employees being educated about the threats specific to their role.

Because Finance and a Developer do not have the same cyber risk profile.

For example Finance:

BEC,

invoice fraud,

vendor change

can receive more training on these subjects.

Developers, on the other hand:

source code,

secrets,

dependency security

can be educated on these.

### Executive Security Awareness

Executives can be high-value targets.

Whaling, CEO fraud and deepfake social engineering attacks can target executives and assistants.

For this reason executive awareness can be designed as a separate security module.

### Finance Security Awareness

Finance teams run high-risk processes such as payment and bank account changes.

The training can include these subjects:

Invoice Fraud

Vendor Email Compromise

BEC

Out-of-Band Verification

Four-Eyes Principle

This is more business-specific than technical training.

### HR Security Awareness

HR processes sensitive employee data.

Social engineering actors can target HR through CVs, payroll or employee requests.

For this reason for HR:

personal data,

identity verification,

secure file sharing

these subjects are important.

### IT Help Desk Awareness

The help desk carries out high-risk actions such as user password and MFA resets.

The attacker can try to manipulate the support team with social engineering.

For this reason help desk training:

identity verification,

MFA reset security,

privileged escalation

should cover these subjects.

### Developer Security Awareness

Developers alongside traditional phishing training:

Secure Coding

Secrets Management

Source Code Security

Dependency Risk

Cloud Credentials

AI Code Assistant Security

should receive training on these subjects.

**This can be thought of within the scope of Developer Security Awareness or DevSecOps culture.**

### Privileged User Awareness

When system administrators and high-privileged users are compromised the blast radius can be larger.

For this reason for privileged users:

phishing-resistant MFA,

PAW usage,

credential handling,

remote administration

special security awareness on these subjects is necessary.

### Third-Party Security Awareness

Contractors and external staff can access corporate systems.

These users should also be included in the awareness programme.

The security policy should not be limited only to permanent employees.

### New Hire Security Training

A new employee does not yet know the organization processes in their first days.

For this reason during onboarding:

password,

MFA,

phishing reporting,

data handling,

acceptable use

fundamental security topics such as these should be explained.

### Offboarding Security Awareness

When an employee leaves the organization access revocation is IT's responsibility.

However, the employee should be reminded of:

data return,

the company device,

confidentiality obligations

these.

This is important in terms of insider risk management.

### What Is Microlearning?

Microlearning is short and focused training content being offered regularly.

For example a 3–5 minute module:

**"How is MFA Fatigue recognized?"**

can focus on a single subject such as this.

Short-format learning can increase user engagement.

### What Is Gamification?

Gamification is game mechanics such as points, badges or challenges being added to training.

If designed correctly it can provide engagement.

However, security awareness should not be turned only into a competition.

The aim is learning.

### Is a Security Quiz Useful?

A quiz can measure knowledge retention.

However, a correct answer being given does not mean that the user will take the correct action in the face of a real attack.

For this reason:

Quiz + Simulation + Behavioral Metrics

should be used together.

### What Is Scenario-Based Training?

Scenario-Based Training provides learning through real business situations.

For example:

"The CEO asked for an urgent payment."

"The supplier changed their bank account."

"An MFA notification came."

"The laptop was lost."

The user is asked to choose the correct action.

This approach can be more effective than theoretical content.

### What Is Just-in-Time Training?

Just-in-Time Training is short training being given to the user immediately after risky behavior.

For example to a user who clicks a phishing simulation link:

**"What were the 3 risk signs in this e-mail?"**

short training such as this can be shown.

This establishes a strong bond between behavior and learning.

### What Is a Security Champions Program?

Security Champions is the programme in which employees who are volunteers or appointed on the subject of security inside business units form a communication bridge with the security team.

Champions:

awareness,

policy adoption,

feedback

can help on these subjects.

This supports the security culture spreading throughout the organization.

### Who Should Security Champions Be?

They do not have to be only IT employees.

Security-minded employees can be chosen from within Finance, HR, Sales, Development and Operations.

The aim is to spread security ownership from the central team to the whole organization.

### What Are Security Communications?

Security Awareness should not be run only over a training platform.

Internal communication channels can be used:

e-mail,

Teams,

Slack,

the intranet,

posters,

newsletters.

However, too many security warnings can create alert fatigue.

### Is a Security Awareness Newsletter Useful?

Yes, but it should be short and practical.

For example:

"The 3 phishing methods seen this month"

organization-relevant content such as this can be more effective.

Generic global threat lists can be less meaningful for employees.

### Real Incident-Based Awareness

If a real incident has been experienced inside the organization it can be turned into lesson learned awareness content without sensitive details being shared.

For example:

"This month a fake supplier bank account change attempt was detected."

This content can be much more realistic for employees.

### Deepfake Awareness

AI-generated voice and video social engineering attacks can become increasingly more realistic.

For this reason security awareness programmes should handle not only traditional phishing but also the risks of:

voice cloning,

deepfake video,

AI-generated messages

these.

### Deepfake CEO Fraud

The attacker can create a payment request using AI-generated audio that resembles an executive's voice.

For this reason the defense should be:

#### Voice Recognition

not this,

#### Process Verification

it should be this.

A financial transaction should not be authorized only over voice or video.

### AI-Generated Phishing

Generative AI can make it easier for attackers to produce more correct grammar and personalized content.

For this reason the old awareness messages:

"If there is a spelling mistake it can be phishing."

are insufficient on their own.

The user:

context,

the request,

the domain,

the business process

should make an evaluation through these.

### Security Awareness and Generative AI

Employees need data security awareness while using public AI tools.

The programme:

which AI services are approved,

which data can be shared,

can source code be uploaded,

can customer data be used

should answer questions such as these.

This is an important subject of modern Cyber Awareness programmes.

### Security Awareness and Data Classification

If the user does not know the data classification levels they may not understand the DLP warnings.

For this reason awareness:

Public,

Internal,

Confidential,

Restricted

should teach the practical use of classifications such as these.

### Security Awareness and DLP

DLP is not only a technical blocking tool.

A policy tip can give the user the message:

"Why should you not carry out this operation?"

this message.

In this way DLP provides real-time security coaching.

### Security Awareness and Endpoint Security

When the user sees an EDR warning they should not try to close the agent.

They should not install unknown software.

If the device shows unusual behavior they should inform the security team.

Endpoint Security is part of the awareness programme.

### Security Awareness and Browser Security

The user:

that HTTPS does not mean site trustworthiness,

that a search engine result can be malicious,

the fake software update risk,

that browser extensions ask for permissions

should know these.

Safe Browsing training is an important part of modern awareness.

### Remote Work Security Awareness

Training for remote workers:

Public Wi-Fi

Lost Device

Home Router

Shoulder Surfing

Fake IT Support

Personal Cloud Storage

should cover these subjects.

Office-only scenarios are not sufficient for a remote workforce.

### USB Awareness

The user should not plug a USB they find on the ground into the endpoint.

Corporate data should not be transferred to personal removable media.

A lost USB should be reported.

These simple behaviors reduce the ransomware and data leakage risk.

### Password Awareness

The training:

unique passwords,

a password manager,

MFA,

credential phishing

should include these subjects.

However, the user should not be expected to remember hundreds of complex passwords.

Technical controls should make user behavior easier.

### MFA Awareness

The user should not approve an unexpected MFA prompt.

This behavior is important especially for MFA fatigue attacks.

The training should give the user the reflex:

**"If I am not logging in I do not approve."**

this reflex.

### What Is a Reporting Button?

A Phishing Report button can be added inside the e-mail client.

The user can send the suspicious mail to the security team with a single click.

The easier the reporting process is the more the reporting rate can increase.

### How Should the Security Reporting Process Be?

The employee:

who they will call,

which e-mail they will write to,

which button they will press

should know these.

Urgent security reporting should not be complicated.

### Is Anonymous Reporting Necessary?

For some insider or ethics scenarios anonymous reporting can be useful.

However, for normal cyber incident reporting a fast and open communication channel should be preferred.

### What Are Security Awareness Metrics?

The success of the programme should be measured.

The important metrics:

Training Completion Rate

Phishing Click Rate

Credential Submission Rate

Reporting Rate

Mean Time to Report

Repeat Failure Rate

Role-Based Risk Score

Incident Reporting Volume

Human Risk Score

These metrics should be interpreted together.

### What Is Training Completion Rate?

It shows how much of the users assigned to training completed the training.

It is important in terms of compliance.

However, completion does not prove that security behavior has changed.

### How Should Phishing Click Rate Be Interpreted?

If the Click Rate is falling over time it can be a positive signal.

However, if the simulation difficulty is not the same the comparison can be misleading.

Metrics should be evaluated in a standardized and contextual way.

### Why Can Reporting Rate Be More Important Than Click Rate?

Because the security goal is not only never to click a phishing.

If the user reports the suspicious content early the SOC can protect the other employees.

One person's report can stop a campaign that would reach hundreds of users.

For this reason reporting behavior is a positive security outcome.

### Why Is Mean Time to Report Important?

A phishing campaign can spread quickly.

If the user reports within 5 minutes the security team can carry out:

search-and-purge,

URL block,

domain block

these.

If it is reported after 3 hours more users may have been affected.

For this reason speed is important.

### What Is Human Risk Score?

Human Risk Score is the measurement approach aimed at estimating the risk level of a user or group through different behaviors and security signals.

For example:

Phishing Simulation Result

Training Behavior

Reported Incidents

Device Risk

Data Handling Events

factors such as these can be used.

This score should be applied carefully and in a privacy-aware way.

### Should Human Risk Score Be Used to Punish the Employee?

No.

The aim of the risk score is to improve training and security controls.

Stigmatizing employees or using it for unfair HR decisions can weaken the security culture.

### What Is a High-Risk User?

High-Risk User can be used in two different senses.

The first is a user who is risky because of behavior.

The second is a high-value target because of their role.

For example even if the CEO clicks no simulation they can be a high-risk target for attackers.

This distinction is important.

### What Is a High-Value Target?

A High-Value Target is a user or role that when compromised can create an important impact for the organization.

For example:

Executive

Finance

System Administrator

Help Desk

can be included in this profile.

Stronger technical controls should be applied for these users.

### The Difference Between Role Risk and Behavior Risk

A Finance user may never have clicked a phishing but is risky because of payment access.

Another user can click a large number of simulations but may not have critical access.

Modern Human Risk Management:

**Role Risk + Behavior Risk + Access Risk**

should evaluate these together.

### Security Awareness Dashboard

For management the dashboard can show these metrics:

Training Completion

Phishing Reporting Rate

Click Rate Trend

Risky Departments

Mean Time to Report

Role-Based Training Status

But the dashboard should not turn into a competition table.

### Department-Based Security Awareness

Departments can meet different threats.

Finance → BEC

HR → Personal Data

IT → Privileged Access

Developers → Source Code

Sales → External Sharing

For this reason department-level analytics can optimize the training programme.

### What Is a Security Awareness Benchmark?

The organization should compare its own metrics with previous periods.

External industry benchmarks can be useful but between organizations:

simulation difficulty,

user profile,

reporting method

can be different.

For this reason the internal trend is most of the time more meaningful.

### Security Awareness Maturity Model

#### Level 1 – Compliance Training

Training is carried out once a year.

Success is measured with the completion rate.

Security awareness is seen as a compliance requirement.

#### Level 2 – Phishing Simulation

Regular phishing simulations and basic metrics are applied.

Click rate and reporting rate are tracked.

#### Level 3 – Role-Based Awareness

Special training is prepared for departments and high-risk roles.

Just-in-Time Training and microlearning are used.

#### Level 4 – Human Risk Management

User behavior, access profile and security events are evaluated together.

Training is assigned on a risk-based basis.

DLP, Identity and Endpoint signals are related to the awareness programme.

#### Level 5 – Security Culture

Security behavior becomes a natural part of the organization's daily way of working.

Employees report quickly to the security team.

Management sets an example for security behavior.

The programme becomes:

**Continuous + Measurable + Adaptive**

this.

### How Is a Security Awareness Program Created?

A successful programme should not start only with buying content.

The first step:

#### Human Risk Assessment

should be this.

The organization should understand which user groups are exposed to which threats.

Afterwards the programme can be created in this order:

#### Identify Human Risks

↓

#### Define Target Behaviors

↓

#### Create Role-Based Content

↓

#### Run Simulations

↓

#### Measure Behavior

↓

#### Provide Targeted Training

↓

#### Improve Technical Controls

↓

#### Measure Again

This is a continuous improvement cycle.

### What Is a Target Behavior?

An awareness programme should define measurable behaviors instead of vague targets.

For example:

"Increase phishing awareness."

instead of this:

**"Raise the suspicious e-mail reporting rate to the X% level."**

becomes a more measurable target.

Another target:

**"Minimize the approval rate of unexpected MFA requests."**

can be this.

### What Is Behavior Change?

The real success criterion of awareness training is not knowledge but behavior change.

The user can answer the question "what is phishing?".

But if they click the link when a real phishing message comes the knowledge has not turned into behavior.

For this reason simulation and real incident metrics are important.

### What Is Positive Reinforcement?

It is correct security behavior being appreciated.

For example the employee who first reports a real phishing campaign can receive a thank you message.

This encourages security reporting.

### Should Punishment Be Applied in a Security Awareness Program?

Repeated intentional policy violations can be a separate management subject.

However, creating a punishment-focused programme for normal mistakes is not correct.

Because the user can start to hide their mistake.

For the security team transparency is more valuable.

### The Relationship Between Security Awareness and the SOC

Employees can actually work like a broad distributed detection network.

The user reports the phishing.

The SOC analyzes the message.

It finds the same campaign over the SIEM/Email Security.

The messages are removed from across the organization.

The domain is blocked.

In this case the user is directly part of the Detection & Response chain.

### How Should User-Reported Phishing Be Processed?

The reported message can if possible be put through:

header analysis,

URL analysis,

attachment analysis,

reputation checks

these operations with an automated workflow.

If it is confirmed phishing an environment-wide search can be carried out.

This can be a suitable use case for SOAR automation.

### How Does SOAR Contribute to a Security Awareness Program?

SOAR can run an automated playbook for user-reported phishing.

For example:

Report Received

↓

Extract URLs

↓

Threat Intelligence Check

↓

Search Mailboxes

↓

Block Indicator

↓

Notify User

This strengthens the reporting feedback loop.

### Should Feedback Be Given to the User?

Yes.

If the user reports a phishing but receives no answer at all they cannot know whether the reporting is useful.

If possible:

"Thank you, this message has been confirmed as phishing."

short feedback such as this being given strengthens the security culture.

### Is a False Positive Report a Problem?

Users can also report legitimate e-mails.

This is not a bad thing.

In the early stages of an awareness programme over-reporting can be normal.

The volume can be managed with automation and triage.

Over time user judgment can develop.

### Security Awareness and Incident Response

A security awareness programme should teach employees not only threat prevention but also incident response behaviour.

For example:

I entered credentials.

The laptop was lost.

I sent a file to the wrong person.

I approved the MFA by mistake.

What should I do?

These scenarios should be taught clearly.

### **"I Made a Mistake, Should I Report It?"**

Definitely.

The incident being reported quickly increases the effect of the technical response.

A password reset, session revocation, link revoke or endpoint isolation can be carried out early.

The security team's aim is not to hide the mistake but to reduce the impact.

### Security Awareness and Cyber Hygiene

Cyber Hygiene expresses daily fundamental security habits.

For example:

updates,

screen lock,

MFA,

a password manager,

approved software,

safe browsing.

A Security Awareness programme should support the continuity of cyber hygiene behaviours.

### Policy Training in a Security Awareness Program

Employees should be informed about rules such as the Acceptable Use Policy, the Data Classification Policy and the Remote Work Policy.

However, instead of expecting them to read a policy of hundreds of pages practical guidance should be given.

### What Is an Acceptable Use Policy?

An Acceptable Use Policy defines for which purposes and how corporate systems and devices can be used.

For example:

software installation,

personal usage,

cloud services,

USB usage

rules on these can be found.

### The Use of AI in a Security Awareness Program

AI systems can be used for personalized microlearning, phishing content analysis or adaptive training.

However, user profiling and the use of personal data must be done in a privacy-aware way.

The aim of an AI training programme should not be to monitor employees continuously.

### What Is Adaptive Security Awareness?

Adaptive Awareness is the training content changing dynamically according to user risk and behavior.

For example when the Finance team meets a new BEC campaign a targeted module can be assigned.

This can be more relevant than static annual training.

### KPIs for a Security Awareness Program

A corporate programme can track these KPIs:

- Training Completion Rate
- Phishing Click Rate
- Phishing Reporting Rate
- Credential Submission Rate
- Mean Time to Report
- Repeat Failure Rate
- High-Risk User Training Completion
- Executive Training Completion
- Incident Reporting Volume
- Role-Based Training Coverage
- Human Risk Trend
- Security Culture Survey Results

Success should not be evaluated over a single metric.

### What Is a Security Culture Survey?

A survey that measures employees' perception and confidence levels about security can be applied.

For example:

Do you know how you will report a suspicious event?

When you make a mistake can you inform the security team comfortably?

Do security policies make your work unnecessarily harder?

This feedback is valuable for programme design.

### The Most Frequently Made Mistakes in a Security Awareness Program

The mistakes frequently seen in organizations are these:

- Seeing Security Awareness as training once a year
- Measuring success only with training completion
- Looking only at the phishing click rate
- Not measuring the Reporting Rate
- Not tracking Mean Time to Report
- Giving every employee the same training
- Not preparing role-based content for Finance, HR, IT and Developers
- Leaving executives outside the programme
- Not taking contractors into the awareness scope
- Preparing training that is too long and theoretical
- Creating a blame culture for user mistakes
- Making security reporting complicated
- Not giving feedback on user reports
- Using phishing simulations like a tool for catching employees
- Using the Human Risk Score for punishment
- Not drawing lessons learned from real incidents
- Not adding deepfake and AI phishing risks to the training
- Ignoring the subject of public AI data leakage
- Running the awareness programme separately from technical controls
- Not measuring the business impact of the programme

### Security Awareness Program Checklist

Organizations can evaluate the following controls:

- Is the Security Awareness Program managed with an annual plan?
- Is there new hire security training?
- Is annual refresher training being applied?
- Is microlearning being used?
- Are phishing simulations carried out regularly?
- Is simulation difficulty being standardized?
- Is the Reporting Rate being measured?
- Is the Click Rate monitored as a trend?
- Is the Credential Submission Rate being tracked?
- Is Mean Time to Report being measured?
- Is repeat risk behavior being detected?
- Is Role-Based Training being applied?
- Is BEC training present for Finance?
- Is there data security training for HR?
- Does the IT Help Desk receive social engineering training?
- Do Developers receive secure coding awareness?
- Is there special training for privileged users?
- Are executives included in the awareness programme?
- Are contractors included in the programme?
- Is deepfake awareness covered?
- Are AI-generated phishing scenarios present in the training?
- Is Generative AI data usage training present?
- Is a Phishing Report button being used?
- Are user reports integrated into the SOC workflow?
- Is SOAR phishing report automation being used?
- Is feedback being given on user reports?
- Is there a Security Champions programme?
- Is a Security Culture Survey being carried out?
- Are Human Risk trends reported to management?
- Are awareness metrics related to technical security metrics?
- Is the programme updated every year with lessons learned?

### Frequently Asked Questions

#### What is Security Awareness?

Security Awareness is the awareness approach that aims for employees to recognize cyber threats, develop safe behaviour and report security incidents correctly.

#### What is a Security Awareness Program?

It is the corporate security programme in which training, simulation, communication and measurement activities are run in a planned way throughout the year.

#### What is Human Risk Management?

It is the approach of measuring, evaluating and reducing the security risks arising from user behaviours.

#### What is a Human Firewall?

It is the concept that expresses the idea of security-aware employees being one of the organization's defense layers.

#### What is Security Culture?

It is the level at which employees see and apply security as a natural part of the daily business process.

#### What is a Phishing Simulation?

It is the authorized awareness test in which security behavior is measured by sending controlled fake phishing messages to employees.

#### What is Phishing Click Rate?

It is the proportion of users who click the simulation phishing link to the total participants.

#### What is Reporting Rate?

It is the proportion of users who correctly report a phishing simulation or suspicious message to the security team.

#### Does a falling Click Rate show that the awareness programme is successful?

On its own no. Metrics such as Reporting Rate, Credential Submission Rate, Mean Time to Report and Repeat Behavior should also be evaluated.

#### What is Mean Time to Report?

It is the time that passes between the user noticing a suspicious event and reporting it to the security team.

#### What is Human Risk Score?

It is the measurement approach that expresses the estimated human cyber risk level of a user or group through role, behavior and security signals.

#### What is Role-Based Security Awareness?

It is employee training being customized according to their duty and risk profile.

#### What is a Security Champions Program?

It is the programme in which selected employees inside departments build an awareness and communication bridge between the security team and the business.

#### What is Microlearning?

It is continuous learning being provided by using short, focused and regular security training modules.

#### What is Just-in-Time Training?

It is short training on the relevant subject being given at the moment the user shows risky behavior or immediately afterwards.

#### Why is Deepfake Awareness necessary?

Because of AI-generated voice and video social engineering attacks employees need to recognize not only e-mail phishing but also multi-channel impersonation risks.

#### What is Generative AI Security Awareness?

It is employees being educated on the subject of sensitive data, privacy, confidential information and approved usage policies while using public or corporate AI tools.

#### Is Security Awareness only the responsibility of employees?

No. The organization must provide technical controls, secure processes and management support. The user should not be the single line of defense.

### Conclusion: The Target of Security Awareness Is Not to Test the Employee but to Strengthen Safe Behaviour

One of the biggest mistakes in corporate security awareness is evaluating the programme only through the training completion rate.

100% training completion can be a good compliance indicator.

However, it does not answer these questions:

What does the employee do when a phishing comes?

Do they approve the suspicious MFA request?

When they send the wrong file do they report it immediately?

Do they upload confidential data to a public AI tool?

When a fake support call comes do they carry out identity verification?

Real success is measured here.

For this reason a modern Security Awareness programme:

#### Knowledge

↓

#### Behavior

↓

#### Measurement

↓

#### Improvement

should be built on this chain.

Training gives information.

Simulation tests behavior.

Metrics show the risk level.

Targeted education develops behavior.

Technical controls, on the other hand, limit the impact in the case of the user making a mistake.

For this reason a strong security culture:

**"The employee does not make mistakes."**

is not this culture.

A strong security culture:

**"The employee notices the suspicious situation, reports it quickly and the organization can manage the mistake before it turns into a disaster."**

is this culture.

The Click Rate is a small part of this.

The more important questions are these:

How quickly do users report phishing?

Can the Finance team stop a fake payment request with process control?

Does the Help Desk carry out identity verification in the face of social engineering?

Do privileged users use stronger authentication?

When employees make a mistake do they come to the security team instead of hiding the event?

Real Human Risk Management answers these questions.

The fundamental formula of a modern Security Awareness programme:

**Continuous Training + Role-Based Awareness + Phishing Simulation + Positive Reporting Culture + Behavioral Metrics + Technical Controls + Human Risk Management**

can be thought of in this way.

However, in terms of the whole series there is a formula more important than this:

**Awareness + Identity Security + Endpoint Security + Data Security + Detection + Response**

Because end user security is not only educating the user.

The user can click a phishing.

Endpoint protection must come into play.

They can share credentials.

MFA and Identity Security must come into play.

They can send the wrong file.

DLP must come into play.

They can see a security alert.

The SOC must come into play.

For this reason the main principle of end user security is this:

**Instead of seeing the user as the weakest link of security, turn them into an active security sensor supported by technical controls.**

**You cannot remove human error completely; but you can build a security architecture that prevents human error turning into a cyber security incident.**
