Cybersecurity Awareness
Cybersecurity Awareness Is a Human Behavior Problem
Sajed Naseem
The Limits of Check-the-Box Security Awareness
Most organizations have a cybersecurity awareness program. Employees complete annual training, acknowledge a policy, and receive a certificate. The compliance box is checked. But completion is not the same as readiness. The question organizations rarely ask is whether the training actually changed anything — whether employees who finished the module will make better decisions when they receive a convincing phishing email, a fraudulent wire transfer request, or a call from someone impersonating their IT department.
Annual training completion tells an organization that employees were exposed to information. It does not tell the organization whether that information changed knowledge, behavior, attitude, or decision-making. An organization that measures only completion is measuring the wrong thing. The goal of a cybersecurity awareness program is not a completed training record. The goal is a workforce that makes more secure decisions under real conditions — including conditions that are stressful, unfamiliar, or deliberately designed to deceive.
Knowledge Is Not the Same as Behavior
There is a persistent gap between knowing the right answer and doing the right thing. Someone can correctly identify a phishing email in a training scenario and still click a convincing message in their inbox the following week. The conditions are different. The training scenario was calm, labeled, and low-stakes. The real message arrived during a busy afternoon, appeared to come from a trusted source, and created a sense of urgency.
Cybersecurity awareness programs that focus exclusively on knowledge transfer — teaching people what phishing is, what social engineering looks like, what the policy says — address only part of the problem. Behavior is shaped by knowledge, but also by attitude, habit, organizational culture, time pressure, and the specific context in which a decision is made. An effective awareness program has to account for all of these. It has to change not just what people know but how they respond when the situation is ambiguous, when they are distracted, and when the attacker has done their homework.
Why People Click
Social engineering works because it exploits normal human psychology rather than technical vulnerabilities. Attackers do not need to break through a firewall if they can convince an employee to hand over credentials, approve a fraudulent transaction, or open a malicious attachment. The techniques they use are well understood: curiosity, urgency, authority, fear, familiarity, trust, personal interests, and routine business processes.
A message that appears to come from an executive creates authority. A notification that an account will be suspended creates urgency. A message referencing a recent project or a colleague's name creates familiarity. A request that mirrors a normal business process — approving an invoice, resetting a password, confirming a delivery — blends into the background of a busy workday.
Organizations that respond to phishing incidents by simply recording that someone clicked are missing the more important question: why did they click? Understanding the specific psychological trigger that was exploited — and whether it reflects a pattern across the organization — is what allows an awareness program to improve. Recording a click is a data point. Understanding why it happened is actionable intelligence.
Cybersecurity Is a Leadership Issue
Cybersecurity awareness is not solely an IT or cybersecurity department responsibility. Every person in an organization who handles information, communicates with external parties, approves transactions, or makes decisions that affect organizational systems is a participant in the organization's security posture. That includes executives, managers, business unit leaders, technology teams, legal and compliance staff, finance employees, and frontline personnel.
When leadership treats cybersecurity as a technical problem owned by the security team, the rest of the organization receives a clear signal: this is not my concern. When leadership models secure behavior, communicates clearly about risk, and treats security as an organizational priority rather than a compliance obligation, the signal is different. Cybersecurity culture is built from the top down and reinforced through consistent behavior at every level.
This means cybersecurity awareness has to be approached as a leadership, behavioral, operational, risk-management, and technical discipline simultaneously. The security team can design the program, but the program will not succeed without genuine organizational ownership.
Build Defense Around Human Reality
No awareness program will eliminate human error. People will occasionally make mistakes — under pressure, under deception, or simply because the attacker was skilled. An organization that designs its security posture around the assumption of perfect human behavior is building on an unstable foundation.
The more durable approach is to assume that mistakes will happen and to build layered controls that prevent a single human error from becoming a major organizational incident. Multifactor authentication means that a compromised password alone is not sufficient for account takeover. Identity security and least-privilege access limit what an attacker can reach once inside. Verification procedures and secondary approval for sensitive transactions — particularly wire transfers and changes to payment information — create checkpoints that slow down fraud. Email security controls reduce the volume of malicious messages that reach employees in the first place. Network segmentation limits lateral movement. Endpoint protection and monitoring provide detection capability. Incident response procedures ensure that when something does go wrong, the organization can contain and recover.
Awareness programs work best when they are part of this layered architecture — not a substitute for it. The objective is not perfect human behavior. The objective is preventing one human mistake from becoming a major organizational incident.
Make Cybersecurity Training Relevant to the Job
Generic cybersecurity training treats all employees as interchangeable. A finance employee who processes wire transfers, an executive who receives targeted spear-phishing, an attorney who handles privileged communications, an HR employee who manages sensitive personnel data, and a technology professional who administers systems all face meaningfully different risks. Training that does not reflect those differences is less effective than training that does.
Role-based security education addresses the decisions people actually make in their jobs. Finance employees benefit from training that focuses on business email compromise, fraudulent invoice schemes, and wire transfer verification. Executives benefit from training that addresses targeted impersonation and the risks associated with their level of access and authority. Technology professionals benefit from training that addresses secure configuration, credential management, and the risks specific to administrative access. Customer-facing personnel benefit from training that addresses social engineering through customer channels.
When training reflects the actual threat landscape an employee faces in their role, it is more likely to be retained and applied. It is also more likely to be taken seriously.
Measure What Matters
Training-completion percentages are easy to collect and easy to report. They are also a poor proxy for cybersecurity readiness. An organization that reports 98% training completion has not demonstrated that its workforce will make secure decisions under real conditions. It has demonstrated that 98% of employees completed a module.
More meaningful measurement looks at what the training was actually trying to change. Did knowledge improve? Did behavior change — as measured through phishing simulations, security assessments, or observed decision-making? Did reporting rates increase, indicating that employees are more likely to flag suspicious activity rather than ignore it? Are organizational outcomes improving — fewer successful phishing attacks, faster detection, lower incident rates?
Measuring attitude and organizational culture is harder but not impossible. Employee surveys, focus groups, and qualitative assessments can surface whether employees understand why security matters, whether they feel supported in making secure decisions, and whether they view security as a shared responsibility or an external imposition. Organizations that measure only completion are optimizing for the wrong outcome. The goal is risk reduction, and measurement should be designed to show whether the program is actually achieving it.
Developing the Next Generation of Cybersecurity Professionals
The cybersecurity field needs professionals who can do more than configure tools and respond to alerts. It needs people who understand human behavior, organizational dynamics, risk, governance, ethics, and leadership — who can communicate clearly with non-technical stakeholders, exercise judgment under uncertainty, and connect technical security decisions to organizational outcomes.
Cybersecurity education that prepares students for these roles has to go beyond technical curriculum. It has to develop the ability to translate risk into language that executives and boards can act on, to navigate legal and regulatory complexity, to build and sustain programs across organizational change, and to mentor the next generation of practitioners.
The connection between education and practical experience matters. Students who have the opportunity to apply classroom learning in real professional environments — through internships, mentorship, and exposure to working security programs — develop judgment that cannot be acquired from coursework alone. That practical foundation is what allows a technically skilled graduate to become an effective security professional over time.
Cybersecurity Awareness as a Continuous Discipline
Annual training is a starting point, not a program. Threats evolve. Business processes change. New employees join. Existing employees move into new roles with different risk profiles. The phishing techniques that were novel two years ago are now familiar, and attackers have moved on to more sophisticated approaches.
An awareness program that runs once a year and then goes dormant is not keeping pace with any of this. Effective awareness is continuous — built into the rhythm of organizational life rather than scheduled as a once-a-year event. It draws on phishing simulation results, incident data, threat intelligence, and employee feedback to identify where the program needs to improve. It reinforces key behaviors through regular communication, not just formal training. It treats security culture as something that is built and maintained over time, not installed and forgotten.
The goal is an organization in which secure decisions become part of normal operations — where employees recognize suspicious activity, report it, and feel supported in doing so. That kind of culture is not created by a training module. It is built through consistent leadership, meaningful education, and a security program that treats the human element as a genuine priority rather than a compliance checkbox.
Selected Work on Cybersecurity Awareness, Education & Leadership
Government Technology — Expert Q&A
Government Technology's Q&A, "Expert Q&A: Cybersecurity Training Needs a Kick in the Pants," documents Sajed Naseem's professional perspective on cybersecurity awareness and training — including the limitations of completion-based measurement, the importance of addressing human behavior, and the need for layered security controls alongside awareness programs.
Expert Q&A: Cybersecurity Training Needs a Kick in the Pants ↗New Jersey Law Journal — The Sippy Cup Problem
"The Sippy Cup Problem: Redefining Cybersecurity Awareness," published in the New Jersey Law Journal, examines how organizations approach security awareness and argues for a more meaningful approach than annual compliance exercises — one that addresses the practical human dimensions of cybersecurity behavior.
The Sippy Cup Problem: Redefining Cybersecurity Awareness ↗SecureWorld Mid-Atlantic 2021
The SecureWorld Mid-Atlantic 2021 conference agenda documents Sajed Naseem and Rebecca Rakoski presenting "The Threat from Within: Creating an Effective Cyber Awareness Program" — addressing organizational cybersecurity awareness, insider risk, and program design.
SecureWorld Mid-Atlantic 2021 — Conference Agenda ↗St. John's University — Cybersecurity Education & Mentorship
A St. John's University article, "A Day in the Life of a Cybersecurity Analyst," profiles a cybersecurity graduate who credits Sajed Naseem among supportive professors and describes obtaining a historical Information Security Analyst internship with the New Jersey Courts under Sajed Naseem — illustrating the connection between cybersecurity education, mentorship, and practical professional experience.
A Day in the Life of a Cybersecurity Analyst: St. John's Alum Story ↗About Sajed Naseem
Sajed Naseem is an experienced cybersecurity executive, information security leader, cybersecurity educator, and professor whose professional background includes government, higher education, enterprise technology, cybersecurity leadership, risk management, security architecture, incident response, governance, and cybersecurity education.