Animation of two people

Introduction

Despite the increased adoption of security awareness training, our latest research reveals that more than half of cyber security professionals share concerns over security behaviours.

The Alarming Findings

We conducted a recent survey that shed light on attitudes towards security awareness training. Respondents were asked about the security behaviours that caused the most concern in their organisations. The top issues identified were:

  • Clicking on links in emails (53%)
  • Sharing corporate data outside of the business (53%)
  • Sharing of usernames and passwords (51%)

The study also highlighted that a quarter of cyber security professionals doubt their colleagues change their behaviour with current security awareness training. Alarmingly, 60% admitted they only receive training once every few months or even just once a year. As threats grow more sophisticated and frequent, it’s essential to provide regular and consistent training to stay effective. If training doesn’t keep up with the latest threats, organisations will be left vulnerable and stuck in the past.

The Importance of Timely Training

Redflags CEO, Tim Ward, emphasises the importance of delivering security awareness training in the moment when it can be directly contextualised by the recipient.

“This approach not only enhances comprehension by linking awareness to an immediate and relevant situation but also serves as a proactive nudge towards safe behaviour, By intervening at the precise moment when a risky action is about to be taken, individuals are more likely to understand the specific dangers and consequences associated with their actions. This timely intervention ensures that the lesson is not abstract or theoretical but grounded in a real-world context, making it more impactful.”

Measuring and Tracking Progress

Organisations must measure and track the progress of their security awareness programmes to determine effectiveness and make necessary changes. When respondents were asked whether their business could identify the user groups carrying out concerning behaviours, almost half (49%) said they did not for all behaviours causing concern.

Other key findings from the survey included:

  • 42% of respondents felt that their organisation could not even somewhat prove whether their current security awareness training is changing risky behaviours.
  • Half of respondents said they would not feel free from repercussions if they reported a mistake within their organisation.
  • 51% of respondents believed that most people across the business were focused on security, whereas 39% felt only the executives and security teams were focused on it.

Time to Re-evaluate

When numerous security experts confess that their organisation’s security awareness training isn’t cutting it, it’s a huge red flag that something’s amiss and it’s time to re-evaluate.

“Cyber security should be a concern for everyone, so pinpointing which user groups need extra help with safe practices is crucial for any business. A training programme that’s flexible and enjoyable can make all the difference, boosting staff engagement and giving cyber professionals greater confidence in their team’s ability to make smart security decisions.”

Tim Ward, CEO & Co-Founder, Redflags

Top 3 Ways to Make Security Awareness Training Work

  1. Deliver ongoing training: Annual training isn’t enough. Security awareness training should be provided to employees regularly to maintain awareness and keep employees up to date with the latest cyber security threats.
  2. Drip-feed content: When respondents were asked how they like to receive security awareness training, 70% said they want to keep their knowledge fresh and that little and often works for them. Delivering the content of your security awareness programme in small, bite-size segments helps to maximise engagement and reinforce ongoing awareness and learning outcomes.
  3. Measure engagement levels and progress: Measure behavioural impact and engagement. Measuring engagement levels indicates progress, but behavioural impact shows the programme’s effectiveness in reducing risk and highlighting user groups that display risky behaviour.

Methodology

Independent researchers on behalf of Redflags surveyed 163 cyber security professionals, including CISOs/CIOs, Senior Cybersecurity Managers, and IT decision-makers, at Infosecurity Europe, held in London between June 4th and 6th, 2024.

If you’d like to know more about how Redflags® addresses these challenges, get in touch.

Frequently asked questions

Why are employees afraid to report security mistakes?

Most people aren’t trying to hide mistakes, they’re trying to avoid what comes after. That awkward moment of realising something’s gone wrong already feels heavy enough without uncertainty about the response.

Fear builds from experience and assumptions mixing together. If reporting has ever led to silence or an overreaction, people remember it. So they pause, try to fix things themselves, or hope it disappears on its own. Redflags helps shift that moment by gently nudging action at the point something happens, so issues surface earlier and reporting becomes part of normal behaviour.

 

How does fear affect cyber security culture?

Fear reduces what gets shared. Small issues stay inside inboxes or heads, which gives them room to grow into larger problems while everything still looks calm on the surface.

It also changes how decisions get made. People second guess whether something is worth mentioning or spend time trying to handle it alone first. Redflags supports earlier visibility by encouraging action in the moment, so signals appear before they turn into avoidable risk.

How can organisations encourage reporting using Redflags?

Clarity removes most of the hesitation. When people understand what to report, how to report it, and what happens afterwards, there’s less space for guesswork to take over.
Consistency builds confidence over time. If reporting is met with calm and constructive responses, people are far more likely to repeat it when something similar happens again. Redflags reinforces those moments in real time, helping reporting feel like part of everyday security behaviour.