TL;DR SUMMARY: DORA training, PCI DSS awareness training and GDPR awareness all matter, although completion data only proves that people finished a task. Effective security awareness training goes further by showing whether behaviour changes in the moments where risk appears.
Compliance evidence and behaviour change
Compliance teams are often asked to prove that training has happened, and the request is reasonable enough. Frameworks, contracts and audits all require evidence, so a clean completion record can feel like the safest thing to show. The more useful question sits slightly deeper: once the module is complete, is the person better prepared to recognise risk when the pressure is real?
The answer usually proves more complicated than the dashboard suggests. PCI DSS awareness training, GDPR awareness and DORA training each ask organisations to show that people understand their responsibilities. The difficulty begins when understanding is reduced to exposure. A person can sit through a course, pass a quiz and still make a risky decision when they’re tired, rushed or faced with an unfamiliar request. Compliance has always been concerned with demonstrating that controls exist. Increasingly, the challenge is demonstrating that those controls continue to influence behaviour once everyday work resumes.
Effective security awareness training, then, needs to behave less like a yearly event and more like an operational control. If risk appears in real work, support needs to appear there too. A reminder about data handling has far more value when someone is about to paste sensitive information into an unapproved tool than it does six months earlier in a generic training module. The closer guidance sits to the decision itself, the clearer the link becomes between policy and practice.
What auditors can see in the data
Auditors are looking more closely at whether controls operate in practice, which means the most persuasive evidence usually has movement in it. Earlier reporting, fewer repeated risky actions and measurable responses to interventions all create a stronger assurance story than a static archive of completed courses. Those signals help turn security awareness training from a paper exercise into something a reader, auditor or board can understand as active risk reduction.
Amy Lemberger, co-owner and Fractional CISO of Lemberger & Associates Limited and former CISO of Gamma, brings more than 15 years of experience driving security transformation across telecommunications, technology and critical infrastructure. Her audit perspective sharpens this distinction neatly:
“These metrics are about compliance. They may be required for a contract or framework, so they can’t be ignored. But they don’t tell you whether human risk is being managed.”
That observation separates evidence of activity from evidence of effect, and it is often where awareness programmes begin to look thinner than their reporting suggests. Organisations can satisfy an audit requirement while still asking whether the behaviours they hoped to influence have actually changed. Those are different questions, and each deserves its own evidence.
There’s also a commercial argument here. ROSI, or return on security investment, becomes easier to discuss when organisations can connect spend to meaningful risk reduction rather than simply programme delivery. Cyber risk quantification is not only about modelling technical exposure. It also needs to account for the human decisions that create, amplify or reduce that exposure every day, because those decisions shape how technical controls perform in practice.
Leaders can make that shift by starting with the behaviour the control is meant to influence, then measuring the decision that sits closest to that risk. Completion rates can remain part of the evidence pack, while behavioural indicators such as reporting speed, repeat exposure and response to nudges give the story more substance for ROSI, return on security investment and cyber risk quantification.
Making compliance useful beyond the audit
This is where the wider shift towards human-centred cyber security becomes useful. Tools such as Redflags are designed around the idea that compliance becomes stronger when it reflects how people actually work. Real-time interventions, behavioural data and nudge-led guidance create a clearer line between policy intent and practical action. The result is a more useful distinction between saying people have been trained and being able to show that safer choices are being made.
As expectations around governance continue to mature, that distinction is likely to matter beyond the audit itself. Organisations that understand how behaviour changes over time are often better placed to demonstrate resilience as well as compliance, because they can show not only that controls exist, but that those controls remain active where risk actually emerges.
Key takeaways
- Completion metrics are useful for compliance, but they don’t prove behaviour change.
- Effective security awareness training should support users at the point of risk.
- ROSI and cyber risk quantification become stronger when human risk data is included.
- Compliance is more defensible when evidence shows controls operating in real work.
