A woman is sitting at her desk looking over documents. Her colleague is also sitting at his desk.

When do security awareness controls move beyond paper?

For many organisations, security awareness sits at an uncomfortable intersection between intention and evidence. Most teams can point to activity: training delivered, policies acknowledged, completion rates logged and archived. On the surface, everything appears in order. The doubt tends to surface later, when incidents occur and leaders start to question whether those controls were doing anything meaningful or simply satisfying a requirement. 

Amy Lemberger has spent years assessing organisations from both sides of the table. Her background spans auditing against international cyber security standards and advising teams responsible for meeting them in practice. That experience gives her a clear view of what stands up under scrutiny and what only looks solid until someone asks the next question. 

From an audit perspective, the difference between controls that exist on paper and controls that operate in practice is usually visible in the data. Static controls leave behind tidy, predictable records. When awareness is genuinely interacting with real work, the picture becomes more complex. There are variations, anomalies and trends that prompt follow-up and explanation. That movement is often the first signal that a control is alive rather than simply documented. 

As Amy Lemberger puts it, when things are happening in the real world, they leave traces in the control data, and hose traces matter. 

Are completion metrics telling us the wrong story?

Completion rates, policy sign offs and quiz scores are often treated as indicators of success. They do serve a purpose, but it is narrower than many organisations assume. 

 “These metrics are about compliance,” Amy explains. “They may be required for a contract or framework, so they can’t be ignored. But they don’t tell you whether human risk is being managed.” 

Managing human risk shows up elsewhere. Auditors often see it reflected in changes over time, such as fewer recurring incidents linked to the same behaviour, or a noticeable increase in first-time reporting. Those patterns point to people responding differently to risk, not just completing assigned tasks. From an assurance perspective, that distinction is fundamental. 

What separates checklist compliance from genuine understanding?

Organisations that truly understand the intent of standards tend to invest differently. They pause to examine why a requirement exists before settling on how to address it. That work is rarely quick, and it often challenges long-held assumptions. 

According to Amy, it also requires a willingness to challenge familiar approaches and defend alternative ones. Understanding the purpose of a standard is only the first step. Designing an approach that genuinely aligns to that purpose, and being prepared to explain it under scrutiny, is where the real effort lies. 

That confidence does not come from following precedent. It comes from clarity of intent. 

How much flexibility do organisations really have?

Many teams assume there is far less room to manoeuvre than actually exists. That belief is usually reinforced by habit, not by the standards themselves. In practice, standards rarely prescribe specific activities. They ask organisations to demonstrate understanding and effect. 

“There is more flexibility than people think,” Amy notes. “But it depends on whether they invest the time to understand how their approach maps to the requirement.” 

Without that investment, alternative approaches can feel risky. With it, they become explainable, traceable and defensible. 

What does good evidence of behaviour change look like?

Evidence becomes meaningful when it is tied to action. The most useful metrics are designed with a question in mind and can be tracked against a deliberate activity. 

A clear baseline. A specific intervention. A measurable change.

Well-designed metrics allow senior leaders to see what is happening without needing to immerse themselves in raw data. They provide a line of sight from decision to outcome. Anecdotes can add context, but it is the metrics that provide assurance. 

How can organisations take a different approach and remain audit ready?

For organisations considering a more contextual approach to security awareness, Amy’s advice is pragmatic. Start by articulating why the change is needed. Write it down. Use that reasoning to guide policy decisions, risk discussions and measurement choices. 

As long as an organisation can show how its approach addresses human risk, and can explain its reasoning, it should be prepared to discuss that position with an auditor. 

“You know your company and your why,” Amy says. “If you can show your workings, you should be able to stand behind your decisions.” 

Audit readiness is not about avoiding scrutiny. It is about being prepared to explain intent, evidence effect, and show that controls are operating as designed. In that context, doing something different is often a sign of maturity rather than risk. 

Key takeaways

  • Compliance metrics and human risk metrics serve different purposes. Completion rates and sign-offs demonstrate adherence, while behavioural indicators show whether risk exposure is changing over time. 
  • Controls that operate effectively in practice tend to produce data that moves, fluctuates and requires explanation, signalling interaction with real behaviour rather than passive completion. Standards allow more flexibility than many organisations assume, provided intent, evidence and effect can be clearly demonstrated. 
  • Meaningful evidence links a defined baseline to a specific intervention and shows measurable change over time. 
  • Organisations are better prepared for audit conversations when they can talk through the thinking behind their approach and show how it connects to managing human risk. 

Continue the conversation…

For practitioners interested in how compliance expectations are evolving alongside human-centred security approaches, our Compliance Hub brings together a collection of webinars, articles and research exploring this shift in more depth.

You may also find our latest compliance guide useful: 

Evidence of Understanding – Rethinking Human Risk in Cyber Security Compliance for 2026 

The guide builds on many of the themes discussed here and includes perspectives from Amy Lemberger, alongside Tim Ward, CEO of Redflags and Lucy Finlay, Delivery Director for Secure Behaviour and Analytics at Redflags. It examines how organisations are interpreting standards, evidencing behavioural change and engaging constructively with auditors while strengthening real-world security outcomes. 

Access our Compliance Hub Here!

About the author

Amy Lemberger is the co-owner and Fractional CISO of Lemberger & Associates Limited and former CISO of Gamma, with over 15 years of experience driving security transformation across telecommunications, technology, and critical infrastructure sectors. Recognised as one of the Top 100 Influential Women in UK Tech (2024), she is known for aligning cyber security strategies with business goals, enabling organisations to scale securely while meeting complex regulatory demands.