Security executives say annual training fails to drive behavioral change

As organizations prepare for Cybersecurity Awareness Month this October, industry leaders are warning that traditional annual training modules and phishing simulations are failing to drive genuine behavioral change. IT security executives view the standard October campaign as a useful amplifier rather than a standalone defense strategy, arguing instead for continuous risk management and operational resilience.

Beyond Annual Compliance Exercises

Every October, corporate security teams roll out refreshed training, informational posters, and phishing simulations. Security executives argue this approach misses the core mark of modern threat mitigation if treated as a standalone cure-all.

I believe Cyber Awareness Month (CAM) is a valuable amplifier and another reminder about the importance we all play in an organization’s cybersecurity risk management program. However, it cannot be the strategy. If companies use CAM as another training module, then it’s just another compliance exercise.

That perspective comes from Rob Gregory, CISO at Optiv. Gregory emphasizes that tracking completion rates for an annual course completely misses the operational reality of digital threats. Security awareness must function as a 24/7, 365-day-a-year operation focused entirely on long-term behavioral reinforcement.

Rafael Narezzi, co-founder and CEO of Centrii, notes that the scope of awareness must expand far beyond traditional employee watch-lists. For years, awareness campaigns focused heavily on what individual workers should do differently, such as recognizing phishing attempts, strengthening passwords, and avoiding suspicious links.

Narezzi argues that while those habits remain foundational, today’s threats demand a much wider definition of operational awareness. Employees should not simply be labeled the weakest link in a chain. Instead, organizations must equip personnel to serve as an active layer of defense.

Redefining Risk in Critical Infrastructure Environments

In critical infrastructure sectors, the stakes of a security failure transcend standard data exfiltration. Narezzi explains that cyber risk is operational risk in these environments.

A compromised battery storage system, renewable energy site, or remote-access connection often lacks the obvious warning signs of a conventional corporate data breach. Instead, the real-world consequences manifest as lost generation, unstable operations, reduced availability, and direct financial loss.

This operational reality forces companies to look far beyond their own internal firewalls. As energy infrastructure becomes increasingly distributed and interconnected, organizations require visibility into the vendors and technologies supporting their operations.

Narezzi also warns that security leaders currently suffer from alert fatigue, characterized by too many alerts paired with too little context. Executives must possess the ability to figure out which vulnerabilities could interrupt business functions, calculate what share of revenue or capacity is in jeopardy, and identify the precise step that will mitigate that danger first.

Building Day-to-Day Habits Against Criminals

Aligning with this year’s official theme, “Don’t Make It Easy for Them,” Sandhya Arun, Chief Technology Officer at Wipro, frames the campaign as a call to build consistent, day-to-day habits that make life difficult for cyber criminals. Arun notes that this mandate applies equally to individuals in their personal lives and to organizations.

As AI becomes more widely adopted, attackers and defenders alike are gaining access to new capabilities. AI-enabled techniques can automate reconnaissance, generate convincing content, and increase the scale at which cyber operations are conducted. For organizations, this raises the imperative to strengthen detection and response, reducing the time between identifying a threat and acting on it.

Arun cautions that artificial intelligence is not a silver bullet. While AI will strengthen cyber defense, it will not make organizations breach-proof.

Organizations must focus on comprehensive systems spanning both prevention and resilience. Cyber agility—defined as the capacity to spot a breach promptly, limit its expansion, bounce back without delay, and evolve following the incident—represents the ultimate competence for contemporary businesses.

Achieving that level of agility depends heavily on getting the balance between automation and people right.

Photo of author

Sophie Lin - Technology Editor

Sophie is a tech innovator and acclaimed tech writer recognized by the Online News Association. She translates the fast-paced world of technology, AI, and digital trends into compelling stories for readers of all backgrounds.

Benzothiazole compounds reduce blood glucose in diabetic rats