Security awareness that changes behaviour
A method for running an awareness programme against measured behaviour instead of completion rates, with the training records falling out as a by-product.
Governance5 Sept 202622 min read
On this page
Scope: one awareness programme, end to end · Who: the officer accountable for it · Prerequisites: an incident log and a named sponsor · First result: a behaviour baseline in six weeks
1. Why this exists (the failure mode it prevents)
Awareness programmes are usually measured by the wrong number. Completion is cheap to count and easy to reach. A module goes out in October, reminders follow in November, and the year-end report shows 98 per cent. Nothing observable about the organisation has changed.
That is a measurement choice, not a failure of effort. Completion measures the delivery of content. It says nothing about whether anyone reports a suspicious message faster, stores a shared credential differently, or stops an out-of-band payment request.
Three patterns follow. The annual module becomes a fixed syllabus with no relation to the incidents the organisation actually has. The phishing simulation becomes a trap: the headline is the click rate, individuals are named, and people quietly stop reporting. The training record satisfies a clause on paper and nothing else.
It surfaces in assessment predictably. ISO/IEC 27001:2022 clause 9.1 is titled "Monitoring, measurement, analysis and evaluation" 1. An assessor asks what the programme is meant to change, how that change is measured, and what the last three measurements showed. A completion report answers none of the three.
The standard asks the same at control level. ISO/IEC 27002:2022 control 6.3 is Information security awareness, education and training. It says understanding should be assessed at the end of an activity, to test knowledge transfer and programme effectiveness 2. A completion tick tests neither.
The regulatory version is sharper. Article 21(2)(g) of Directive (EU) 2022/2555 lists basic cyber hygiene practices and cybersecurity training among the measures essential and important entities must at least take 3. Article 21(2)(f) requires policies and procedures to assess the effectiveness of those measures 4. A slide deck is not such an assessment.
This playbook replaces the completion number with a small set of measured behaviours, and treats every intervention as an experiment against one of them.
2. Definitions (only the ones that cause disputes)
Six terms account for most disagreement between a security function, its assessor and its human resources partner. Guidance text is paraphrased throughout; titles are quoted, and nothing longer than a short phrase.
| Term | Working definition | Source |
|---|---|---|
| Awareness | Working definition: what a person needs to know about the policy, their contribution and the consequence of not conforming. General, for everyone in scope. | ISO/IEC 27001:2022 clause 7.3, titled "Awareness" 5 |
| Competence | Working definition: the ability to do a specific job to a defined standard, shown by education, training or experience and recorded per role. Awareness does not substitute for it. | ISO/IEC 27001:2022 clause 7.2, titled "Competence" 6 |
| Target behaviour | One observable action, by a named audience at a named moment, that changes the outcome of a plausible incident. "Be vigilant" is not one. "Report a suspected message within ten minutes" is. | Working term, measured under clause 9.1 1 |
| Measure of behaviour | A number produced by a system that records the behaviour, not by asking people about it. Report counts and approval records qualify; survey confidence does not. | Working term; control 6.3 asks for assessed understanding and programme effectiveness 2 |
| Cyber hygiene | A common baseline of practices. Recital 49 names software and hardware updates, password changes, management of new installs, limits on administrator-level accounts, and backing up data. | Directive (EU) 2022/2555, recital 49 7 |
| Management-body track | A separate duty on the board, not a senior edition of the staff module. Its members are required to follow training; entities are encouraged to offer similar training to employees. | Directive (EU) 2022/2555 Art. 20(2) 8 |
The first two are worth separating in writing, because assessors do. Clause 7 of ISO/IEC 27001:2022 covers resources, competence, awareness, communication and documented information 9. An awareness campaign delivered to an engineering team is not a competence record.
3. The method — numbered steps, each with input, activity, output and owner
Eight steps. The first four build the programme from evidence the organisation already holds. The fifth handles the body carrying its own duty. The last three measure, record and retire.
3.1 Start from incidents and risks, not from topics
Most syllabuses are inherited: they cover phishing, passwords and clear desk because the previous version did. Start instead from what has gone wrong here, and from what the risk register says could.
Read the last twenty-four months of the incident log and pull out the human action in each entry. Someone clicked, shared, approved, skipped a step, or waited two days before reporting. Group those actions, keep the groups that recur, then cross-check the risk register for scenarios where a human action is the first or last line of defence.
Five to eight target behaviours is the working range: fewer ignores real exposure, more and no single behaviour gets enough attention to move.
ISO/IEC 27002:2022 control 6.3 supports this directly: the programme should be built on lessons learnt from information security incidents 2. A syllabus with no traceable link to the incident log is one nobody chose.
- Input: incident log for the last twenty-four months; risk register; policy set and topic-specific policies.
- Activity: extract the human action from every incident; group and rank by frequency and consequence; select five to eight behaviours; write each as an observable action.
- Output: behaviour catalogue, one row per behaviour, with audience, moment, action and the failure it prevents.
- Owner: security officer drafts; risk owners confirm the ranking.
3.2 Map the audiences and their moments
A behaviour without a moment is a poster. The moment is when the person is in the situation: opening a payment request, being granted an administrator role, changing team.
Six audiences cover most organisations — new joiners, role changers, privileged-access holders, the management body, engineers, and third parties with access. Control 6.3 puts external people explicitly in scope: the programme should be planned taking account of the roles of personnel, including internal and external personnel such as external consultants and supplier personnel. The same control treats a substantial change of role as an initial-training trigger, alongside joining 2.
Financial entities are to include ICT third-party service providers in the relevant training schemes where appropriate 10. For everyone else the same reach comes through supplier obligations.
Write the map as a grid: audience down the side, behaviour across the top, the moment in each cell. Empty cells are as informative as full ones.
- Input: behaviour catalogue; joiner, mover and leaver process; access model; supplier register.
- Activity: list the audiences; name the moment each meets each behaviour; mark empty cells and decide whether the behaviour applies.
- Output: audience map, a grid of audience against behaviour, with the moment named in each live cell.
- Owner: security officer, with the human resources partner and the access owner.
3.3 Baseline the behaviours before intervening
This is the step programmes skip, and skipping it is why nothing can be shown afterwards. A measure taken only after the campaign proves nothing.
Every measure comes from a system that records the behaviour: the reporting channel, the credential store, the approval records, the endpoint estate, the change record. Surveys measure confidence, which in our working view is not the same thing as behaviour.
Take the baseline over a defined window and record the method, not only the number. A report rate measured against a different denominator next quarter is not a comparison.
Two measures need care. A report rate reflects how easy and how safe reporting feels, in our working view, so read it beside median time-to-report. A low click rate on an obvious lure tells us little.
- Input: audience map; access to the recording systems; a defined measurement window.
- Activity: define one or two measures per behaviour; write down the source system, denominator and collection method; collect the first window; record who can reproduce it.
- Output: measure definitions and the baseline record, one value per behaviour per audience cohort.
- Owner: security officer defines; the system owners produce the numbers.
3.4 Design one intervention per behaviour, and run it as an experiment
An intervention exists to move one measure. If it cannot be tied to a measure, it does not go in the calendar. Four kinds cover most of the work.
Just-in-time prompts sit at the moment itself: a banner on external mail, a confirmation step on a first-time payee, a reminder in the approval screen. They do not rely on recall.
Role-based sessions carry what genuinely differs by role. Control 6.3 asks for a training plan for technical teams whose roles need specific skill sets, and for acquiring skills that are missing 2. That is competence work under clause 7.2, and it produces a competence record rather than an awareness record.
Simulations run as practice. Publish the rules before the first run: what is simulated, how often, what is recorded, who sees individual results, and what never follows from them. The measures are report rate and time-to-report, not click rate.
That is not a matter of taste. ISO/IEC 27002:2022 control 6.4, Disciplinary process, describes a graduated response that weighs whether an offence was intentional or accidental, first or repeated, and whether the person was properly trained. It also asks that people facing disciplinary action are shielded from exposure where possible, and it allows good behaviour to be rewarded 11. A simulation that names people inverts both.
Leader modelling is a control in its own right. ISO/IEC 27002:2022 control 5.4 is Management responsibilities. It asks that personnel be briefed before access is granted, and given guidelines stating what their role expects 12. Where practicable, it also asks for a confidential channel for reporting violations 12.
Two behaviours have control text worth designing against. Control 6.8 is Information security event reporting. It asks that the mechanism for reporting observed or suspected events be as easy, accessible and available as possible 13. It also asks that people be told the procedure and the point of contact, and that they not try to prove a suspected vulnerability 13.
Control 8.7 is Protection against malware. It states that protection should be supported by appropriate user awareness, and that detection and repair software alone is not usually adequate 14. It asks for training on identifying malware-infected mail, files and programs 14.
- Input: behaviour catalogue; audience map; baseline record.
- Activity: design one intervention per behaviour per audience; state the measure it targets and the change expected; schedule it; publish the simulation rules first.
- Output: intervention calendar, naming a target measure and expected direction per entry; simulation rules, published.
- Owner: security officer designs; the audience's line management sponsors delivery.
3.5 Run the management-body track as a separate obligation
The board's training is a duty in its own name, not the staff module with a shorter deck.
Directive (EU) 2022/2555 requires Member States to ensure that members of the management bodies of essential and important entities follow training 8. Member States must also encourage those entities to offer similar training to employees regularly 8. The purpose is that they gain sufficient knowledge and skills to identify risks, and to assess cybersecurity risk-management practices and their impact on the entity's services 8.
The same article puts the body in the approval seat. Management bodies approve the Article 21 measures, oversee implementation, and can be held liable for the entity's infringements 15. Training that leaves a member unable to challenge a proposed measure set has missed the clause.
Financial entities carry two overlapping duties. Regulation (EU) 2022/2554 makes ICT security awareness programmes, and digital operational resilience training, compulsory modules within the staff training scheme 10. Those modules reach all employees and senior management staff, with complexity matched to the remit of their functions 10. Separately, members of the management body must keep up to date with the knowledge and skills to understand and assess ICT risk, through regular training 16.
A third literacy duty sits alongside them. Regulation (EU) 2024/1689 requires providers and deployers of AI systems to take measures supporting the AI literacy of their staff 17. The duty reaches other persons dealing with the operation and use of those systems on their behalf 17. It does not require any specific level of AI literacy to be guaranteed in any individual 17. Because no level is defined, the defensible position is a stated one: write down what sufficient means for each role, and keep the record of what was delivered.
- Input: the applicable instruments; the measure set awaiting approval; the register of AI systems in use.
- Activity: set a syllabus around assessment and challenge rather than threat description; fix the cadence; record attendance per member; state the AI-literacy level per role.
- Output: management-body programme with syllabus, cadence and per-member attendance; AI-literacy statement per role.
- Owner: the chair or company secretary schedules; the security officer supplies the content.
3.6 Measure change, not completion
The measurement step reuses the definitions written in 3.3. Nothing new is invented, or the comparison is lost.
Report by cohort, not as an organisation-wide average. An average hides the two things worth acting on: the audience that has not moved, and the audience that moved and then slid back.
Read each measure against the direction stated in the calendar. Three outcomes are all useful. It moved as expected, so the intervention stays. It did not move, so it is redesigned or dropped. It moved the wrong way, which usually means the intervention changed what people report rather than what they do.
This is what the directive means by procedures to assess the effectiveness of the measures 4. NIST CSWP 29 sets the PR.AT outcome: personnel receive cybersecurity awareness and training so they are able to perform their cybersecurity-related tasks 18. Performing the task is the test, not attending the session.
- Input: measure definitions; the baseline record; the intervention calendar with its stated expectations.
- Activity: collect each measure for the period using the recorded method; compare to baseline by cohort; classify each intervention as kept, redesigned or dropped; record the decision.
- Output: quarterly measure set by cohort, with the decision per intervention.
- Owner: security officer produces; the sponsor reviews the decisions.
3.7 Let the training record fall out of the work
The record that satisfies clauses 7.2 and 7.3 is a by-product of steps 3.4 to 3.6. It becomes a separate exercise only when the programme produced nothing else.
Keep three sets separately. The awareness record covers everyone in scope and shows what each person was made aware of and when. The competence record covers roles needing a defined skill and shows how it was established. The effectiveness record is the baseline plus the quarterly measure sets plus the decisions.
Control 6.3 asks that understanding be assessed at the end of an activity 2. An awareness entry carrying a comprehension result is therefore stronger than an attendance line. The control lists what general awareness should cover: management's commitment, the applicable rules and obligations, and personal accountability 2. It names basic procedures such as event reporting, and the contact points for advice 2.
Store the sets where the process already keeps its records, and name them in the document control register.
- Input: delivery records; comprehension results; measure sets; the document control register.
- Activity: separate the awareness, competence and effectiveness records; attach comprehension results to awareness entries; register the location and retention of each set.
- Output: training record set, in three parts, registered and retained.
- Owner: human resources holds the per-person records; the security officer holds the effectiveness record.
3.8 Keep it alive, and retire what does not move a measure
A programme that runs unchanged for three years is a syllabus. Three mechanisms keep it current.
Incident-driven refresh. An incident whose human action matches a catalogue behaviour triggers a review of that intervention within the month. One matching nothing in the catalogue asks whether the catalogue is complete.
Annual re-baseline. Repeat 3.3 in full once a year, with the same methods, and reset the comparison point.
Retirement. An intervention that has not moved its measure across two consecutive periods is dropped, and the reason recorded. Its absence is why calendars only ever grow.
Where a measure does not move because the underlying control is missing, that is a finding, not an awareness problem. ISO/IEC 27001:2022 clause 10.2, Nonconformity and corrective action, separates reacting to the nonconformity, examining its cause, acting on the cause and reviewing effectiveness 19. A campaign aimed at a missing control fails the second of those.
- Input: incident log; the quarterly measure sets; the intervention calendar; the finding register.
- Activity: review the affected intervention within a month of each matching incident; re-baseline annually; drop interventions that have not moved a measure over two periods. Raise a finding where the cause is a missing control.
- Output: updated behaviour catalogue and intervention calendar, with a dated retirement note per dropped item.
- Owner: security officer; the sponsor approves retirements.
4. Deliverables
Seven artefacts carry the method. Retention periods are organisational choices, not requirements of any instrument cited here.
| Deliverable | Produced by | Format | Retention |
|---|---|---|---|
| Behaviour catalogue | Step 3.1, revised in 3.8 | register | current version, plus one cycle |
| Audience map | Step 3.2 | grid | current version |
| Measure definitions and baseline | Step 3.3, reset in 3.8 | register plus data extract | whole cycle |
| Intervention calendar and simulation rules | Step 3.4 | plan plus published rules | whole cycle |
| Management-body programme and AI-literacy statement | Step 3.5 | syllabus plus attendance | whole cycle, plus one |
| Quarterly measure set | Step 3.6 | data extract with decisions | whole cycle, plus one |
| Training record set, in three parts | Step 3.7 | per-person plus effectiveness records | per the retention policy |
5. What the auditor or authority will ask
Every clause, article and subcategory below is verified where it is first cited, in sections 2, 3 or 7. The phrasing follows an assessor's line of enquiry: a request for the record, then for the decision behind it.
An enquiry that stays on the syllabus is going well. One that moves to the measures, and then to the cohort that did not improve, is where a completion-based programme runs out of answers.
6. Failure modes and how they surface as findings
Five patterns account for most avoidable findings. Each is the pattern, the wording it tends to produce, and the smallest change that removes it.
The root of all five is the same: the programme was designed backwards from a number that was easy to produce.
7. Mapping behaviour to requirement, intervention, measure and evidence
Clause and control titles below were read from the sources named in the References section, on the dates shown. Guidance text is paraphrased; only titles are quoted.
| Behaviour | Requirement | Intervention | Measure | Evidence | Verified |
|---|---|---|---|---|---|
| Report a suspected event promptly | ISO/IEC 27002:2022 control 6.8 | One-click reporting in the mail client | Reports per hundred staff; time-to-report | Reporting channel extract | 13 |
| Keep every work credential in the managed store | Directive (EU) 2022/2555 Art. 21(2)(g) | Enrolment at joining; shared-account clean-up | Staff fully enrolled; shared accounts | Credential store extract | 3 |
| Verify payment and access changes out of band | ISO/IEC 27002:2022 control 5.4 | Confirmation step on first-time payees | Changes verified on a second channel | Approval records | 12 |
| Place confidential data only in sanctioned stores | NIST CSWP 29 PR.AT-01 | Prompt on external sharing; role sessions | Confidential items outside sanctioned stores | Data store scan and sharing log | 20 |
| Patch, lock and report a lost device same day | ISO/IEC 27002:2022 controls 6.8, 7.9 and 8.8 | Endpoint prompt; one-click loss reporting | Patch compliance at day fourteen; time to report | Endpoint estate report | 21 |
| Put every production change through approval | NIST CSWP 29 PR.AT-02 | Role session for engineers; gate in the pipeline | Changes with recorded approval; emergency ratio | Change record extract | 22 |
| Use only registered AI systems, within instructions | Regulation (EU) 2024/1689 Art. 4(1) | AI-literacy session per role; registration path | Share of AI use cases registered | AI use-case register; gateway logs | 17 |
| Management body: challenge and approve the measures | Directive (EU) 2022/2555 Art. 20(1) | Assessment-focused syllabus, fixed cadence | Attendance per member; challenges recorded | Minuted approval | 15 |
| Programme: prove effectiveness, not delivery | ISO/IEC 27001:2022 clause 9.1 | Quarterly review, one decision per intervention | Movement per measure per cohort | Quarterly measure set | 1 |
| Programme: put security into people processes | NIST CSWP 29 GV.RR-04 | Joiner and mover triggers wired to the map | Joiners and movers reached at the right moment | Joiner and delivery records | 23 |
Two notes. Regulation (EU) 2024/2847 places no article-level training duty on manufacturers, so it is not mapped. The Annex A awareness control is cited through ISO/IEC 27002:2022, which carries the same numbering and is the text that was read.
8. Checklist
Each item is observable. "Staff are aware" is not; a dated measure with a recorded method is.
References
Primary sources only. The European instruments were read at the EU Publications Office, the framework at the publisher, the ISO/IEC 27001 clause titles on the publisher's contents listing, and the ISO/IEC 27002 controls in a licensed copy.
- European Parliament and Council. Directive (EU) 2022/2555 of 14 December 2022 on measures for a high common level of cybersecurity across the Union (NIS 2 Directive). OJ L 333, 27.12.2022, p. 80. Articles 20 and 21 and recital 49 read at https://publications.europa.eu/resource/celex/32022L2555 24
- European Parliament and Council. Regulation (EU) 2022/2554 of 14 December 2022 on digital operational resilience for the financial sector (DORA). OJ L 333, 27.12.2022, p. 1. Articles 5 and 13 read at https://publications.europa.eu/resource/celex/32022R2554 25
- European Parliament and Council. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), consolidated text of 27 July 2026. Article 4 read at https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:02024R1689-20260727 26
- National Institute of Standards and Technology. The NIST Cybersecurity Framework (CSF) 2.0. NIST CSWP 29. Appendix A, the CSF Core, read at https://doi.org/10.6028/NIST.CSWP.29 27
- ISO/IEC. Information security, cybersecurity and privacy protection — Information security management systems — Requirements. ISO/IEC 27001:2022. Contents and clause titles read at https://www.iso.org/obp/ui/#iso:std:iso-iec:27001:ed-3:v1:en 28
- ISO/IEC. Information security, cybersecurity and privacy protection — Information security controls. ISO/IEC 27002:2022. Controls 5.4, 6.3, 6.4, 6.8 and 8.7 read in a licensed copy; catalogue entry at https://www.iso.org/standard/75652.html 29
- European Parliament and Council. Regulation (EU) 2024/2847 (Cyber Resilience Act). Checked for a manufacturer-side training duty: recital 23 says manufacturers should ensure their staff has the necessary skills, and no article imposes one 30
Retention periods, cadences and cohort definitions above are organisational choices, not requirements of any instrument or standard cited here.
Sources
- 1ISO/IEC 27001:2022 clause 9.1, iso.org/obp · verified 2026-09-03
- 2ISO/IEC 27002:2022 control 6.3, licensed copy · verified 2026-09-05
- 3EU Publications Office CELEX 32022L2555 Art. 21(2)(g) · verified 2026-09-05
- 4EU Publications Office CELEX 32022L2555 Art. 21(2)(f) · verified 2026-09-05
- 5ISO/IEC 27001:2022 clause 7.3, iso.org/obp · verified 2026-09-03
- 6ISO/IEC 27001:2022 clause 7.2, iso.org/obp · verified 2026-09-03
- 7EU Publications Office CELEX 32022L2555 recital 49 · verified 2026-09-05
- 8EU Publications Office CELEX 32022L2555 Art. 20(2) · verified 2026-09-05
- 9ISO/IEC 27001:2022 clause 7, iso.org/obp · verified 2026-09-03
- 10EU Publications Office CELEX 32022R2554 Art. 13(6) · verified 2026-09-05
- 11ISO/IEC 27002:2022 control 6.4, licensed copy · verified 2026-09-05
- 12ISO/IEC 27002:2022 control 5.4, licensed copy · verified 2026-09-05
- 13ISO/IEC 27002:2022 control 6.8, licensed copy · verified 2026-09-05
- 14ISO/IEC 27002:2022 control 8.7, licensed copy · verified 2026-09-05
- 15EU Publications Office CELEX 32022L2555 Art. 20(1) · verified 2026-09-05
- 16EU Publications Office CELEX 32022R2554 Art. 5(4) · verified 2026-09-05
- 17EU Publications Office CELEX 02024R1689-20260727 Art. 4(1) · verified 2026-09-05
- 18NIST CSWP 29 Appendix A PR.AT, nvlpubs.nist.gov · verified 2026-09-05
- 19ISO/IEC 27001:2022 clause 10.2, iso.org/obp · verified 2026-09-03
- 20NIST CSWP 29 Appendix A PR.AT-01, nvlpubs.nist.gov · verified 2026-09-05
- 21ISO/IEC 27002:2022 controls 6.8, 7.9 and 8.8, licensed copy · verified 2026-09-05
- 22NIST CSWP 29 Appendix A PR.AT-02, nvlpubs.nist.gov · verified 2026-09-05
- 23NIST CSWP 29 Appendix A GV.RR-04, nvlpubs.nist.gov · verified 2026-09-05
- 24EU Publications Office CELEX 32022L2555 · verified 2026-09-05
- 25EU Publications Office CELEX 32022R2554 · verified 2026-09-05
- 26EU Publications Office CELEX 02024R1689-20260727 · verified 2026-09-05
- 27NIST CSWP 29 Appendix A, nvlpubs.nist.gov · verified 2026-09-05
- 28ISO/IEC 27001:2022 contents, iso.org/obp · verified 2026-09-03
- 29ISO/IEC 27002:2022 controls 5.4, 6.3, 6.4, 6.8 and 8.7, licensed copy · verified 2026-09-05
- 30EU Publications Office CELEX 32024R2847 recital 23 · verified 2026-09-05