Skip to content
  • Home
  • Resources
  • Blog
  • Compliance Standards to Security Habits: Security Awareness Training Needs Updating

Compliance Standards to Security Habits: Security Awareness Training Needs Updating

Webinar Thumbnail of 2 speakers, Kathy Bennett and Connor Swalm, with the title: Engagement > Compliance: Rethinking Security Awareness Training.

By Connor Swalm, Co-founder & CEO, Phin Security

We recently hosted a webinar with two experienced MSP leaders, Kathy Bennett and Brett Klieforth at CCB Technology, to discuss why some security awareness programs drive real behavior change while others struggle with employee engagement. The conversation covered everything from cyber insurance requirements and cybersecurity compliance standards to practical ways MSPs are increasing participation and building stronger security cultures. You can watch the full discussion below, then continue reading for my biggest takeaways and perspective on where the industry needs to go.


Watch the full webinar:


For years, organizations have approached cybersecurity awareness training with one goal in mind:

Check the box.

Of course you need to meet the cyber insurance requirements and pass the audits, but it shouldn’t stop there. In reality, that mindset is one of the biggest reasons security awareness programs fail.

After talking with hundreds of MSPs and security leaders, I've noticed almost everyone agrees they need cybersecurity awareness training, but very few spend enough time asking whether their program is actually changing employee behavior.

If your training exists solely to satisfy cybersecurity compliance, you're probably missing the bigger opportunity: reducing real-world risk.

 

Cybersecurity Compliance Is the Starting Point—Not the Finish Line

One of the biggest drivers behind cybersecurity awareness training today is compliance.

Whether you're dealing with:

  • Cyber insurance requirements
  • NIST Cybersecurity Framework recommendations
  • HIPAA
  • PCI DSS
  • CMMC
  • SOC 2
  • Or countless other cybersecurity compliance standards

...employee security awareness almost always appears somewhere in the requirements.

But most frameworks don't prescribe how you should deliver training. They simply require that employees receive it. That flexibility is helpful, but it also creates a trap where many organizations interpret the requirement as:

"As long as everyone watches one annual training video, we're compliant."

Compliance tells you what needs to happen. It rarely tells you how it should happen to actually change user behavior and add value to your security stack.

 

The Biggest Reason Employees Stop Engaging

When people ask why security awareness training doesn't work, they usually expect some complicated answer, but it’s actually pretty basic.

Employees stop paying attention when they stop believing the training is relevant and important to them.

That happens for several reasons:

  • The content doesn't match their role.
  • They've seen the same material repeatedly.
  • Training is too long.
  • It feels like punishment instead of education.
  • Nobody explains why they're doing it.

Eventually employees begin treating every training notification exactly the same:

Delete. Ignore. "I'll get to it later."

It’s not because employees don't care about security, but because humans naturally ignore things that don't feel immediately useful.

 

"I'm Not Going to Fall for a Phishing Email"

One of the most common responses MSPs hear is:

"I don't need this training." or "I'm careful enough."

Ironically, those are often the people who benefit the most.

Cybercriminals don't exclusively target non-technical users anymore. One of the more surprising findings I've seen over the years—and something we've discussed with security practitioners repeatedly—is that IT professionals aren't magically immune to phishing or social engineering. Everyone is still human.

The attack methods have evolved. Instead of obvious spelling mistakes and fake Amazon emails, attackers now use AI to gather public information, personalize messages, and make phishing campaigns significantly more convincing.

AI hasn't fundamentally changed phishing, the principles and the goal are still the same. However, it has dramatically improved attackers' ability to make social engineering believable.

That's why continuous education matters more today than ever before.

 

Annual Training Isn't Enough

Imagine going to the gym once every January. Would you expect to stay healthy all year? (The answer is no.)

Cybersecurity awareness works the same way. Threats evolve constantly, employees forget what they’ve learned — or it’s at least not top of mind — and completely new attack techniques develop constantly.

So why do many organizations still deliver training once a year? Because that's what they've always done and it hasn’t gotten them into trouble… yet.

Our MSP partner shared during the recent webinar that they encourage clients to deliver short monthly training because security stays top of mind. If employees only think about phishing once every twelve months, they're far less likely to recognize it when it actually appears in their inbox.

Small, consistent learning that builds habits beats marathon training sessions every time. Verizon’s 2025 Data Breach Investigations Report even found that phishing report rates increased by 4x when users had received training within 30 days prior.

 

Security Awareness Shouldn't Feel Like Punishment

I've seen organizations take wildly different approaches to cybersecurity awareness training.

Negative Reinforcement:

  • Treating failed phishing simulations like disciplinary actions
  • Assigning training as punishment instead of as consistent, continuous learning
  • Punishment for incomplete training

Positive Reinforcement:

  • Implementing competitions
  • Rewarding training completion with prizes
  • Celebrating departments with the highest training completion rates or the lowest phishing click rates

Can you guess which environments usually see better engagement? It’s the ones where employees aren't afraid to mess up, but are motivated to do well.

A security culture where people hide mistakes is dangerous. It means when a real threat occurs, you’re going to have a hard time responding quickly and efficiently. Instead, you should be creating a culture where people report suspicious emails early because they know they'll receive support—not blame.

When users believe reporting matters, they keep reporting. When they feel punished or like their reports aren’t going anywhere, they stop. Fewer tickets might sound nice, but only until you realize it’s better to have one hundred fire drills versus one real fire.

 

Leadership Matters More Than the Platform

One thing became incredibly clear during our conversation with CCB Technology:

The most successful cybersecurity awareness programs have engaged leadership.

When executives, managers, and department heads reinforce why training matters, employees take it more seriously. Not to mention, leadership is one of the most targeted employees by attackers.

People rarely want to do things without knowing why they need to do them. Leadership should help connect business objectives to employee actions so they understand the importance not just for the business, but for their role specifically.

And leadership should be a role model, not an exception to the rule. If the person who runs the company with access to highly sensitive information (yet doesn’t know CTRL+C is “copy”) doesn’t do their training, why would any other employees feel obligated to?

 

How Do You Know Training Is Actually Working?

Completion rates tell you if someone follows the rules, but they don’t tell you if someone is learning.

The key thing to focus on is: Has employee behavior changed?

Some indicators include:

  • More suspicious emails being reported.
  • Fewer compromised accounts.
  • Better password practices.
  • Employees asking security questions before clicking.
  • Fewer security-related support tickets over time.

CCB Technology shared a story about a user who had historically ignored password best practices. Months later, that same employee proactively used encrypted communication and followed password guidance before the technician even mentioned it.

That's behavior change and exactly what success looks like.

For more ways to prove ROI of your security awareness training, download this e-guide.

 

Give Employees Choices, Not Excuses

One lesson I've learned building a security awareness platform is that no single type of content works for everyone. Whether it’s the format or the tone of the training, what some clients love, others hate.

The goal isn't to find one perfect training module. It's to offer enough variety that employees feel like they have options while still completing the education they need. Just like every other aspect of cybersecurity, flexibility leads to better adoption.

 

Better Security Awareness Creates Better Security Outcomes

Cybersecurity compliance standards and cyber insurance requirements aren't going away. If anything, they're becoming more demanding, which isn’t a bad thing. They've helped normalize cybersecurity awareness training across organizations that previously ignored it.

But compliance should be viewed as the minimum acceptable standard—not the objective.

The organizations that see the biggest improvements don't stop after checking the compliance box. They:

  • Build habits
  • Reinforce learning consistently
  • Involve leadership
  • Measure behavior, not just completion rates

Over time, small improvements compound into a workforce that's prepared to recognize and respond to real threats. At the end of the day, cybersecurity awareness training isn't about passing an audit. It's about helping people make better security decisions when it matters most.

For a full guide on how to go beyond cybersecurity compliance standards and create real change with security awareness training, download this SAT Best Practices e-guide.

 

 

Leave a comment: