Human-Centric Cyber Awareness

Why the future of cybersecurity starts with people.

two people discussing

For years, organisations have invested heavily in cybersecurity awareness training.

Our employees sit through annual training sessions. They complete the mandatory quizzes. They watch simulation videos. Completion rates are all tracked, reports are generated to explain the results, and leaders feel confident they addressed the human side of cybersecurity. But somehow, cyber incidents continue to occur at an alarming rate. And, humans remain the first point of entry.

Reality makes us uncomfortable but it’s very difficult to ignore: if awareness training alone worked, we would be far safer than we are today, wouldn’t we?

Organisations have spent years increasing their investment in awareness programmes, yet human error remains one of the most common contributors to cyber incidents. Traditional methods often overemphasise technology, assume more information automatically changes behaviour, and the methods rely on generic content that has little connection to the reality of how people work.

The challenge is not awareness.
The challenge is behaviour.

Cybersecurity is a human problem before it becomes a technology problem

Most employees know they should not click suspicious links. Most understand strong passwords are important. Most have heard the warnings about social engineering. Yet somehow, people still click. It’s not because people are careless. It’s because they are human.

Modern employees operate in environments with constant interruptions, competing priorities, information overload, hybrid work arrangements, and increasingly sophisticated digital interactions. Decisions are expected to be made in seconds. Attention is fragmented with constant content switching which has become the norm.

Threat actors understand this reality extremely well. Cybersecurity programmes don’t.

Human-centric cyber awareness starts with a simple but important observation: people don’t make decisions in a laboratory environment. They make decisions while busy, distracted, under pressure, and trying to get work done. If organisations want different security outcomes, training has to reflect those realities.

From compliance to behaviour change

Traditional awareness programmes are often designed to demonstrate compliance. Human-centric programmes are designed to change behaviour. That distinction matters. Completion metrics tell us who attended training, but they tell us little about whether someone will make a better decision when confronted with a convincing phishing email, a fraudulent payment request, or an AI-generated social engineering attempt.

Effective awareness programmes focus on understanding how people think, what motivates them, which biases influence decision-making, and where risky behaviours are most likely to occur. They incorporate behavioural science principles and continuously reinforce learning rather than treating awareness as a once-a-year exercise.

The objective is not to create security experts. The objective is to help people make safer decisions when it matters most.

Context matters

One of the biggest gaps in awareness programmes is the assumption that everyone faces the same risks. They don’t. For example:

A finance employee processing payments faces different threats than a member of the executive team.

A developer encounters different risks than a customer service representative.

A healthcare organisation operates under different pressures than a manufacturer or financial institution.

Human-centric awareness recognises these differences and tailors content to these differences. Training is aligned to specific roles, business processes, industries, and threat scenarios, making it more relevant, more engaging, and ultimately more effective.

When employees see themselves in the examples presented, they pay attention. When training feels generic, they tune out.

A smarter approach

The rise of AI makes the human element even more important

The cybersecurity landscape is shifting rapidly.

Artificial intelligence has lowered barriers for threat actors, accelerated social engineering capabilities, and increased the volume and sophistication of attacks. Organisations are also embracing AI internally to drive efficiency, innovation, and growth.

While technology continues to play an essential role in cyber defence, the human element becomes even more critical.

The future of cybersecurity will depend on organisations' ability to combine technology, process, and people into a resilient operating model. As cyber risk becomes more integrated into business strategy, resilience can’t be achieved through tools alone. Resilience requires employees at every level to become active participants in managing risk. That’s why awareness training has to evolve.

Organisations need programmes that help employees recognise emerging risks, adapt to changing environments, and make informed decisions in real-world situations.

Building security behaviours that last

The strongest cybersecurity cultures aren’t built through fear. They’re built through relevance.

Employees respond when training reflects their daily experiences, helps them understand consequences, and demonstrates practical ways to reduce risk without slowing down the business.

Organisations who succeed in this area treat awareness as an ongoing capability rather than an annual event. They continuously measure outcomes, refine content, identify high-risk behaviours, and reinforce positive security habits over time.

This approach transforms awareness from a compliance requirement into a business enabler.

It helps create a workforce that is more resilient, more informed, and better equipped to operate confidently in an increasingly complex digital environment.

The path forward

Cybersecurity has become a speed problem, not a technology problem.

Organisations are moving faster than ever. AI is accelerating innovation. Digital ecosystems are expanding. Threats continue to evolve.

In this environment, the organisations who thrive won’t be those with the longest awareness courses, most awareness training courses or the highest training completion rates.

They will be the organisations who understand people.

They will recognise that cybersecurity is ultimately about decision-making, behaviour, and culture.

The future of cyber awareness is not more content.

It is better outcomes.

And those outcomes begin with a human-centric approach that meets people where they are, reflects how they work, and empowers them to become one of the strongest layers of defence an organisation can build.

slate background

BDO helps organisations build stronger security behaviours through training that is practical, relevant, and aligned to real business risks.