Organisations should move to personalised campaigns when one size fits all messaging stops producing measurable improvement. Different roles face different risks, and learners absorb material differently. If phishing results, click rates, or quiz scores remain flat over time, the programme needs segmentation, targeted content, and better feedback loops. Personalisation is most valuable when the audience is diverse and the threat exposure is uneven.
When does a training programme stop working as a single message?
Generic awareness works best when the workforce is relatively uniform and the risk pattern is simple. Once different teams face different attack paths, the programme should be judged on whether it still changes behaviour in the areas that matter. If results stay flat, the issue is usually not awareness volume, but poor fit between message, audience and risk.
A useful trigger is repetition without movement: repeated phishing failures, unchanged quiz performance, or managers who cannot show that high-risk groups are improving. That is the point where broad reminders stop being enough and the programme needs segmentation, role-aware messaging and tighter feedback loops. Personalisation is less about making content friendlier and more about making it operationally relevant.
It also matters that awareness is not one control. Different audiences need different emphasis: finance may need payment fraud scenarios, engineers may need secret handling and change-risk examples, and executives may need impersonation and approval-friction scenarios. When the same message is sent everywhere, the training may still be useful, but it is no longer precise enough to shift the highest-risk behaviours.
What changes when the audience is segmented?
Segmentation lets organisations align content with the actual exposure of each group instead of assuming a single baseline risk. That usually means separating by function, privilege level, tool usage, or exposure to specific attack types. The practical win is not more content, but more relevance: each group sees the mistakes, lures and consequences that are most likely to affect them.
This also improves measurement. If a campaign is personalised, you can compare like with like, rather than hiding weak performance behind a broad average. That makes it easier to see whether a department needs a different scenario set, a different cadence, or a manager-led intervention. It also reduces the common failure mode where a programme reports high completion rates but no meaningful change in susceptibility.
Personalisation works best when it is tied to a known behaviour change objective. For one audience that may be reducing click-through on phishing simulations; for another it may be shortening the time to report suspicious messages; for another it may be improving handling of sensitive data prompts. If the campaign cannot connect content to a measurable action, it becomes harder to tell whether personalisation is actually doing anything.
How should organisations decide the right level of personalisation?
The right level is usually the smallest amount needed to address a real difference in risk or comprehension. Start with broad segmentation, then add deeper tailoring only where the data shows uneven exposure or stubborn failure. Over-customising too early can create unnecessary operational burden, while under-customising leaves high-risk groups under-served.
A practical approach is to use outcome data as the decision rule. If one segment is improving and another is not, do not redesign the entire programme. Adjust the lagging segment’s content, delivery format or cadence first, then re-test. That keeps the programme focused on observed behaviour rather than assumptions about what should work.
Useful personalisation also depends on credibility. People ignore generic training when it feels detached from their day-to-day work. Campaigns become more persuasive when they use role-specific examples, current attack themes, and simple calls to action that match the recipient’s responsibilities. The goal is not to make every lesson unique, but to make the message recognisably relevant to the person receiving it.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-14 — Security Awareness and Skills Training | Directly covers role-aware awareness training and behavior change measurement. |
| Recommendation — Segment training by role and verify it changes risky behaviors, not just completion rates. | ||
| NIST CSF 2.0 | PR.AT-01 — All personnel are provided security awareness training | Supports awareness training as an ongoing protective control for the workforce. |
| PR.AT-02 — Employees and roles receive role-based training | Directly matches the move from generic messaging to audience-specific awareness. | |
| Recommendation — Tailor awareness delivery to audience risk and validate that training changes behavior. Deliver role-based awareness content that reflects each group’s actual exposure. | ||
| NIST SP 800-53 Rev 5 | AT-2 — Awareness Training | Establishes workforce awareness training as a formal control needing effectiveness. |
| AT-3 — Role-Based Training | Directly supports personalized campaigns aligned to job function and risk. | |
| Recommendation — Use training effectiveness results to refine audience segmentation and content. Align awareness scenarios to job-specific threats and responsibilities. | ||
Practitioner Guidance
What to verify: Before moving to personalised campaigns, confirm that you have enough behavioural data to justify the split. If you cannot show a stable difference between groups, you may be seeing random variance rather than a training problem.
What to measure: Track a small set of outcomes that reflect real behaviour, not just attendance. Click rates, report rates, repeat failure rates and time-to-report give a better picture of whether segmentation is changing outcomes.
Common mistake: Do not confuse more content with better personalisation. The weak version of personalisation is simply adding role labels to the same message; the useful version changes the scenario, the risk context or the action expected from the learner.
Practitioner takeaway: Move from generic to personalised awareness when the programme can no longer explain or improve uneven performance, and when different groups clearly need different behavioural cues to reduce their specific risk.
Related resources from NHI Mgmt Group
- What breaks when organisations rely on generic security awareness training instead of behaviour-based risk management?
- When should organisations move from generic awareness campaigns to risk-based interventions?
- What do organisations get wrong when they rely on generic security awareness training for PCI DSS?
- What do organisations get wrong about email security awareness training?