Join our Newsletter — 33% off our NHI Course

What should security teams do to build a culture of cyber awareness across the organisation?

Security teams should make awareness part of everyday work by combining policy, training, practice, and easy-to-use controls. Encourage peer learning, run incident response dry runs, and use blue and purple team exercises to expose weaknesses safely. When people can learn, test themselves, and receive feedback without blame, security becomes shared behavior rather than a compliance exercise.

Make awareness part of daily security behavior, not a one-off programme

Culture changes when cyber awareness is embedded into routine work, not delivered as an annual reminder. Teams should connect policy, training, and simple controls to real tasks so people learn the secure path while they are doing their jobs. That means making expected behavior visible, reinforcing it often, and reducing friction so the secure choice is also the easy choice.

Effective awareness programmes also treat learning as social. Peer discussion, manager reinforcement, and short practice loops usually work better than purely passive content because people remember what they do, not only what they read. A good programme gives staff enough context to recognise suspicious activity, report it quickly, and understand how their role fits into the organisation’s wider security posture.

Use practice to turn knowledge into muscle memory

Awareness becomes real when people rehearse decisions under realistic conditions. Incident response dry runs, phishing simulations, and blue and purple team exercises help teams see how attacks unfold, where people hesitate, and which controls fail under pressure. The value is not embarrassment or scorekeeping, it is safe exposure to weak points before an actual incident forces the lesson.

Exercises should be designed to expose both technical and human failure modes. If staff only ever hear what the right answer is, they will not learn how to act when uncertainty, urgency, or conflicting instructions are present. Practice should include reporting paths, escalation cues, and the handoff between users, operations, and security so the organisation can respond as one system rather than as disconnected teams.

Practices such as blue and purple teaming are especially useful when they are linked to known attack patterns and observed control gaps. The 52 NHI Breaches Report is a useful reminder that real-world compromise often follows repeatable paths through weak access paths, exposed credentials, and poor control hygiene, which makes rehearsal and feedback more valuable than abstract advice.

Design the organisation so the secure action is easy to repeat

Awareness programmes fail when they ask people to remember too much or work around inconvenient controls. Security teams should reduce unnecessary complexity, standardise the expected path, and provide just enough guidance at the moment of need. Clear reporting buttons, concise playbooks, and simple approval paths make it more likely that people will behave securely even when they are busy.

That same principle should apply across channels and functions, not only in the security team. Managers, HR, legal, IT, and operations each shape what people believe is acceptable. When leadership reinforces the same message, and when controls match that message, awareness becomes part of organisational habit rather than a side conversation owned by security alone.

Teams should also watch for places where process friction creates shadow behavior. If a secure workflow is slower than an unsafe shortcut, people will eventually take the shortcut unless the control is redesigned. The strongest culture signals are usually practical ones: fast reporting, visible follow-up, and controls that make the safe path straightforward.

Risk and Threat Considerations

A weak awareness culture increases the odds that normal human behavior becomes an attack path. People who do not understand why a control exists are more likely to ignore warnings, approve unsafe requests, or delay reporting when something looks wrong. That creates exposure to phishing, social engineering, credential theft, and slower incident containment.

Failure mechanism: attackers exploit trust, urgency, and confusion, then use the resulting delay or misjudgment to gain access, move laterally, or hide activity long enough to increase impact.

Impact: the organisation sees more successful initial access, more inconsistent reporting, and a wider blast radius before detection and response begin.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 PR.AT-01 — Awareness and Training Policy and Procedures Cyber awareness programmes need defined training policies and procedures.
PR.AT-02 — Awareness of Roles and Responsibilities Culture improves when staff understand their security responsibilities.
PR.AT-03 — Third-Party Stakeholder Awareness Awareness culture must extend beyond the security team to stakeholders.
Recommendation — Define and maintain a training policy that reinforces secure behavior across the organisation. Clarify security responsibilities so employees know how to act and escalate. Extend awareness expectations to relevant third parties and business partners.
NIST SP 800-53 Rev 5 AT-2 — Awareness Training The topic centers on recurring awareness training and reinforcement.
AT-3 — Role-Based Training Different functions need different security behaviors and escalation cues.
IR-3 — Incident Response Testing Dry runs and exercises are central to the question's practice-based approach.
Recommendation — Deliver role-appropriate awareness training and refresh it regularly. Tailor training to each role so the guidance matches actual decisions. Test incident response procedures with exercises and table-top rehearsals.
CIS Controls v8 CIS-14 — Security Awareness and Skills Training This is the core CIS safeguard for building organisation-wide awareness.
CIS-17 — Incident Response Management Dry runs and escalation practice are part of mature awareness culture.
Recommendation — Run continual awareness training that is relevant, role-based, and reinforced. Exercise incident response so staff can report and escalate correctly under stress.
ISO/IEC 27001:2022 A.6.3 — Information security awareness, education and training Awareness culture maps directly to ISO 27001 awareness and training expectations.
A.5.24 — Information security incident management planning and preparation Practice and dry runs support incident readiness and shared response behavior.
Recommendation — Implement awareness, education, and training that fit organisational risks. Prepare and rehearse incident handling so people know what to do when events occur.

Practitioner Guidance

What to prioritise: focus first on the moments where staff make security decisions under pressure, such as reporting suspicious messages, approving access, handling sensitive data, and escalating anomalies. Those are the places where awareness most directly affects outcomes.

What to verify: check whether people can actually explain the reporting path, recognise the organisation’s escalation thresholds, and use the secure workflow without help. If they cannot do that in practice, the programme is informational but not operational.

What good looks like: the organisation sees early reporting, fewer repeated mistakes, and less reliance on blame after incidents. The best signal is not perfect compliance, but consistent, confident action when something abnormal appears.

Practitioner takeaway: build awareness as a repeatable operating habit, because culture changes when secure behavior is practiced, reinforced, and supported by controls that people can realistically use.