They often assume personalisation means better outcomes by default. In reality, personalisation only helps if it is based on meaningful risk signals such as role, exposure, and prior behaviour. Otherwise, it becomes a cosmetic feature that changes presentation without changing risk.
Why This Matters for Security Teams
Personalised security training is often treated as a simple engagement tactic, but that framing misses the real objective: reducing human-enabled risk in ways that can be measured and defended. If personalisation is driven by superficial attributes such as job title or office location, it can create a false sense of assurance while leaving phishing, credential misuse, and unsafe data handling unchanged. NIST Cybersecurity Framework 2.0 emphasises risk-based governance and continuous improvement, which is the right lens for training programmes that need to prove value rather than popularity. For an overview of that approach, see NIST Cybersecurity Framework 2.0.
The common mistake is to personalise the format instead of the control objective. A short video, a manager-specific example, or a gamified module may improve completion rates, but completion is not the same as reduced exposure. Security teams need to ask whether the content reflects actual threat paths, whether it adapts to observed behaviour, and whether it targets the people who can meaningfully alter risk. In practice, many security teams encounter the limits of personalised training only after a real phishing or credential abuse event has already exposed the gap between engagement metrics and actual resilience.
How It Works in Practice
Effective personalisation starts with defining the risk signals that matter. For most organisations, that means combining role, system access, data sensitivity, prior report behaviour, phishing susceptibility, and business process exposure. Training for a finance approver should differ from training for a developer, but not because one group is “less careful”; it should differ because the attack paths and consequences differ. The goal is to align content with likely decision points, not to build a bespoke curriculum for every person.
Security teams usually get better outcomes when personalisation is operationalised through a small set of controls:
- segment users by risk-relevant attributes, not by vanity categories;
- tie modules to actual incidents, threats, and control failures;
- refresh training when behaviours or responsibilities change;
- measure behaviour change, such as reporting speed or reduced repeat mistakes;
- avoid over-optimising for completion rates or click-through rates.
Behaviour-based adaptation is especially important, but current guidance suggests it should be transparent and proportionate. If organisations use prior click behaviour or simulation results, they should avoid turning training into a punitive scoring system that users game or resent. That is where alignment with broader governance matters, including the NIST Cybersecurity Framework 2.0 and identity-aware controls that limit who can reach sensitive systems in the first place. Training is weakest when it is asked to compensate for poor access design, weak verification, or excessive privilege. These controls tend to break down when training data, access data, and incident data are fragmented across departments because the programme cannot reliably target the highest-risk behaviours.
Common Variations and Edge Cases
Tighter personalisation often increases operational overhead, requiring organisations to balance relevance against privacy, complexity, and maintenance cost. There is no universal standard for this yet, especially when teams want to personalise based on behavioural telemetry or employee risk scoring. That makes governance important: personalisation should be explainable, limited to legitimate security purposes, and reviewed regularly so it does not drift into surveillance.
Some environments need extra caution. In highly regulated sectors, training records may be audited, so content changes need change control and documentation. In distributed or multilingual workforces, over-personalisation can fragment the message and weaken baseline consistency. For contractors, seasonal staff, or third parties, the right answer is often role-based minimum training plus targeted reinforcement, not full customisation. Where AI is used to recommend modules or generate examples, teams should treat output validation as part of the control, because model drift or unsafe generation can distort the message. Useful supporting guidance can be found in OWASP’s work on LLM application risks and CISA’s training and awareness material at Secure Our World.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and MITRE ATLAS address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OC-01 | Personalised training must support risk-based governance and measurable outcomes. |
| OWASP Agentic AI Top 10 | AI-generated training content can misstate threats or reinforce unsafe guidance. | |
| NIST AI RMF | GOVERN | AI-assisted personalisation needs accountability, transparency, and oversight. |
| MITRE ATLAS | AML.TA0001 | Attackers can exploit training gaps, making behavioural realism important. |
Define training objectives from business risk and track whether behaviour changes reduce exposure.