Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Security culture programs and training fatigue: what teams should do


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18004
Topic starter  

TL;DR: Security culture programs break down when training, phishing simulations, and champion workflows stop feeling relevant to employees, according to Escape’s recap of Marisa Fagan’s discussion. The lesson is that culture succeeds through tailored programmes, clear metrics, and practical enablement, not one-size-fits-all awareness theatre.

NHIMG editorial — based on content published by Escape: the Elephant in AppSec recap on security culture programmes

Questions worth separating out

Q: How should security teams design culture programmes that people actually use?

A: Start by mapping each initiative to a specific audience and workflow.

Q: Why do completion rates fail as audit evidence for security awareness programmes?

A: Completion rates measure participation, not security outcome.

Q: How can organisations tell whether their security culture is actually working?

A: Look for practical signals such as quick self-reporting, low blame in incident follow-up, strong participation in drills, and consistent use of verification steps.

Practitioner guidance

  • Segment programmes by audience and workflow Separate employee awareness, developer security practices, and tactical response activities into different programme lanes so the content matches the job being done.
  • Assign a dedicated programme owner Name one accountable owner for security culture who can coordinate across security, product, and business teams, and make sure that person can reach leadership without bottlenecks.
  • Measure behaviour, not just attendance Track whether training is completed, whether workflows are closed on time, and whether the supporting tools are actually used.

What's in the full article

Escape's full recap covers the conversational detail this post intentionally leaves for the source:

  • The original podcast discussion with Marisa Fagan on security champions and programme ownership.
  • Direct examples of how the quadrant model maps to different culture programme types.
  • The five-whys approach to rebooting a failed programme and why relevance matters.
  • Additional commentary on zero trust messaging and employee adoption.

👉 Read Escape's recap of security culture programmes, metrics, and rebooting failed training →

Security culture programs and training fatigue: what teams should do?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 17593
 

Security culture is an access-control problem in disguise: if people cannot see why a workflow matters, they will route around it. That same failure mode appears in IAM, PAM, and NHI governance when approval steps, reviews, or training feel detached from operational reality. The control may exist, but the human system around it does not reinforce use. Practitioners should treat relevance as a control requirement, not a communication nice-to-have.

A question worth separating out:

Q: What should teams do when a security culture programme stops gaining traction?

A: Run a retrospective and ask why the programme failed to resonate before adding more content. The likely fixes are narrower scope, a clearer business case, stronger ownership, or a better delivery model. Restarting without understanding the reason for disengagement usually repeats the same problem.

👉 Read our full editorial: Security culture programs fail when training content stops feeling relevant



   
ReplyQuote
Share: