Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What should security leaders do when awareness efforts…
Governance, Ownership & Risk

What should security leaders do when awareness efforts are creating resistance instead of improvement?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 27, 2026 Domain: Governance, Ownership & Risk

Reframe the programme around education, relevance, and shared benefit. Use opt in experiences where possible, explain why the content matters, and show people how to protect themselves as well as the organisation. Reuse strong material instead of rebuilding everything, and connect awareness to communications, threat updates, and crisis messaging. That makes security feel useful, not punitive.

Why resistance is often a design problem, not an audience problem

When awareness creates resistance, the usual failure is that the programme is trying to force behaviour change through obligation instead of relevance. People disengage when content feels generic, repetitive, or disconnected from what they actually do, especially if it reads like policy enforcement rather than practical help.

The fix is to treat awareness as a service: explain the risk in the context of the work, show the personal benefit as well as the organisational benefit, and give people a reason to care before asking them to act. That shifts the experience from compliance pressure to usable guidance.

For security leaders, the key judgement is that resistance is a signal about trust, timing, and usefulness. If the material does not help someone make a better decision in their role, the programme is asking for attention without earning it.

How to redesign awareness so it lands

Start with the highest-friction topics and rewrite them around concrete situations people actually face, rather than abstract rules. Short, timely, role-aware messages usually outperform large generic campaigns because they are easier to absorb and easier to remember.

Where possible, use opt-in or self-serve experiences for deeper learning and reserve mandatory delivery for the minimum content needed to meet policy, legal, or operational requirements. That reduces the feeling of coercion while still letting motivated staff go further when they want to.

Reuse strong material instead of rebuilding everything from scratch. Good awareness programmes borrow from incident lessons, threat updates, and crisis messaging so the message stays current and credible, not stale and ceremonial.

It also helps to connect awareness to everyday protection, not just enterprise risk. If people can see how a control helps them avoid account compromise, fraud, or time loss, the programme starts to feel useful rather than punitive.

What “better” looks like in practice

Better awareness is measurable in behaviour and reception, not in the number of slides delivered. Look for fewer avoidance signals, better completion quality, improved reporting, and more people using the guidance when they face an actual decision.

It also shows up in how the organisation talks about security. When awareness is working, communications, incident response, and employee education reinforce one another instead of sounding like separate functions with different messages.

Security leaders should be careful not to over-rotate toward novelty. The goal is not to make awareness entertaining for its own sake, but to make it relevant enough that people will act on it when it matters.

Risk and Threat Considerations

Resistance is not just a communications issue. If awareness is poorly targeted or framed as punishment, people may ignore real warnings, delay reporting, or treat security as noise, which increases exposure during phishing, social engineering, and incident escalation.

Failure mechanism: Generic or coercive messaging reduces credibility, so the audience stops distinguishing urgent guidance from routine corporate messaging. That weakens both preventative behaviour and response speed when a real threat appears.

Impact: The organisation gets lower engagement, weaker reporting discipline, and less effective crisis communication, which can turn a solvable security issue into a broader operational and reputational problem.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OC-03 — Cybersecurity Supply Chain Risk ManagementAwareness works better when tied to organisational communication and risk context.
PR.AT-01 — Cybersecurity Awareness and TrainingThe subject is directly about making awareness and training more effective.
RS.CO-02 — Incidents are reported consistent with criteriaConnecting awareness to incident and crisis messaging supports better reporting behaviour.
Recommendation — Align awareness messages with enterprise risk communications and stakeholder needs. Tailor awareness content to role, context, and practical action. Use awareness to improve timely reporting and escalation of suspicious activity.
ISO/IEC 27001:2022A.6.3 — Information security awareness, education and trainingThe question concerns redesigning awareness so it changes behaviour instead of triggering resistance.
Recommendation — Design awareness activities around relevance, role, and measurable behaviour change.
CIS Controls v8CIS-14 — Security Awareness and Skills TrainingThe issue is the effectiveness and reception of awareness training.
Recommendation — Deliver role-based awareness that people can apply in real situations.

Practitioner Guidance

What to prioritise: Focus first on the few moments where awareness changes a decision, for example before credential entry, when a suspicious message arrives, or when staff need to escalate a concern. If the programme cannot change a decision, it is probably too abstract.

What to verify: Check whether each campaign has a clear audience, a clear action, and a clear benefit to the recipient. If you cannot explain why a person should care in one sentence, the message is likely too generic to work.

Common mistake: Treating low engagement as apathy. In many cases it reflects overproduction of content, poor timing, or a message that protects the organisation rhetorically but does not help the individual in the moment.

Practitioner takeaway: The most effective awareness programmes reduce resistance by earning attention, not demanding it, which means relevance and practical value matter more than volume.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 27, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org