Because awareness alone does not change behaviour. Many users understand that a risky action could harm them, but still proceed due to convenience, habit, or low perceived immediate consequence. Effective programmes treat this as a behaviour change problem, not a knowledge problem, and focus on relevance, reinforcement, and removing the friction that drives unsafe shortcuts.
Why awareness does not stop risky behaviour
Knowing a control is risky rarely overrides the incentives and habits around the moment of action. People usually weigh immediate convenience, speed, and routine more heavily than an abstract future loss, especially when the downside feels unlikely, delayed, or shared by the organisation rather than the individual.
This is why awareness campaigns often fail when they only repeat the hazard. The underlying problem is not ignorance, it is that the environment still makes the unsafe option the easiest one, and the user has not been given a strong enough reason to slow down or choose differently.
What actually drives the shortcut decision
Risky actions tend to persist when the safe path is slower, harder to remember, or interrupts the work flow. Habit and friction matter: if the risky choice is the default, repeatedly available, and socially tolerated, many employees will keep taking it even after they can explain the risk in a training session.
Perceived immediacy also matters. A person may understand that a mistake can cause harm, but still treat the chance of being affected as remote. That gap between abstract awareness and immediate personal consequence is where unsafe behaviour survives, especially when the task feels routine or urgent.
Organisations also create mixed signals when they ask for speed, responsiveness, and flexibility while expecting perfect caution. When the unsafe shortcut helps someone finish work, awareness has to compete with operational pressure, not just with knowledge. That is why behaviour change usually depends on design, reinforcement, and supervision, not training alone.
How to change the behaviour instead of repeating the warning
The most effective response is to make the safe action easier than the risky one. That can mean reducing friction, changing defaults, adding just-in-time prompts, or removing workarounds that people rely on to get the job done quickly. If the control only works when users remember and care at the exact right moment, it will be bypassed.
Reinforcement matters because people learn from what gets rewarded, ignored, or punished in real work. When managers tolerate unsafe shortcuts as long as output is delivered, the organisation is signalling that the risk is acceptable in practice. A better approach is to pair clear consequences with practical alternatives that do not slow the business to a crawl.
Measuring success should focus on behaviour, not just completion of awareness content. Look for changes in observed shortcuts, exception rates, repeated policy violations, and whether the safer path is actually being used under time pressure. If the unsafe action still feels faster, the programme has not changed the decision environment enough.
Risk and Threat Considerations
When risky behaviour becomes normal, the organisation gets a false sense of control. The danger is not only accidental error, but also the fact that predictable human shortcuts create repeatable exposure that an attacker, insider, or opportunistic failure can exploit.
Failure mechanism: the unsafe action remains the lowest-friction path, so users keep choosing it despite understanding the risk, and the control fails at the moment the behaviour must change.
Impact: repeated exceptions erode policy credibility, widen the blast radius of routine mistakes, and make it easier for malicious activity to blend into normal work patterns.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 provides the primary governance reference for this topic.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AT-01 — Awareness and Training | Behaviour change still depends on security awareness and training. |
| PR.AT-02 — Role-Based Training | Different job roles face different risky shortcuts and pressures. | |
| GV.OC-01 — Organizational Context | Unsafe shortcuts often persist when work goals and incentives conflict with caution. | |
| Recommendation — Reinforce risky-action scenarios and safe choices in role-relevant training. Tailor training to the decisions and shortcuts each role actually encounters. Align security expectations with the operating realities of the work environment. | ||
Practitioner Guidance
What to prioritise: treat the behaviour you want to stop as a workflow problem first. If the safe option is not the easiest option, awareness will have limited effect no matter how well the message is delivered.
What to verify: test the actual decision path under time pressure, including whether people can complete the task without a workaround. If users can explain the risk yet still cannot perform the safe action quickly, the control design needs adjustment rather than more messaging.
Decision rule: if the same risky shortcut keeps recurring, stop assuming it is a knowledge gap and investigate whether the process, incentives, or default tooling are rewarding the wrong behaviour.
Practitioner takeaway: awareness is necessary, but behaviour changes only when the safe choice is obvious, available, and easier to defend in the moment than the risky shortcut.
Related resources from NHI Mgmt Group
- Why do passwords still persist even when organisations know they are risky?
- Why do developers ignore security tools even when they know a risk is real?
- Why do risky security behaviors persist even when employees know the rules?
- Why do AI-driven impersonation attacks increase fraud risk even when users believe they know the requester?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 25, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org