Skip to content
All posts

6 reasons your behavioural change plan didn't work

Behavioural change plans often fail because organisations focus on activity rather than outcomes, overlook stakeholder engagement or fail to make security relevant to employees. Effective security behaviour change requires clear objectives, collaboration and an understanding of how people actually work.

Behavioural change

Here are six common reasons behavioural change plans fall short, and practical ways to turn those failures into lasting improvements.

1. Failing to engage key stakeholders

You have developed a security awareness campaign, the creative work is complete and everything is ready to launch. Then a senior stakeholder raises concerns about the approach and sends the project back to the drawing board.

The problem is not necessarily the campaign. It is that an influential stakeholder was not engaged early enough.

Understanding who can influence a behavioural change programme is critical. Stakeholders should be identified at the beginning, consulted at appropriate stages and kept informed as the programme develops.

For larger change programmes, stakeholder mapping can help identify levels of influence and interest, uncover potential conflicts and establish who needs to be involved in key decisions.

The lesson: Understand your stakeholders, involve them early and maintain communication throughout the programme.

2. Measuring eLearning completion instead of behaviour change

Your latest eLearning figures arrive and completion rates have fallen. The immediate response might be to increase reminders or introduce incentives to push the numbers back up.

But completion rates only tell you whether employees completed training. They do not tell you whether their behaviour changed.

Instead, organisations should look at outcomes and the metrics that demonstrate whether employees are making more secure decisions. These might include phishing reporting rates, changes in risky behaviours, policy adherence and improvements among higher-risk employee groups.

Low completion rates can still provide useful information. They may indicate that training has become stale, too broad or insufficiently relevant to the audience.

Security training should have clear learning objectives and focus on behaviours employees can apply in their everyday work.

The lesson: Measure outcomes rather than participation. Use the right metrics to understand whether training is producing meaningful behaviour change.

3. Not listening to employees

Imagine a lost USB drive results in a data breach and the organisation responds by banning removable media.

The policy appears straightforward, but a group of employees needs to transfer large, sensitive files to third parties while away from the corporate network. Without an approved alternative, they begin using consumer cloud-sharing services instead.

The security problem has not disappeared. It has simply changed.

Policies and behavioural interventions that do not reflect how employees actually work can create friction and encourage insecure workarounds.

Before introducing new controls or changing expected behaviours, organisations should consult the people affected. Understanding their workflows, pressures and practical requirements makes it easier to develop security policies that employees can realistically follow.

The lesson: Understand real-world working practices before attempting to change them. Effective security behaviours need to work in practice as well as on paper.

4. Delivering training that isn't relevant to the audience

Face-to-face security training has been delivered to a group of higher-risk employees, but the feedback is poor. Employees say the content was too technical, generic or unrelated to their roles.

The problem is relevance.

A one-size-fits-all approach can struggle to engage employees whose responsibilities, knowledge and exposure to cyber risk differ significantly.

Training should reflect the audience's role, risks and working environment. Information from learning and development teams, employee conversations, security incidents and focus groups can all help identify knowledge gaps and shape more relevant training.

The language matters too. Security concepts should be explained clearly and connected to situations employees recognise from their everyday work.

The lesson: Understand the audience before designing the training. Relevant, role-based security awareness is more likely to engage employees and influence behaviour.

5. Failing to support your security champions

Security champions can play an important role in sustaining behavioural change. They provide local support, reinforce security messages and help connect central security teams with employees across the organisation.

But a champions network cannot simply be established and expected to maintain itself.

Falling attendance, declining engagement or inconsistent participation may indicate that champions do not have enough support, clarity or resources.

Choose people who are suited to the role and provide appropriate training from the outset. Give champions clear responsibilities, regular communications, practical resources and visible support from leadership.

Recognition is also important. Acknowledging their contribution and giving champions access to useful security insights can reinforce their value within the organisation and help maintain engagement.

The lesson: Treat security champions as an ongoing programme rather than a one-off initiative. Support, communication and recognition are essential to sustaining the network.

6. Not going deep enough with your metrics

A phishing simulation shows that click rates are falling. That appears to be good news.

Then an employee falls for a sophisticated phishing attack.

The problem is assuming that a click rate tells the whole story.

Anyone can make a mistake and click a convincing phishing message. What happens afterwards can be equally important. Does the employee recognise something is wrong? Do they report the message? Do they know how to report it? Do they enter credentials or disclose sensitive information?

Phishing simulation metrics should therefore look beyond clicks. Organisations can track reporting rates, credential submission, repeat behaviour and how employees respond after interacting with a suspicious message.

Simulations should also reflect the types of attacks different employee groups are likely to encounter. A generic phishing campaign may reveal very little about how a higher-risk group would respond to a targeted and convincing attack.

The lesson: Measure the behaviours that determine risk, not simply the easiest numbers to collect.

Building lasting security behaviour change

These six failures have something important in common: behavioural change cannot be achieved by the security team in isolation.

Successful programmes depend on collaboration between security teams, senior stakeholders, employees, security champions, learning and development teams and other parts of the organisation.

Security also competes with many other organisational priorities. Rather than treating other change programmes as competitors, look for areas where objectives overlap. Initiatives involving HR, safety, compliance or the digital workplace may share similar challenges around communication, engagement and behaviour.

Security culture is part of the wider organisational culture. Lasting change is more likely when security behaviours are integrated into how people already work rather than treated as a separate activity.

Talk to stakeholders. Listen to employees. Support your champions. Measure meaningful outcomes. Most importantly, keep adapting the programme based on what the evidence tells you.

Related pages

Human Risk Platform
Products & Services
 

 

Behavioural Change Plan FAQ

Why do behavioural change plans fail?

Behavioural change plans can fail when objectives are unclear, communications are inconsistent or employees do not understand why new security behaviours matter. Successful programmes need clear goals, relevant messaging and regular reinforcement.

How can organisations improve cyber security behaviour change?

Organisations can improve behaviour change by combining targeted security awareness training with regular communications, practical guidance and measurable objectives. Training should reflect employees’ roles, risks and everyday working environments.

How do you measure security behaviour change?

Security behaviour change can be measured using indicators such as phishing simulation results, training engagement, incident reporting and changes in risky employee behaviours. Tracking these measures over time helps organisations identify where awareness programmes are working and where additional support is needed.

Build lasting security behaviour across your organisation

Turn security awareness into measurable behaviour change with targeted training, insight and consultancy.

Get regular insights and updates