All Posts

Best Practices

7 min read

 read

Building a security culture: from awareness to behavior change

Technology alone does not protect a company. Learn how to build a security culture that turns your people into your strongest line of defense.

Jan Zeppernick - Amitego CEO

Jan Zeppernick

Management

Published

15 Mar 2026

Aktualisiert

29 Sep 2026

Introduction

You can deploy the most sophisticated security technology in the world, and a single employee who clicks a phishing link can undo all of it. The human factor remains the weakest link in cybersecurity, and at the same time the most neglected. Building a genuine security culture is the only sustainable solution.

Key Takeaways

  • Annual training is not enough. Continuous micro-learning drives lasting behavior change.
  • Simulated phishing is the most effective way to bring click rates down.
  • Psychological safety encourages employees to report incidents without fear.
  • The behavior of leadership is by far the strongest indicator of a healthy security culture.

Why annual security training is not enough

The tick-the-box approach to security awareness, a 30-minute annual training video followed by a quiz, has proven largely ineffective. Employees forget what they learned within a few weeks, and the training rarely connects security topics to the real situations employees actually face.

There is a timing problem on top of that. Training delivered in March does little against a well-crafted phishing wave in October. What protects people is not the knowledge itself but attention at the decisive moment, and attention only holds up through repetition at short intervals.

Four cards showing the pillars of a security culture: continuous microlearning, simulated phishing attacks, psychological safety when reporting mistakes, and leadership setting the example
4 pillars of a strong security culture

The building blocks of a strong security culture

  • Continuous micro-learning: Short, frequent learning sessions are far more effective than annual marathon sessions. Two minutes a month beats thirty minutes a year, because it keeps the topic present.
  • Simulated phishing: Regular, realistic phishing simulations drive genuine behavior change, provided they do not end in humiliation. Anyone embarrassed for clicking will not report the next incident.
  • Psychological safety: Employees need to feel safe reporting incidents without fear of punishment. The time between click and report is the single most important number in incident handling.
  • Leadership by example: Security culture starts at the top. When leadership takes security seriously, employees follow. Conversely, one exemption granted to the executive team devalues every policy beneath it.

Where training stops and privileged accounts begin

Security culture lowers the probability of a mistake; it does not eliminate it. That is exactly why the damage has to stay contained when the mistake happens anyway. A click on a phishing link is inconsequential as long as the affected account holds no far-reaching rights.

This is where culture and technology meet: where no permanent admin rights exist, a successful phishing attack runs into nothing. Zero standing privileges and least privilege are therefore part of an awareness strategy, not only of the infrastructure.

Measuring security culture

What gets measured gets managed. Four metrics have proven useful:

  • Phishing click rate: the obvious number, but weak on its own.
  • Reporting rate: how many employees actively report a suspicious email? A rising reporting rate is a better signal than a falling click rate.
  • Time to first report: it decides whether a response is possible at all before damage occurs.
  • Patch compliance: an indirect but reliable gauge of how seriously security is taken day to day.

Celebrate progress publicly and use the data to identify teams or departments that need extra support, not to sanction individuals.

External service providers count too

Awareness programs usually stop at the company boundary. Attacks do not. When a provider with remote access to your systems falls for a phishing email, it is your incident, regardless of whose inbox the message landed in.

In practice that means provider access needs the same technical limits and logging as internal access. NIS-2 frames this as supply chain security and makes it an obligation in its own right.

The three most common mistakes

First, awareness gets treated as a project rather than an ongoing operation, with one campaign a year and silence in between. Second, simulations become fault-finding rather than learning aids, which reliably drives the reporting rate down. Third, the metrics measure participation rather than behavior: a 100 percent completion rate says nothing about whether anyone picks up the phone when it counts.

Contact

Your Direct Path to Secure Remote Access

Speak directly with a cybersecurity expert.

Personal Meeting
Personal Meeting
Personal Meeting

Conclusion

Technology is your last line of defense, not your first. Companies that invest in a genuine security culture, where every employee understands their role and feels empowered to act, are far more resilient than those that rely on tools alone.

Jan Zeppernick - Amitego CEO

Jan Zeppernick

Management

Jan has over 12 years of consulting experience at PwC and Ernst & Young, focusing on information security and compliance for critical infrastructure and the automotive industry. As a certified ISO 27001 Lead Auditor and strategy expert, he advises organizations on establishing and auditing security management systems in accordance with ISO 27001 and TISAX.