The Lab

Your team completed the training. Did their behaviour change?

Frank De Pasquale ·

Every year the reminder goes out, staff work through the modules, and the completion report comes back at or near 100 per cent. On paper the business is covered. The training was assigned, it was finished, and there is a certificate to show an auditor or an insurer if either of them asks.

So it is worth asking what that number actually tells you. It tells you people attended. What it leaves open is whether anyone would behave differently the next time a well made lure lands in their inbox, and that is where most programs quietly come undone. The human element is still involved in 62 per cent of breaches (Verizon 2026 DBIR), after a decade in which training completion has been close to universal. The figure that moves is attendance. The figure that matters has barely shifted.

Completion is not competence

A finished module proves someone sat through it, in the same way a watched safety video proves someone pressed play. Competence is whether they slow down and check when an email asks them to move money or reset a password under time pressure. Those are different things, and only one of them shows up on a compliance dashboard. In my experience the programs that struggle are rarely the ones with the wrong platform. They are the ones that chose a platform on compliance criteria, assigned the content, and then left it to run itself, when the thing they had bought was a behaviour-change effort.

A program, not a product

Awareness training is usually bought as a product, a library of modules with an Australian accent and a phishing button bolted on, and then treated as done once it is deployed. Our own testing across the category found that roughly two thirds of the platforms are capable of changing behaviour, while only about one program in thirteen actually manages it (Tekspace product research). That is not a product gap. It is the distance between owning a tool and running a program, and it is almost entirely an implementation problem: who chose it, on what basis, and whether anyone treats the first six months as organisational change, which is what it is.

We publish Frank's read on each market to the Lab as we test it. Get it in your inbox →

Measure behaviour, and make reporting easy

The way through this starts with measuring the right thing, which is behaviour under pressure, ideally reduced to a single number a board can act on and watch move over the year. A specialised security awareness layer does two things a completion report cannot. It calibrates the training to each person's real risk, and it makes reporting a suspicious email the easy, rewarded thing to do, so the signal reaches you early. The program exists to protect the user; one that treats staff as the problem to catch out produces shame, and shame produces silence, which is the failure mode that defeats the whole effort.

See it in your own environment

You do not have to take any of this on faith. The honest place to start is a baseline: a read of how your people behave today, before any platform decision, usually a short simulation and a look at your current reporting rate across a small group. Most leaders are surprised by what comes back. Once the baseline is in front of you, deciding what to change becomes a concrete conversation with the evidence attached. If that is useful, we start with a short assessment.

See the security awareness analysis

Sources

1. Verizon 2026 Data Breach Investigations Report — the human element was involved in 62% of analysed breaches (global; 2026 edition) 2. Tekspace product research — across the security awareness platforms we road tested, around two thirds are capable of driving behaviour change, while roughly 7.5% of programs achieve it in practice; an implementation gap, not a product gap