Cyber security has never been more advanced. Detection tools are faster, response times are tighter, and most organisations now have a far stronger technical security posture than they did just a few years ago.
Yet despite all this progress, the same issue continues to sit at the centre of most security incidents. People.
The majority of breaches still involve a human element. Whether it’s clicking a malicious link, sharing credentials or simply making the wrong judgement call at the wrong moment. End users remain the most consistent point of entry for attackers.
The reality is simple. No matter how good your technology is, if your users are not prepared, you are still exposed. That is why cyber training isn’t just a compliance exercise. It is fundamental.
The challenge: Training without impact
Most organisations already have cyber awareness programmes in place. Annual modules are completed, phishing simulations are sent out, and policies are signed off. On paper, it looks robust. In practice, it often falls short.
Users quickly learn how to pass training rather than engage with it. They begin to recognise patterns in simulated phishing emails and click through modules to complete them as quickly as possible. Over time, the whole process becomes something to get through rather than something to learn from.
This creates a false sense of assurance. Completion rates go up, but real-world behaviour does not always follow. In some cases, repeated simulations can even reinforce the wrong behaviours. Users begin to expect that threats will look a certain way, which can lead to overconfidence when faced with something more sophisticated. If phishing tests become too standardised or predictable, bad actors can account for those patterns when creating their own campaigns.
The risk here is subtle but significant. Training becomes familiar, but threats continue to evolve, often in ways that take those training patterns into account.
Getting back to basics
Effective cyber awareness does not come from more content. It comes from better habits. The most impactful programmes focus on a small number of core behaviours and reinforce them consistently:
- Slow down before acting
- Question anything unexpected
- Verify requests through trusted channels
- Understand context rather than relying on patterns
- Change platform – maybe make a phone call or send a message via a different compliant internal platform.
These are simple principles, but they are what make the difference.
At Lanware, training is not treated as a one-off activity. It is delivered as an ongoing programme, with regular refreshers, evolving content and continuous reinforcement. The aim is to embed security into everyday behaviour, rather than rely on a once-a-year exercise.
When this is done properly, users stop being a risk to manage and start becoming a line of defence.
Gamification: Engagement vs behaviour
To address engagement challenges, many organisations have introduced gamification into their training programmes. Points, leaderboards and simulated challenges can increase participation, giving users a reason to engage and making training feel less like a chore. There is real value in this approach. When done well, it can improve engagement and help users retain key concepts, particularly when scenarios are realistic and relevant. But there is a limit.
Gamification can sometimes shift the focus away from learning and towards performance. Users start aiming to score highly or avoid being caught out, rather than genuinely developing judgement and awareness. Over time, they may learn how to beat the system rather than how to recognise genuine risk.
There is also a cultural consideration. If training feels like a trap or a test designed to catch people out, it can create frustration rather than confidence. Gamification is a useful tool, but it should support behaviour change, not replace it. There is a big difference between meaningful engagement and trivialisation.
If users begin to treat phishing simulations as something to win or avoid, rather than a learning opportunity, the effectiveness of the programme drops quickly. In some cases, overly complex or punitive approaches can even reduce trust between users and IT teams. This matters, as cyber security is most effective when users feel comfortable reporting issues, asking questions, and escalating concerns. If they feel they are being tested or judged, they are far less likely to do so.
The best programmes focus on building confidence. They create an environment where users feel supported in making decisions, not afraid of getting them wrong.
The role of AI: Raising the bar
AI is already changing the landscape, and it cuts both ways.
On the threat side, attackers are using AI to produce more convincing phishing emails, better targeted messages and increasingly sophisticated social engineering. The traditional signs people once relied on are becoming less reliable.
At the same time, AI is improving how training can be delivered. Modern platforms can personalise content based on user behaviour, tailoring training to individual risk levels and learning styles. They can simulate more realistic scenarios and update content dynamically to reflect current threats. This shift, from static, one-size-fits-all training to adaptive, personalised learning, is a significant step forward.
However, AI is not a silver bullet. It enhances training, but it does not replace the need for human judgement. Users still need to think critically and make decisions in real time.
What good looks like
The most effective cyber training programmes share a few common characteristics:
- They are continuous rather than annual
- They are realistic without trying to trick users
- They focus on behaviour, not just knowledge
- They adapt to the individual rather than treating all users the same
When these elements come together, training starts to have a measurable impact.
Users become more aware, more confident, and more capable of making the right decisions when it matters most.
Security starts with People
Cyber threats will continue to evolve, and technology will continue to improve.
But one constant remains. Every attack still needs a way in, and often, that way in is through a person. The goal of cyber training is not to help users pass a test. It is to help them make better decisions in the moments that matter. Get that right, and everything else becomes far more effective.




