Security awareness training teaches employees to recognise threats. A security behaviour and culture programme takes that knowledge as a starting point, then uses data, reinforcement and cultural change to shift how people actually behave at work. Awareness is one component of the wider programme but success moves from measuring course completion to measuring demonstrable behaviour change.
For the best part of two decades, the standard answer to human cyber risk has been training. Buy a library of modules, assign them to the workforce, chase the stragglers and file the completion report for the auditor. It was a reasonable approach when the alternative was nothing at all and it produced a genuine improvement on the years when staff received no guidance whatsoever.
That model is now under pressure and boards are asking harder questions, insurers want evidence rather than assurances and security teams have noticed something uncomfortable: A workforce can be fully trained on paper and still click on the first convincing invoice fraud that lands in their inbox. The industry response has a name and Gartner has given it a label that is quickly becoming the standard term. A security behaviour and culture programme, or SBCP, is the discipline of changing what people do rather than simply telling them what they should know.
This guide sets out what separates the two approaches, what is genuinely changing and what the shift means for the training programme you are already running.
What is security awareness training?
Security awareness training is structured education that helps employees recognise and respond to the threats they are likely to encounter. A typical programme covers phishing and social engineering, password hygiene and multi factor authentication, safe data handling, device and remote working security, physical security and the process for reporting something suspicious.
Most organisations deliver it as a library of short modules, assigned either annually or in a quarterly cycle, often supported by phishing simulations that test whether the message has landed. In the UK, well built programmes follow NCSC guidance, which has moved a long way from the old model of long annual sessions and now emphasises a little and often delivery, plain language and a blame free reporting culture.
Done properly, this works and our own analysis of more than 400,000 platform users found that untrained users are 8.8 times more likely to click a phishing email than trained users. That is not a marginal difference but closer to an order of magnitude and it is the strongest available argument that education changes outcomes.
The problem is not that awareness training fails but that awareness training on its own is measured in a way that tells you almost nothing about whether it worked. A completion rate of 98% describes an administrative achievement, not describe a reduction in risk.
What is a security behaviour and culture programme?
Gartner defines a security behaviour and culture programme as an enterprise wide approach to minimising cyber security incidents associated with employee behaviour. The important word in that definition is behaviour. An SBCP is not a content library, but a co-ordinated programme that sets out to change specific, observable actions across an organisation, which then measures whether those actions have changed.
Gartner structures the approach around a framework called PIPE, which stands for practices, influences, platforms and enablers:
- Practices covers the security controls and processes people interact with.
- Influences covers the behavioural science, the nudges and the social proof that shape decisions.
- Platforms covers the technology used to deliver and measure the programme.
- Enablers covers the people, from executive sponsors to departmental champions, who carry it forward.
Two numbers explain why this has moved so quickly from analyst language into procurement conversations. Gartner expects that by 2027, half of all large enterprise Chief Information Security Officers (CISOs) will have adopted human centric security design practices, prioritising behavioural transformation over awareness. Yet as of 2025, only around 13% of organisations had a fully operational programme of this kind. The direction of travel is settled and most organisations simply have not made the move yet.
What is actually changing?
Strip away the terminology and three practical shifts sit underneath the change.
The first is a shift from knowledge to behaviour. It is entirely possible for someone to score full marks on a phishing module in March and forward a fraudulent payment request in April. Knowing and doing are different problems and they respond to different interventions. Knowledge responds to teaching and behaviour responds to friction, feedback, habit and social norms.
The second is a shift from campaign to continuum and the annual training push creates a spike of attention that then decays within weeks. A behaviour programme runs continuously, delivering small interventions at the point of risk rather than one large intervention at the point of compliance deadlines.
The third is a shift from compliance evidence to risk evidence. The question a board now asks is not whether everyone completed the training, but whether the organisation is measurably harder to compromise than it was six months ago and what proof exists for that claim.
Why are completion rates no longer enough?
Completion rates are popular because they are easy to collect and comfortable to report, they are also almost entirely disconnected from risk. A completion rate rises when people click through slides but it does not fall when someone reuses a password across three systems. It also does not rise when the finance team starts verifying payment changes by phone. Real behavioural changes that are not measured within a percentage that rises and falls.
The exposure is real and Verizon's Data Breach Investigations Report has found for several years running that a substantial majority of breaches involve a human element, whether that is error, misuse, stolen credentials or social engineering. Roughly two thirds of incidents trace back to something a person did or failed to do. If that is where the risk sits, that is where the measurement needs to sit too.
A behaviour led programme replaces the completion metric with indicators that actually move: Phishing simulation click rates tracked over time, the proportion of employees who report a suspicious message rather than deleting it, the speed of that reporting, repeat clicker trends by department and the rate at which risky behaviours such as credential reuse are being designed out. These are covered in more depth in our guidance on cyber security awareness training and how to measure it.
Does an SBCP replace security awareness training?
No and this is where a lot of the current commentary overreaches. Awareness training is a component of a security behaviour and culture programme, not a rival to it. You cannot ask people to behave differently if nobody has told them what good looks like. Education remains the foundation.
What changes is the role education plays. In the old model, training was the whole programme, but in the new model, training is one of four connected stages. At Boxphish we describe those stages as assess, educate, reinforce and measure. You assess the current level of risk across the organisation, educate people with focused and relevant content, reinforce that learning with simulations and timely nudges, then measure whether behaviours have changed. The loop then repeats with the findings feeding the next assessment.
Read that way, an SBCP is not a repudiation of awareness training, it is what awareness training grows into once you start taking measurement seriously.
How do awareness training and an SBCP compare?
| Dimension | Security awareness training | Security behaviour and culture programme |
|---|---|---|
| Primary goal | Build knowledge and meet compliance obligations | Change specific, observable behaviours |
| Cadence | Annual or quarterly assignment | Continuous, with interventions at the point of risk |
| Core metric | Completion rate and quiz score | Click rate, report rate, repeat clicker trend, time to report |
| Scope | Owned by the security or compliance team | Enterprise wide, with departmental ownership |
| Evidence produced | Attendance records for the auditor | Risk trend data for the board and insurer |
| View of the employee | A risk to be mitigated | A control that can be strengthened |
Programmes that treat staff as a vulnerability tend to produce fear and fear produces silence. Programmes that treat staff as an active layer of defence tend to produce reporting and reporting is what shortens the time between a phishing email landing and the security team knowing about it.
What does an effective programme look like in practice?
Before any content is assigned, run a simulation and a short risk assessment so you know where the organisation actually stands by department, by seniority and by role, this is your baseline. Finance, HR and executive assistants carry a different threat profile from the warehouse floor and a single blanket programme will over serve one group and under serve the other.
Then segment the education into short, relevant modules delivered to the people who need them. Statistics suggest this method is far more valuable than a universal annual course by a wide margin, both in engagement and in outcome. Our guidance on cyber security training for employees covers how to build that segmentation without creating an administrative burden.
Reinforce continuously through simulated phishing. Phishing is the most direct reinforcement tool available, provided it is run to teach rather than to catch people out. Pair every simulated click with an immediate, short, non-punitive learning moment and make the report button as easy to reach as the delete key. Where a technical control can remove a risky behaviour altogether you should use it, because a behaviour you have designed out never needs to be trained.
Finally, measure and report in the language the board uses. Trend lines beat snapshot and a chart showing click rate falling from 22% to 6% across three quarters while reporting rate climbs from 9% to 41% is a business case, an insurance conversation and a board update in a single image.
How do you begin the shift?
Most organisations do not need to tear anything down. The training library you have is an asset and what is usually missing is the measurement layer and the reinforcement rhythm around it.
A sensible first quarter looks like this:
- Establish your baseline click and report rates - Pick three behaviours you actually want to change, such as reporting suspicious emails, verifying payment detail changes and using the password manager for every credential.
- Define what success looks like for each one in numbers.
- Run a continuous simulation and micro-learning cycle against those three behaviours.
- Report the trend at the end of the quarter, then choose the next three.
Three behaviours changed properly is worth considerably more than thirty topics covered superficially. It also gives you something the completion report never could, which is evidence that the programme is working.
Frequently asked questions
Is a security behaviour and culture programme the same as human risk management?
They overlap heavily and are often used interchangeably. Human risk management focuses on identifying and quantifying the risk each individual or group presents. A security behaviour and culture programme covers that measurement but places more weight on the cultural and behavioural interventions used to reduce it. Our human risk management guidance explains how the two fit together.
Do we still need annual training for compliance?
In most regulated environments, yes. Cyber Essentials, ISO 27001 and sector specific requirements still expect documented training. A behaviour programme satisfies those obligations comfortably, because it produces both the completion evidence and the outcome evidence. You are adding to the compliance record rather than replacing it.
How long does it take to see behaviour change?
Click rates usually respond within one to two simulation cycles, so within roughly eight to twelve weeks. Reporting rates take longer because they depend on trust as much as knowledge, and typically move over two to three quarters. Cultural change, meaning the point at which colleagues correct each other without prompting, is a matter of years rather than months.
Will simulated phishing damage trust with employees?
Only if it is run punitively. Simulations that name and shame, or that are used as a disciplinary trigger, reliably suppress reporting and make the organisation less safe. Simulations that are announced as part of a training programme, followed immediately by short constructive feedback and reported at team level rather than individual level, tend to build trust rather than erode it.
Who should own the programme?
Security should own the design and the data, but the programme needs named owners in each function to succeed. Gartner's enablers concept exists precisely because a programme run entirely from the security team rarely achieves enterprise wide behaviour change. Executive sponsorship and departmental champions are what carry it into the day to day.
Where to go next
If you are running a mature awareness programme and want to know whether it is working, the fastest route is to measure what your people do rather than what they have completed. Boxphish combines training content aligned to NCSC guidance with continuous simulation and behaviour reporting, so the assess, educate, reinforce and measure loop runs in one place. Book a demo to see the reporting your board is asking for.


