A security behaviour and culture programme (SBCP) is an enterprise wide approach to reducing the cyber security risk created by human behaviour. Coined by Gartner, it moves beyond annual awareness training using behavioural science, data and continuous reinforcement to change how people act every day to build a measurable security culture, rather than simply recording who completed a course.
Most organisations have run security awareness training for years, yet people are still at the centre of the majority of cyber breaches. That gap between what staff are told and what they actually do is exactly what a security behaviour and culture programme sets out to close. This guide explains what an SBCP is, why analysts such as Gartner are moving the industry towards it, what should be involved in practice and how to begin building your own programme.
What is a security behaviour and culture programme?
A security behaviour and culture programme is the mature evolution of security awareness training. The term was coined by Gartner and the distinction it draws is simple but important. Where awareness training sets out to tell people the rules, an SBCP sets out to change what they actually do, making the secure choice the easy and expected one across the whole organisation.
In practice that means bringing several things together rather than relying on a single annual course. This type of programme combines role based training, realistic phishing simulations, behavioural nudges, reinforcement tasks and the measurement of real behaviour, rather than course completion. The shift in emphasis is the whole point, so employees stop asking whether everyone finished the training and start asking whether their day to day behaviour has genuinely become more secure because of it.
Why are analysts moving from awareness to behaviour and culture?
For most of the last decade the dominant idea was awareness and to inform people about phishing, password hygiene, safe browsing and the risk level would fall. It helped, but it plateaued, because being aware of these attacks and knowing what to do and doing it under pressure are not the same thing.
Gartner expects behaviour and culture to become the norm and it predicts that by 2027 half of cyber security programmes will prioritise behavioural transformation over awareness, yet today only around 13 percent of organisations have a fully operational SBCP. That combination matters for any organisation weighing up where to invest. The approach is rising quickly, but adoption is still low, so there is a real window to get ahead of the category rather than catch up to it later.
It is worth noting that Gartner uses the US spelling, 'security behavior and culture program'. The meaning is identical but we use the UK spelling throughout for a British audience.
Why is the human layer your biggest cyber risk?
Most breaches start with a person, not a piece of technology and Verizon's 2025 Data Breach Investigations Report found that around 60% of breaches involve a human element, whether that is a mistaken click, a socially engineered phone call or a misdirected email. Attackers focus on people for the straightforward reason that people are easier to fool than firewalls.
The encouraging part is that this risk is measurable and it responds to training. Boxphish analysis of more than 400,000 platform users found that untrained users are 8.8 times more likely to click a phishing email than trained users. A security behaviour and culture programme exists to close that gap permanently, by building habits that hold up during a real attack rather than knowledge that fades within a few weeks.
What does a security behaviour and culture programme include?
An SBCP is best understood as a set of moving parts that reinforce one another, rather than a product you switch on. A mature programme usually includes:
- Role based training: Short modules matched to the threats a person actually faces, so finance teams learn about invoice fraud and executives learn about whaling, instead of everyone sitting the same generic course that might not be relevant to their role or department.
- Realistic phishing simulations: Safe, controlled tests that show how people respond to a genuine lure, then turn each click into an immediate learning moment with tailored training courses following a phishing simulation click.
- Behavioural nudges and reinforcement: Timely prompts, positive recognition and little and often refreshers that keep secure behaviour front of mind between training sessions.
- Measurement of real behaviour: Tracking what people do, such as click rates and reporting rates, rather than how many finished a module.
The common thread running through all four points is reinforcement over time. Behaviour change is not a single event and a programme is designed to keep working long after the initial rollout.
How is an SBCP different from security awareness training and human risk management?
These three terms are often used interchangeably, but they are not the same thing. Security awareness training delivers knowledge, human risk management identifies and scores the riskiest people and a security behaviour and culture programme is the wider discipline that brings these together to add the missing piece, which is sustained behaviour change across the whole workforce.
| Dimension | Security awareness training | Human risk management | Security behaviour and culture programme |
|---|---|---|---|
| Primary focus | Delivering knowledge and meeting compliance | Identifying and scoring risky individuals | Changing behaviour and embedding culture across everyone |
| Measure of success | Course completion rates | Risk scores by user or group | Demonstrable behaviour change, such as falling click rates and rising reporting |
| Cadence | Often annual | Periodic risk review | Continuous, woven into daily work |
| How it feels to staff | A tick box exercise | Something done to them | Supported to make the secure choice the easy one |
Put simply, an SBCP is the umbrella that the other two now sit under. It treats the human layer as something to be managed and improved continuously, with the same rigour applied to technical controls.
What is the Gartner PIPE framework?
Gartner's recommended way to run a security behaviour and culture programme is the PIPE framework, which stands for practices, influences, platforms and enablers. It gives structure to what can otherwise feel like a vague ambition to improve culture.
| PIPE element | What it means for your programme |
|---|---|
| Practices | The specific secure behaviours you want to see, from reporting a suspicious email to verifying a payment request through a second channel. |
| Influences | The levers that shape behaviour, including visible leadership, peer norms and behavioural science techniques such as timely nudges and positive reinforcement. |
| Platforms | The technology that delivers and measures the programme, including training, phishing simulations, in inbox reporting and analytics. |
| Enablers | The organisational support that keeps the programme alive, such as executive sponsorship, budget, clear ownership and meaningful metrics. |
The aim of PIPE is to make secure behaviour a normal part of work rather than an interruption of it.
How do you build and measure an SBCP?
A practical way to run a programme is a continuous four stage cycle of Assess, Educate, Reinforce and Measure, which maps neatly onto the practices and platforms that PIPE calls for.
You begin by assessing where the real risk sits, using phishing simulations and short knowledge checks to set a behavioural baseline. You then educate with short, role based, NCSC-Assured modules that target the gaps that the assessment exposed. You reinforce that learning with regular simulations, nudges and refreshers, which is where awareness matures into genuine habit. Finally you measure behaviour over time, then feed the results back into the next cycle.
Measurement is where an SBCP proves its worth, so the metrics matter. The two headline numbers are the phishing click rate, which should fall and the reporting rate, which should rise. Tracked over time against your baseline, these show whether human risk is genuinely dropping and they give leadership and cyber insurers the evidence they look for. Crucially, none of these measures include module or training completion rates.
Who needs a security behaviour and culture programme?
An SBCP suits any organisation whose people are a primary target, which today means almost all of them. It is especially valuable where staff turnover is high, where regulation is tight or where a single mistake can be costly. Four sectors feel the benefit most clearly:
- Education and Multi Academy Trusts, where large, dispersed staff bases and frequent onboarding make continuous behaviour change essential.
- Healthcare, where sensitive data and high pressure environments raise the stakes of a single click.
- Finance and legal, where payment fraud and business email compromise target specific high value roles.
- Local government and public sector, where broad public facing services and limited security resource make a culture led approach efficient.
Frequently asked questions
What is a security behaviour and culture programme (SBCP)?
It is an enterprise wide approach to reducing the cyber security risk created by human behaviour. An SBCP uses behavioural science, training, phishing simulations and measurement to change how people act and to build a lasting security culture, rather than simply recording course completion.
How is an SBCP different from security awareness training?
Awareness training delivers knowledge and is often measured by completion. An SBCP goes further, using continuous reinforcement and behavioural science to change what people actually do and it measures success by real behaviour change such as falling click rates and rising reporting rates.
Is an SBCP the same as human risk management?
They are closely related but human risk management focuses on identifying and scoring risky individuals, while a security behaviour and culture programme is the wider discipline that brings training, simulations and behaviour change together across the whole workforce.
What is the Gartner PIPE framework?
PIPE stands for practices, influences, platforms and enablers. It is Gartner's framework for running a security behaviour and culture programme, covering the behaviours you want, the levers that shape them, the technology that delivers them and the organisational support that sustains them.
How do you measure a security behaviour and culture programme?
Measure behaviour against a baseline. The headline metrics are the phishing click rate, which should fall and the reporting rate, which should rise. Tracked over time, these show whether risk is genuinely dropping and give leadership and cyber insurers the evidence they look for.
Build your security behaviour and culture programme with Boxphish
See where your organisation stands today. Book a Boxphish demo and start with a baseline phishing simulation. It is the fastest way to find out how many of your people would click and to begin building a security behaviour and culture programme that measurably reduces human risk.


