top of page

ARVIND CLEMENTE

Reflection
2

Cybersecurity Awareness Fatigue

When Security Becomes Background Noise

One of the assumptions many organisations make is that more awareness naturally leads to better security. It seems logical. Employees receive regular training, phishing simulations, security reminders and policy updates. The expectation is simple: the more people know, the better decisions they will make.


After many years of working in cybersecurity, I have come to believe that it is not quite that straightforward.


Organisations invest significant effort into awareness programmes, yet employees continue to fall victim to phishing attacks. Not because they are unintelligent. Not because they choose to ignore the risks. More often, it is because security messages have become part of the background noise of everyday work.


A particular incident changed the way I think about awareness. During a phishing investigation, an employee received a convincing email announcing salary increases. It looked genuine, arrived at exactly the right time and contained a QR code. The employee scanned it.


Our monitoring systems detected the activity immediately. The account was secured, passwords were reset and the employee was contacted to explain what had happened. After the discussion, the employee returned to the desk.


A few moments later, the same QR code was scanned again.


At first, the incident seemed almost impossible to believe. But the more I reflected on it, the more I realised the problem was not a lack of knowledge. The employee had received the training. The risks had been explained. The warning was understood. Yet the behaviour did not change.


That experience forced me to rethink what cybersecurity awareness is really trying to achieve. Perhaps the objective is not simply to increase knowledge. Perhaps it is to influence behaviour and there is an important difference.


Human beings quickly become accustomed to repetition. Messages that once captured attention gradually become routine. Eventually, even important warnings compete with hundreds of other emails, meetings and notifications that fill the working day.


Cybercriminals understand this well. They do not simply exploit technology; they exploit moments of distraction, curiosity and urgency. Often, one emotional decision is enough to overcome months of awareness training.


Looking back, I have come to believe that the success of a cybersecurity awareness programme should not be measured by the number of training sessions delivered or phishing simulations completed. It should be measured by whether people behave differently when faced with a real decision. That is a far more difficult challenge.


And it reminds us that cybersecurity is not only about protecting systems. It is about understanding people.

Closing Reflection

Awareness creates knowledge. Behaviour creates resilience.


The real measure of a security culture is not what people remember after the training. It is what they choose to do when nobody reminds them.

— Arvind Clemente

Reflections on Leadership, Technology & Risk
About

These reflections draw on more than 28 years of experience leading technology, cybersecurity and business transformation. Their purpose is not to document events, but to preserve the leadership lessons those experiences revealed.

The views expressed are personal reflections and do not represent the views of any employer, client or organization.

Written from experience. Not from a template.

bottom of page