
The Wrong Goal
One of the biggest mistakes in cybersecurity awareness and human risk management is assuming the best way to reduce risk is to make every employee care deeply about security.
It's not.
The goal is not to create more security enthusiasts, it's to make secure behavior more likely. Those are not the same thing.
It is far easier to influence habits than opinions, and habits are how strong cybersecurity cultures are built. The people responsible for building and maintaining that culture usually do care deeply. They think about risk every day. They understand the consequences of a bad click, a rushed login, or a moment of misplaced trust.
Most employees do not live in that world. They have their own priorities, pressures, and areas of expertise, whether that is sales, design, development, operations, or something else entirely. They are not thinking like security professionals, and they shouldn't need to. What they do need are clear, repeatable behaviors that help them make better decisions when risk shows up without needing to become experts themselves.
"It is far easier to influence habits than opinions"
Prevention Works Through Repetition
You would not expect everyone in your office to be a dentist, but you do expect them to brush their teeth. That is how most prevention works in real life. It's not built on passion. It's built on habit.
Most people do not wake up excited about flossing, sunscreen, seatbelts, or locking their doors. They do those things because the behavior is simple, familiar, and reinforced over time. In most areas of life, prevention is a pattern, not a passion. Human risk in cybersecurity should be approached the same way.

"...behavior is simple, familiar, and reinforced over time."
Actions Are What Matter
Too many security programs are still built around the idea that if employees just understood the risks more, cared more, or paid more attention, better outcomes would follow. But knowledge and concern do not automatically translate into behavior. People can agree with the message, support the goal, and still fail in the moment because agreement is not the same as practice, and awareness is not the same as instinct.

That is why behavior matters more than buy-in. If you want to reduce human risk, focus less on trying to turn employees into security advocates and more on helping them build better instincts. Put realistic situations in front of them. Use security awareness training that reinforces the right behavior in context. Make the safer action easier to recognize and repeat.
Recent events only reinforce the point. Verizon's 2025 DBIR (https://www.verizon.com/business/resources/reports/dbir/) found that the human element was involved in about 60% of breaches, while Proofpoint reported that malicious emails now use URLs 4 times more often than attachments and that at least 55% of suspected smishing messages contain malicious URLs. Attackers are evolving how they influence behavior across channels, which makes realistic practice and habit formation more important than ever.
"awareness is not the same as instinct"
Conclusion
When the moment comes, people are not making decisions based on what they were told to care about. They are acting from habit.
In the end, the job is not to make every employee care about cybersecurity the way the security team does. The job is to make secure behavior as routine as brushing your teeth.



