Board members and IT board members often ask when investing in employee awareness yields more than an additional technical measure. The answer depends on the risks, the existing security and the behaviour you want to influence. You can read what security awareness really means, what threats employees face every day, how you practically build an awareness program, and how you balance the two investments.
What technical measures don't solve for you
A firewall is not a human manager. Systems protect infrastructure; They don't control behaviour. This gap is quickly underestimated, especially in organisations where information security is seen as a purely technical issue and not as an organisational issue.
Specifically: an employee who opens an attachment to a "colleague" bypasses virus scanners as soon as the message creates just enough confidence. Technique can stop a lot, but not every convincing e-mail. A worker must therefore also learn to recognise abnormalities and know how to safely check them. Technology and safe behaviour complement each other.
What security awareness is exactly
Security awareness, or security awareness, is the extent to which employees recognise, understand and act securely on digital risks. It's about knowledge, attitude and behaviour. An annual e-learning can help, but is not enough in itself.
A good awareness program contains five core components: knowledge building on concrete threats, behavioural change through repetition and exercise, practical simulations such as phishing trials, direct feedback after each exercise, and clear reporting procedures so that employees know what to do in case of doubt. Security awareness and technical measures are not competitors. They're complementary. The question is not which one you choose, but in what order and with what emphasis.
The threats that employees face every day
Concrete examples make it clearer what behaviour presents a risk. NCSC research shows that 22% of SME employees click on a link in a generic phishing mail. In the case of phishing simulations that appear to be from an internal sender, that percentage may exceed 40% on initial test. And in 2025, 31% of reported data leaks caused by human error: misaddressed emails, incorrect attachments, login data set on a counterfeit page.
Smaller organisations are also affected by these incidents. Those with high risk exposure often consider themselves too small or too obscure to be targeted: healthcare organisations with sensitive patient data, childcare organisations with limited IT capacity and logistics companies working with many external suppliers and transport partners.
Three scenarios that make the threat recognizable
In a childcare organisation, an employee receives a fake invoice from a "known supplier" with a modified account number. She's paying. Many common technical measures probably would not have prevented this completely without additional process checks, the invoice looked exactly like it always was. Additional guarantees such as a double signature in case of payments or supplier validation may make a difference in such cases.
At a care facility, a nurse taps her login data on a counterfeit portal page she received via email. The attacker will be able to access patient files. At a transport company, a planner clicks on a link in a "failure order" of an unknown client. Ransomware is shutting down the entire schedule. In all three cases, human behaviour was the decisive factor, underlined by the aforementioned fact that 74% of successful attacks have a human component.
From baseline assessment to a security awareness program that actually works
One-time training without follow-up is usually not effective. Studies show that ongoing approaches are evidence of better results. A mandatory module in January, a quiz in December, and nothing in between: that doesn't change any behaviour. One awareness program that works, follows a different rhythm.
Phase 1: Start measuring what's already there
Without a starting point, you don't know if you're improving. An unannounced phishing simulation or a targeted knowledge test provides instant insight into the current risk behaviour of employees. A baseline assessment or Cyber RI&E shows the blind spots, risk groups and priorities. The outcome shall be usable for an executable improvement planning.
Phase 2: training, simulation and repetition in a working rhythm
Start with the board and management. Their involvement also determines whether the programme is given sufficient attention, time and follow-up. A basic training course for all employees followed by monthly phishing simulations and short microlearning modules for repetition. With only annual training, you rarely achieve lasting behaviour change. Role-specific deepening for finance, HR and IT makes the program more relevant and effective than a generic approach for everyone.
Phase 3: anchoring in processes and policies
Security consciousness that is not anchored in processes evaporated. Take it into the onboarding of new employees, link findings to audit results, and discuss progress periodically in board-level reporting. For organisations without internal security capabilities, CISO as a Service of Kynexis Information Security provides a continuous sparring partner at strategic and operational level, so that management and oversight always have steering information without the need for a full-time staff member.
How to measure whether the program is effective
Measuring without purpose results in numbers, no insight. The KPIs that really matter are the phishing click rate before and after simulations, the completion rate of trainings, the level of knowledge measured with targeted quizzes, and the number of reports of suspicious situations by employees themselves. The latter is the most valuable signal: An employee reporting suspicious is a trade agent.
A useful framework is the Kirkpatrick model. Measure not only whether people were following training (level 1: range), but also whether they learned something from it (level 2: knowledge), whether they were acting differently (level 3: behaviour), and whether there are significantly fewer incidents (level 4: result). Organisations that only measure the rounding rate, know if the module is started, not whether something has changed.
Choose tooling that suits your organisation
There are four main categories. E-learning platforms are strong in scalability and progress management: suitable for basic training and compliance, less suitable if you want to measure real behaviour. Phishing simulators show exactly how employees react in a realistic situation; they work best as part of a broader approach, not as a loose measure. Microlearning is suitable for frequent short repetition, but does not replace deeper training. Workshops offer the most interaction and are strongest for custom behaviour change, but scales less good. Combined approaches usually produce better results than one single means. The choice depends on your target group, your budget and the phase of your program.
When the investment is the most profitable
Technology and security awareness require a common priority. An organisation that has no basic security yet, multiple verification, patch management and access management in order, invests in it first. That is the basis for an awareness programme to be able to make the most of it.
Once that base is there, it can invest in security awareness be a cost-effective way of reducing the residual human risk. The reason is simple: technology protects systems, but 74% of the attacks pass through those systems through people. Reducing human risk behaviour directly affects the greatest remaining vulnerability. Audit findings and risk analyses provide the best guidance for this assessment; they shall identify the real vulnerabilities and the order of priority for action.
How Kynexis provides information security support
At Kynexis, a trajectory starts with the current situation and the risks that are relevant to your organisation. I translate the outcome into a feasible improvement planning with clear controllers. A boardroom session can help management and oversight to discuss the choices and priorities together.
The approach is independent and risk-driven. The training should contribute visibly to safer behaviour and provide useful information for evaluation and audits. For organisations in SMEs, care, childcare and the social care and community services without internal security capacity, CISO as a Service offers a structural solution at strategic and operational level.
Beginning tomorrow: a starter checklist
Technical measures and security awareness reinforce each other. Follow the correct order and balance from your risk analysis and existing security. Organisations that take both layers seriously are more structurally resilient than organisations that invest only in technology or only in training.
Use these five steps to start immediately:
- Run a zero reading. Map the current level of knowledge and risk behaviour with a phishing simulation or knowledge test.
- - Involve the board. The surface from above determines whether the awareness program succeeds or sands.
- Plan a first phishing simulation. Without measurement, you don't know where you stand and you can't improve.
- Determine three measurable KPIs. Click percentage, training rounding and the number of notifications are a good start.
- Set up a first training cycle. Basic training for everyone, followed by monthly repetition and role-specific floor.
Do you want to know where your organisation is now in the field of security awareness? Contact Kynexis Information Security for a baseline assessment or GAP analysis. You get an independent picture of your current risk profile and a useful first step.


