Adaptive Security Awareness Training: Unlearning and Relearning Routines

Adaptive Security Awareness Training: Unlearning and Relearning Routines

Jul 10

Lev Lesokhin
Lev Lesokhin Lev Lesokhin is an experienced business technologist, a former software developer, consultant, and tech executive. Having started his career at MITRE, Lev has had many touch-points with cybersecurity thought leaders over the years. In his current role as OutThink's Executive Vice President for Technology and Analytics, he works with customers and industry leaders to build a quantitative framework for evolving security awareness into human risk management.
View Profile
Share
Cybersecurity is evolving, and so must our approach to training. Traditional security awareness training programs have often fallen short, focusing merely on compliance rather than cultivating a genuine culture of cybersecurity. As Professor Angela Sasse highlights in today's Secure and Engage Podcast episode, effective security awareness training requires us to rethink routines and integrate continuous learning principles to meet the challenges presented by an incredibly dynamic cyberthreat landscape.

The Roots of Human-Centric Cybersecurity Awareness Training

Aside from serving as OutThink's scientific advisor, Professor Sasse also consults for the UK’s National Cyber Security Centre (NCSC) and the EU Agency for Cybersecurity (ENISA). She is the founding director of the multidisciplinary UK Research Institute for Science of Cyber Security (RISCS) and has overseen over 30 Ph.D. students to successful defense of their dissertations. Needless to say, every time I speak to Angela I get to learn something new, which, back to my earlier point, makes it an absolute pleasure.
For our podcast, we started with a great story of how Angela got pulled into studying the human factors of cybersecurity. It all started with pesky passwords – a telecom company in the 1990’s whose internal support center to help people reset their passwords had grown 100 strong. That’s an awful lot of expense. Their question to the new professor: Why can’t these “stupid users” remember their passwords? Relatable question!

The Role of Behavioral Economics in Cybersecurity Awareness Training

Sasse’s insights draw heavily from Daniel Kahneman’s research on System 1 and System 2 thinking. These behavioral economics principles explain how most human actions are driven by routines (System 1), while problem-solving requires deliberate thought (System 2). Effective cybersecurity training must account for these cognitive patterns to be effective.
Most of our actions—80-90%—are automatic, governed by System 1 thinking. For example, entering passwords or recognizing phishing emails can become intuitive with proper training. However, asking employees to engage in deep, continuous System 2 thinking for every task can lead to cognitive overload and frustration.
Professor Sasse underscores the importance of designing security practices that blend seamlessly into daily routines. She quotes General MacArthur to drive home her point: "Never give an order that's impossible to execute." By making secure behavior effortless, organizations can ensure consistent adherence without overburdening employees.

Transforming Cybersecurity Awareness into Routine Behavior

Occasional, one-off cybersecurity awareness training alone isn’t enough. Organizations must invest in ongoing, regularly updated training that reinforces secure behaviors until they become routine. Gamified and role-specific modules, scenario-based content, and real-time reminders can help embed these practices into employees’ daily lives.
Cultural transformation requires top-down support. Corporate leaders must champion cybersecurity culture and initiatives, allocate resources for training, and model secure behavior themselves. A Chief Information Security Officer (CISO) can act as an enabler, but the real change comes when the entire leadership team prioritizes security.

Lessons from Broader Workplace Transformations

The workplace has undergone significant changes over the past two decades, from embracing racial diversity to fostering gender inclusivity. These shifts demonstrate that systemic change is possible with sustained effort and should serve as models for the drive to embrace human-centric cybersecurity culture. Transforming cybersecurity culture demands continuous reinforcement, strategic planning, and alignment with organizational goals - its increasingly clear that the benefits of achieving such progress are well worth the efforts involved.
Enjoyed this blog post? Share it with someone!Share

Build effective and sustainable human-centric security with OutThink

Build effective and sustainable human-centric security with OutThink

Related Articles
Risk Quantification for Cybersecurity Human Risk Management
Lev Lesokhin
13/12/2024

Risk Quantification for Cybersecurity Human Risk Management

Read More about AI-Native Cybersecurity Human Risk Management
Empowering Organizations with Adaptive Security Awareness Training
Roberto Ishmael Pennino
07/11/2024

Empowering Organizations with Adaptive Security Awareness Training

Read More about AI-Native Cybersecurity Human Risk Management
Cybersecurity Awareness Training for Remote Workforces
Roberto Ishmael Pennino
25/10/2024

Cybersecurity Awareness Training for Remote Workforces

Read More about AI-Native Cybersecurity Human Risk Management
Human Risk Management Gets Adaptive
Lev Lesokhin
08/10/2024

Human Risk Management Gets Adaptive

Read More about AI-Native Cybersecurity Human Risk Management
What is Cybersecurity Human Risk Management? What You Need to Know
Lev Lesokhin
23/09/2024

What is Cybersecurity Human Risk Management? What You Need to Know

Read More about AI-Native Cybersecurity Human Risk Management
Engagement Strategies for Cybersecurity Human Risk Management
Lev Lesokhin
16/08/2024

Engagement Strategies for Cybersecurity Human Risk Management

Read More about AI-Native Cybersecurity Human Risk Management
Enhance Your Phishing Training With Outthink
Lavinia Manocha
02/08/2024

Enhance Your Phishing Training With Outthink

Read More about AI-Native Cybersecurity Human Risk Management
Adaptive Security Awareness Training for Frontline Workers
Lavinia Manocha
26/07/2024

Adaptive Security Awareness Training for Frontline Workers

Read More about AI-Native Cybersecurity Human Risk Management
The Role of Security Awareness Training After IT Outages
Lev Lesokhin
26/07/2024

The Role of Security Awareness Training After IT Outages

Read More about AI-Native Cybersecurity Human Risk Management
Human Risk Management's Eight Dimensions of Secure Behavior Segmentation
Lev Lesokhin
25/07/2024

Human Risk Management's Eight Dimensions of Secure Behavior Segmentation

Read More about AI-Native Cybersecurity Human Risk Management
State-Sponsored Phishing Attacks Target 40,000 Corporate Users: What This Means for Protecting Your Business
Lev Lesokhin
18/07/2024

State-Sponsored Phishing Attacks Target 40,000 Corporate Users: What This Means for Protecting Your Business

Read More about AI-Native Cybersecurity Human Risk Management
Adaptive Security Awareness Training: Unlearning and Relearning Routines
Lev Lesokhin
10/07/2024

Adaptive Security Awareness Training: Unlearning and Relearning Routines

Read More about AI-Native Cybersecurity Human Risk Management
Did You Think Your Password Was Secure? Let’s Talk Password Security
Lev Lesokhin
24/05/2024

Did You Think Your Password Was Secure? Let’s Talk Password Security

Read More about AI-Native Cybersecurity Human Risk Management
Rethinking Security Awareness: Towards a Cybersecurity Human Risk Management Framework
Lev Lesokhin
23/05/2024

Rethinking Security Awareness: Towards a Cybersecurity Human Risk Management Framework

Read More about AI-Native Cybersecurity Human Risk Management
Password Security: Why the UK is Banning Generic Passwords
Lev Lesokhin
17/05/2024

Password Security: Why the UK is Banning Generic Passwords

Read More about AI-Native Cybersecurity Human Risk Management
Instagram Security Awareness Training: A Step-by-Step Guide
Lev Lesokhin
10/05/2024

Instagram Security Awareness Training: A Step-by-Step Guide

Read More about AI-Native Cybersecurity Human Risk Management
Cybersecurity Human Risk Management Forum Kicks Off in London
Lev Lesokhin
18/04/2024

Cybersecurity Human Risk Management Forum Kicks Off in London

Read More about AI-Native Cybersecurity Human Risk Management
Gamification Can Enhance Security Awareness Training – Badges and Leaderboards Are Just the First Step
Rory Attwood
31/01/2024

Gamification Can Enhance Security Awareness Training – Badges and Leaderboards Are Just the First Step

Read More about AI-Native Cybersecurity Human Risk Management