Cybersecurity lessons have a better chance to endure when people first understand how the same risks affect their own lives.
By Jim West, based on the “inSECURITY” session for Hacker Halted / Global CISO Forum 2026
“Security awareness asks people to remember a rule. Relevance gives them a reason not to forget it.”
The Problem Is Not Awareness
Most people in an organization, from new hires to executives and security professionals, do not need another definition of phishing. They have heard the litany of warnings about suspicious links, password reuse, multifactor authentication, data handling, social engineering, and keeping software up to date. The problem is not that cybersecurity organizations have failed to distribute information; rather, the information is too often delivered from the business’s perspective rather than from the perspective of the person expected to remember it.
Each year, during compliance training, employees are told to protect corporate data, preserve customer trust, reduce ransomware risk, and follow the policies. While these goals are important for any business, they can feel distant and disconnected from the decisions an individual makes during the workday. Once the annual module ends and the quiz is passed, the lesson competes with every other demand for that person’s attention.
Completion is not comprehension, and comprehension is not retention. If the goal is lasting behavior change, awareness alone is not enough. Cybersecurity must become relevant.
Make It Personal Before You Make It Corporate
The central idea behind my inSECURITY session at Hacker Halted and the Global CISO Forum is simple. Regardless of role, title, or technical expertise, people are more likely to remember cybersecurity principles when they first understand why those principles matter to them personally.
Consider password reuse. A corporate training module may explain credential stuffing and instruct users not to reuse passwords. That is technically correct, but it starts with the organization’s concern. A relevance-based approach starts somewhere more personal for each attendee. What happens if the password from a forgotten website is exposed? What else could it unlock – their personal email, shopping accounts, social media, cloud photos, or financial information?
Once a person sees the consequence in their own real life, the organizational connection requires very little explanation, and the parallels begin to draw themselves. Replace the personal account being compromised with a corporate account, and the principle is the same. The learner has not merely memorized a rule; the learner understands the reason why the rule exists.
The same approach works with social engineering. Rather than beginning with business email compromise, we should be asking how much a stranger could learn about us as a person from a few minutes of searching publicly available information. A child’s or pet’s name, a favorite sports team, a recent trip, an employer, a colleague, or a supervisor can all become ingredients in a convincing message. When participants recognize how easily their own public information can be contextualized and weaponized, “verify before you trust” stops sounding like corporate policy and starts to sound a lot more like common sense.
Participation Turns Information Into Experience
Participation is the reason why inSECURITY is an interactive event. Rather than asking an audience to consume slides passively, attendees are asked to make personalized choices and answer questions tailored to their point of view to help reveal common assumptions we make and work through familiar situations that connect to real-world cybersecurity concepts, using the connections they’ve made to their personal lives.
For example, I can ask a room to consider where they reuse a password – or even a variation of one – and then progressively identify which personal accounts that credential could expose. Before technical concepts such as credential stuffing or the risks of predictable password variations become the focus, participants have already mapped the threat to their own money, identity, privacy, and memories. The concept is no longer abstract.
Participation creates experience; experience creates relevance. Relevance gives understanding and retention a better chance to take hold. Those better decisions can reinforce a stronger security culture.

Cybersecurity Is Already Part of Daily Life
Each inSECURITY session demonstrates how individuals are already making access-control decisions. When they decide who enters their home, they’re implementing access controls. When they share a restaurant recommendation freely or protect a banking PIN during a transaction, they are already making intuitive information-classification and handling decisions. Audience members understand resilience when they keep copies of irreplaceable family photographs in more than one location because they know a phone, laptop, or home can be lost.
The opportunity for security leaders is not merely to invent analogies, but to reveal the cybersecurity principles people already use. Instead of beginning with a framework and searching for a relatable example, begin with a relatable experience and reveal the framework within it to build stronger associations, encourage more durable recall, and reframe how people think about cybersecurity in daily life.

Shifting away from a business-first perspective when teaching cybersecurity principles changes the learner’s role, from a passive recipient of security rules to a practitioner. They recognize the principle, test it against their own experience, and apply it in a new context. The real test does not occur during the course; it occurs days or months later, when a person must make a decision without a training slide telling them what to do.
What CISOs Should Change
Making this shift does not require abandoning compliance training, phishing simulations, or established awareness programs. It requires changing the objective from “Did people complete the training?” to focusing on “What will trainees still remember when the training is no longer in front of them?” Relevance-based learning does not replace technical controls or secure-by-design systems; it strengthens the human layer that must make decisions where the technology cannot make them automatically.
- The overarching goal of cybersecurity awareness programs is to influence human behavior and decision-making. Humans rarely make those decisions because a compliance dashboard is green. People are more likely to change behavior when the reason behind the behavior feels meaningful, relevant, and applicable to the decisions they actually make.
- By starting with an individual-first perspective in training, every lesson should answer “Why does this matter to me?” before asking “What does the organization require?”
- Designing participation in the lesson asks people to choose, predict, identify, and/or respond rather than just define or explain the security principle.
- Revisit concepts 30, 60, or 90 days later instead of relying only on an immediate post-training quiz to measure retention of the information over an extended period of time.
- Measure behavior, not just physical or virtual attendance. Looking beyond completion rates to reporting, recognition, repeat risky behavior, and other indicators shows whether decisions and user behaviors are changing and whether they have changed in response to the effectiveness of the training.
From Awareness to Relevance
Organizations will always need policies, controls, and mandatory training. But the most effective lesson may begin before we mention the organization at all.
Show people how cybersecurity protects their money, privacy, identity, family, reputation, memories, and choices. Let them experience the concept. Then connect that same lesson to the systems and information they protect at work.
Before asking people to protect what matters to the business, show them why cybersecurity matters to them. The goal is not for people to remember the cybersecurity training. The goal is for them to remember the cybersecurity lesson when the training is nowhere in sight.
About the Author
Jim West is a cybersecurity leader, educator, and speaker whose work focuses on making complex security concepts practical, memorable, and relevant for audiences at every organizational level. His interactive “inSECURITY” session is being presented at Hacker Halted / Global CISO Forum 2026.

