Beyond Compliance: How To Build Stronger Cybersecurity Instincts
gettyCybersecurity training is often treated as a compliance exercise: Employees complete a course, pass a quiz and get back to work. But as scams and attacks grow more convincing, varied and embedded in everyday communications and workflows, tech leaders need employees to recognize when something feels off and know what to do next.
That means thinking beyond security awareness as a periodic event and considering how people build judgment, confidence and good habits on the job. Below, members of Forbes Technology Council discuss practical ways tech leaders can help employees develop stronger security instincts as threats continue to expand and evolve.
Education is more successful when you’re nurturing human instincts rather than training people on mechanical procedures. To help your people get smarter about security, use technology to remove critical but tedious security tasks—like data tagging and retrieval—from their workflows. This gives organizations more time to do education and training around high-order skills that have a greater impact. - Dr. TJ Jiang, AvePoint
As AI turns more employees into software builders, tech leaders should embed security directly in the creation process, giving people guardrails and context as they work. Employees need to understand how the apps they build, the data they access and the permissions they grant can create real exposure. Security instincts are built through repeated, informed decisions in the flow of work, not by simply completing a training module. - Gil Geron, Orca Security
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?
The biggest shift should be moving to continuous practice. Turn security readiness into an ongoing measurable outcome instead of a compliance module. Help employees make decisions in realistic simulations and environments to give them reps and practice against threats they are likely to encounter. Static training just can’t do this. - Lee Rossey, SimSpace
Tech leaders should continuously deploy adaptive, realistic simulations to establish individual performance baselines and gradually improve employees’ security instincts by training them to pause, think independently and verify out-of-band requests in real time. This way, security training becomes a part of their day-to-day work rather than being relegated to periodic training sessions. - Eyal Benishti, IRONSCALES
Instincts get built through practice and repetition, which is why a once-a-year module rarely sticks. Give people continuous, realistic scenarios instead, like phishing simulations and tabletop exercises pulled from their real work, with fast, blameless feedback. Once they’ve seen a real attack unfold and know it’s easy to raise a hand, catching the next one becomes second nature. - Ido Geffen, Novee Security
Historically, security training has been a once-a-year, check-the-box exercise. That may satisfy a requirement, but it doesn’t build instinct, which is critical since AI is making threats faster and more convincing. Tech leaders should move to continuous, threat-informed training that mirrors real attacks. Repetition builds the reflex to pause, verify through another channel and respond when it matters. - Kevin Tian, Doppel
Stop measuring completion and start measuring behavior change. When I rolled out our AI governance and security policy, I skipped the standard slide deck and instead walked teams through real examples of what a bad prompt or a phishing attempt actually looks like in our own systems. People don’t build instincts from a module they clicked through once. They build them from seeing something close to their own work go wrong. - Surya Kishan Chikkala, LeadingResponse
Tech leaders need to institutionalize cyber discipline, not just mandate training. That means building security into daily routines, reinforcing good habits through leadership and repetition, and creating a culture where employees understand that protecting data and reducing risk is part of everyone’s job. - Erik Wittreich, Veilant
One way to shift employees from “compliance mode” to building actual security instincts is to replace generic training modules with real, recent examples from your own environment. Near-misses, actual phishing attempts your team received, or anonymized incidents from peer companies should be reviewed together in short, regular sessions rather than an annual click-through course. - Timmi Ryerson, Smart Property Systems
Leaders should inspire teams to understand why security matters. Build security instincts by making trust—not compliance—the purpose. “Be secure” is a command; “be trusted by our customers” and “be stewards of their information” are a mission. Celebrate judgment that advances that mission and address conduct that undermines it, and employees will gain a reason to pause, verify and report. Security then becomes a shared commitment, not an annual obligation. - David Etue, Cyberbit
Security awareness should extend beyond people to the operations they manage. Employees build stronger security instincts by recognizing operational deviations that “do not look right.” Changes in machine behavior, production, quality, maintenance or data flows can be early indicators of cyberthreats. Operational awareness helps teams detect attacks before traditional security tools generate alerts. - Claudio Laterreur, Chronos Smart Manufacturing
Turn security training into frequent, context-specific practice. Short simulations based on situations employees actually face—suspicious requests, unusual login prompts or sensitive data sharing—build pattern recognition better than annual modules. The goal is to make pausing, questioning and reporting feel like part of everyday work, not a compliance task. - Irina Shymko, Langate Software
Make it effortless for employees to report something suspicious. A one-click way to flag an email, message or unusual request helps turn security from a once-a-year training exercise into an everyday habit. The more often employees act on those instincts, the more confident they become in spotting potential threats. - Judit Sharon, OnPage Corporation
Trainings should include live roleplay, with scenarios in which security is compromised and teams need to learn how to act, respond and intervene. Such “live fire” training will sharpen the instincts of employees in a safe, sandbox environment while making them aware of the multitude of areas in which security risks exist and can be compromised. - Mark Francis, CaregiverZone
Security awareness needs to be embedded at the very top of the leadership structure, and then it will percolate through the organization, just like any other leadership trait. If the most senior people in the organization are insulated from having to be aware and having to practice good security posture, it will never flow down through the organization as a habit. - Erik Jost, Black Box
Security becomes a habit when people practice decisions, not just memorize rules. The goal is to build pattern recognition, much like a fire drill builds instinct before an emergency. Instead of relying mainly on annual training, expose employees to small, contextual scenarios—phishing attempts, suspicious prompts, unusual data requests, risky file sharing—and give immediate feedback on the decisions they made. You can also add gamification; perhaps something similar to “capture the flag.” - Peter Smulovics, Morgan Stanley
Tech leaders can help by weaving practice into team talks. For example, at a meeting, the leader could share a made-up, odd email and ask for gut reactions. Then, the team can discuss the clues indicating risk. This trains the mind to spot trouble fast, just like athletes drill moves. It beats dry lessons, as people learn better by working together. Instincts grow through live chats, not screens. - Rohan Pinto, 1Kosmos BlockID
Replace annual awareness alone with frequent, role-specific simulations followed by immediate coaching. Let employees practice recognizing the threats they actually face and reward fast reporting, not silent perfection. For example, run a realistic phishing or deepfake request, then show which cues mattered and how to escalate it. Security becomes instinct when people repeatedly practice decisions under realistic pressure. Make vigilance a daily habit. - Shelli Brunswick, SB Global LLC
Simulations build instinct, but only if there’s a real, clean signal. Most organizations bury it under “External Sender” banners on every email, alerts firing all day and warnings nobody reads. That “fire and forget” banner noise often trains people to click past danger. Before adding training, cut the false positives so real signals stay scarce and trusted. AI is making phishing attempts more flawless and harder to detect. A signal still believed is the last real edge. - Dan Sorensen, Nexus Security Advisors
Gamifying spam reporting or putting ridiculous phishing attempts on a dashboard can go a long way toward turning cybersecurity from a chore into a field your employees want to engage with. Engaged employees, in turn, are your best line of defense. - Kevin Korte, Univention
