Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
Training Alone Won't Stop the Next BreachPasswords & Hashing
5 min readFor Cyber-Risk Analysts

Training Alone Won't Stop the Next Breach

Your team just failed another phishing simulation. You've run the awareness training, sent reminder emails, and posted security tips. Yet someone still clicked the link, and now you're explaining to leadership why education isn't translating to behavior change.

The problem isn't your people. It's your approach.

NIST recently released a concept paper on human-centered cybersecurity, asking a vital question: what if we stopped treating users as vulnerabilities to patch and started designing security processes that actually fit how humans work?

This isn't about abandoning training. It's about recognizing that awareness alone can't compensate for poor user experience, impossible workflows, or tools that assume perfect decision-making at 2 a.m.

The Decision You're Facing

You need to reduce security incidents tied to human error. The question isn't whether to invest in your people, it's how. Do you double down on traditional awareness training, or do you redesign your security processes with human factors in mind?

This matters because many breaches trace back to human errors: clicking malicious links, reusing passwords, misconfiguring settings, or choosing insecure workarounds to bypass friction. Your current approach likely emphasizes training employees to memorize rules and make perfect decisions. But that's not addressing root causes like confusing interfaces, disrupted workflows, or security fatigue.

Key Factors That Affect Your Choice

Before choosing a path, assess these conditions:

Your current incident patterns. Are failures concentrated around specific tools or processes? If password reset requests spike every 90 days, that's a design problem, not a knowledge problem.

Employee feedback on security friction. Do people describe security processes as obstacles? Are they inventing workarounds? That's a signal that your controls don't align with actual work patterns.

Security team burnout levels. Are your analysts drowning in alert fatigue, juggling disconnected dashboards, or making judgment calls while exhausted? Tools that ignore operator workflow create risk.

Organizational tolerance for redesign. Can you modify authentication flows, reconfigure access controls, or simplify approval processes? Or are you locked into rigid legacy systems?

Path A: Maintain Training-Focused Programs

Choose this path when:

  • You've recently redesigned core security processes and confirmed they're usable.
  • Incident analysis shows genuine knowledge gaps (people don't know what phishing looks like).
  • Your security tools already integrate smoothly into daily workflows.
  • You're working with compliance requirements that mandate specific training hours.
  • Budget constraints prevent tool or process changes this cycle.

What this looks like in practice:

Refine your awareness programs to address specific, observed gaps. If people struggle to identify credential phishing, run targeted simulations with immediate feedback, not gotcha-style tests that breed resentment.

Measure behavior change, not completion rates. Track whether people report suspicious emails after training, not whether they clicked through the slides.

Accept the limitations. Training can't overcome a password policy so complex that people write credentials on sticky notes. It can't fix a VPN that disconnects mid-task or a multi-factor authentication flow that requires six taps to approve a login.

The risk:

You're treating symptoms. If your processes create friction, frustration, or cognitive overload, training won't prevent workarounds. You'll see compliance in the training portal and noncompliance in actual behavior.

Path B: Redesign Security Processes Using Human-Centered Principles

Choose this path when:

  • Incident reviews reveal that people knew the right action but chose the wrong one due to friction.
  • Your security tools disrupt workflows or require decisions during high-pressure moments.
  • You're seeing security fatigue: employees ignoring alerts, clicking through warnings, or expressing frustration.
  • You have authority to modify authentication methods, access request flows, or monitoring interfaces.
  • Your organization values long-term risk reduction over short-term compliance checkboxes.

What this looks like in practice:

Start with the processes that generate the most friction. If password resets dominate your helpdesk tickets, that's your target. Replace complex rotation requirements with passkey-based authentication or FIDO2 hardware tokens that eliminate password memorization entirely.

Redesign based on actual workflow. If developers need temporary elevated access to production systems, don't make them submit a ticket and wait. Implement Just-in-Time Elevation with automated approval for pre-authorized scenarios and audit trails for review.

Build security controls that work with human limitations, not against them. If analysts miss critical alerts because they're buried in noise, fix your SIEM correlation rules. If users ignore warnings because they appear constantly, redesign your Policy Decision Point logic to reduce false positives.

Test with real users before deployment. Run your new authentication flow past someone who isn't a security professional. If they're confused, your design isn't done.

The effort required:

This path demands collaboration across teams. You'll need buy-in from IT, application owners, and business units. You'll spend time mapping workflows, identifying pain points, and iterating on designs. But the outcome is sustainable: security that people can actually follow.

Path C: Hybrid Approach, Redesign High-Friction Areas While Maintaining Training for Knowledge Gaps

Choose this path when:

  • You've identified specific processes causing the most friction (password policies, access requests, alert fatigue).
  • You have budget and authority to fix some systems but not all.
  • Your incidents split between genuine knowledge gaps and design-induced errors.
  • You need to show incremental progress while building the case for broader change.

What this looks like in practice:

Prioritize redesign for your top three friction points. Maybe that's implementing phishing-resistant authentication for privileged accounts, simplifying your access certification campaign workflow, or consolidating security dashboards so analysts aren't context-switching between tools.

Maintain targeted training for areas where redesign isn't feasible yet. If you can't replace your legacy application's clunky authentication this quarter, run specific training on recognizing session hijacking attempts in that system.

Use training to support new processes. When you roll out FIDO2 tokens, don't just hand them out, explain why they're better than one-time passwords and how they protect against credential phishing.

Measure both adoption and outcomes. Track whether people use the new streamlined access request process and whether that correlates with fewer shadow IT workarounds.

Summary Matrix

Factor Training-Focused Human-Centered Redesign Hybrid
Primary investment Content development, delivery Process redesign, tool evaluation Both, sequenced by friction impact
Timeline to impact Weeks to months Months to quarters Incremental wins over quarters
Addresses root causes No, assumes knowledge fixes behavior Yes, removes friction that causes errors Partially, fixes high-impact areas first
Requires cross-team collaboration Minimal Extensive Moderate
Best for Known knowledge gaps, recent tool improvements Systemic friction, high error rates despite training Budget constraints, mixed incident patterns
Risk if chosen incorrectly Persistent incidents, workarounds, fatigue Stalled projects without executive support Slow progress if priorities aren't clear

NIST is seeking feedback on its human-centered cybersecurity concept paper through September 30, 2026. That's your window to influence how these principles get codified into practical guidance.

The question isn't whether humans will remain part of your security equation. They will. The question is whether you'll keep blaming them for failures your processes created, or whether you'll design security that works with how people actually think, work, and make decisions under pressure.

Choose the path that matches your current constraints. But don't mistake training for strategy. If your people keep making the same mistakes, your design is the problem.

Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide

You Might Also Like