Skip to main content

Security Awareness and Behavior Change

Build role-specific learning around real tasks, safe alternatives, practice, feedback, and measured behavior instead of annual completion.

Learning tied to work

Security awareness creates recognition of risks and expected action. Training develops a skill for a role. Education builds deeper understanding. A behavior-change program connects these to real tasks, tools, environment, incentives, feedback, and measurement.

Completion does not prove skill or safe behavior. A person cannot follow a control that is unavailable, too slow, inaccessible, or contradicted by management incentives.

Role and task analysis

Identify high-risk tasks by role: support recovery, administrator changes, developer secret handling, finance payment verification, user reporting, executive approval, vendor access, and incident containment. State desired behavior, preconditions, safe tool, expected time, escalation, and consequence.

Teach the smallest relevant knowledge near the task. Provide practice in a realistic environment and immediate corrective feedback. Make the approved path easier to find than a workaround.

Measurement and learning loop

Measure ability and system outcome: correct completion, errors, reporting time, unsafe exceptions, recovery quality, credential sharing, broad access, support load, incident recurrence, and control use. Interpret phishing simulations with message difficulty, role, exposure, and harm.

Use aggregate results to improve systems and teaching. Protect privacy and avoid public punishment. If people repeatedly fail at one step, redesign the workflow and control before repeating the same lesson.

Failure and residual risk

Annual generic training decays and may reward attendance. Surprise simulations can damage trust and discourage reporting. Metrics can drive easy tests or hidden incidents. Training can shift responsibility from unsafe architecture to users.

Knowledge does not stop deliberate insider abuse, compromised devices, or a technically phishable protocol. Use engineering controls for those risks.

Pomerium boundary

Pomerium can make protected routes consistent and provide access evidence. It does not create the organization's learning program or verify that users understand application actions. Training should cover the actual identity provider, route, approval, support, and reporting workflow deployed around Pomerium.

Evaluation checklist

  • Is each lesson tied to a role, real task, safe tool, escalation path, and measurable behavior?
  • Can the person perform the safe action under realistic time, device, accessibility, and workload conditions?
  • Do metrics measure harm reduction and reporting, not only completion or simulated clicks?
  • Does repeated error trigger workflow and control redesign as well as more training?
  • Are privacy, fairness, trust, and non-punitive reporting protected?

Sources and further reading

Keep learning

Human Factors and Security EconomicsSecurity Engineering Foundations

Usable Security

Make the secure action effective, efficient, understandable, accessible, recoverable, and compatible with the person's real task.

Learn this term
Human Factors and Security EconomicsIdentity and Authentication

Phishing

Distinguish deceptive delivery from verifier impersonation, credential relay, malware, payment fraud, and session theft, then use protocol controls.

Learn this term
Human Factors and Security Economics

Social Engineering

Model deception and influence that cause a person or process to disclose information, change identity state, or perform an unauthorized action.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo