Learning tied to work
Security awareness creates recognition of risks and expected action. Training develops a skill for a role. Education builds deeper understanding. A behavior-change program connects these to real tasks, tools, environment, incentives, feedback, and measurement.
Completion does not prove skill or safe behavior. A person cannot follow a control that is unavailable, too slow, inaccessible, or contradicted by management incentives.
Role and task analysis
Identify high-risk tasks by role: support recovery, administrator changes, developer secret handling, finance payment verification, user reporting, executive approval, vendor access, and incident containment. State desired behavior, preconditions, safe tool, expected time, escalation, and consequence.
Teach the smallest relevant knowledge near the task. Provide practice in a realistic environment and immediate corrective feedback. Make the approved path easier to find than a workaround.
Measurement and learning loop
Measure ability and system outcome: correct completion, errors, reporting time, unsafe exceptions, recovery quality, credential sharing, broad access, support load, incident recurrence, and control use. Interpret phishing simulations with message difficulty, role, exposure, and harm.
Use aggregate results to improve systems and teaching. Protect privacy and avoid public punishment. If people repeatedly fail at one step, redesign the workflow and control before repeating the same lesson.
Failure and residual risk
Annual generic training decays and may reward attendance. Surprise simulations can damage trust and discourage reporting. Metrics can drive easy tests or hidden incidents. Training can shift responsibility from unsafe architecture to users.
Knowledge does not stop deliberate insider abuse, compromised devices, or a technically phishable protocol. Use engineering controls for those risks.
Pomerium boundary
Pomerium can make protected routes consistent and provide access evidence. It does not create the organization's learning program or verify that users understand application actions. Training should cover the actual identity provider, route, approval, support, and reporting workflow deployed around Pomerium.
Evaluation checklist
- Is each lesson tied to a role, real task, safe tool, escalation path, and measurable behavior?
- Can the person perform the safe action under realistic time, device, accessibility, and workload conditions?
- Do metrics measure harm reduction and reporting, not only completion or simulated clicks?
- Does repeated error trigger workflow and control redesign as well as more training?
- Are privacy, fairness, trust, and non-punitive reporting protected?
