As cyber-attacks grow more sophisticated, organisations cannot rely on compliance training alone. Nick Petschek argues that L&D leaders must drive behavioural change through realistic simulations, cross-functional ownership and a culture where employees feel urgency, think critically under pressure and treat cyber security as everyone’s responsibility, every single day at work.
Last summer we saw two of the UK’s largest retailers experience devastating cyber-attacks. M&S reported approximately £300 million in losses with empty shelves and online shopping services entirely shut down from the April attack date through to June, while Co-Op suffered a loss of £206 million when hackers caused payment problems, goods shortages and the loss of customer data.
Human error drives 95% of cyber breaches, meaning L&D face a critical challenge
Cyberattacks have become sophisticated enough to penetrate even the most robust security infrastructure. Yet human error drives 95% of cyber breaches, meaning L&D face a critical challenge: moving beyond conventional compliance training and towards genuine behavioural transformation. They must find a way to empower employees to recognise online manipulation and successfully deter attacks that could cost millions.
Why conventional training falls short
Traditional training methods often confuse awareness with action, meaning employees continue to compromise company networks, with 74% of Chief Information Security Officers (CISOs) citing human error as the biggest cybersecurity vulnerability.
Consider the M&S attack, a consequence of social engineering where hackers posed as employees to IT helpdesks, acquired password resets and gained access via a third-party supplier to enter and deploy ransomware which stole data and disrupted operations. When hackers deploy manipulation to enter organisational systems, employees need to be prepared to identify this deception and respond effectively even amid the high-pressure reality of an active incident.
Leaders should cultivate a sense of urgency within their teams by applying a “see, feel, change” approach. The conventional “Analyse-Think-Change” methodology rarely delivers the necessary impact to employees. For example, presenting statistics that show the severity of the situation, such as surveys that show 70% of medium businesses and 67% of large businesses have experienced breaches in the past year, although startling, fail to spark action. People will remain in “analyse” mode and quickly rationalise why they would be in the minority that wouldn’t fall victim to a breach.
To combat this, you should shift to a scenario-based approach, rather than relying on statistics. For example, inviting a leader from a compromised company to share their experience, how it felt to announce that they’d been hacked and its repercussions, will drive emotion that frequently leads to modified behaviour.
Building a security-conscious culture
Redesigning the onboarding process is also a key step in ensuring that you not only communicate the company’s vision but establish a culture where protection is equally prioritised.
Rather than simply sharing slides with information on cyber security, implement practice simulations that replicate genuine attempted attacks. This will create opportunities for employees to experience how they would prevent an intrusion. You can simulate a potential cyber threat by incorporating time constraints, creating authentic emails with genuine company branding, including replica help desks with precise information and invoices with recognisable vendor details. These components will compel employees to exercise judgement, not just recall information. This process generates immediate wins that can be acknowledged and used to monitor progress and motivate employees.
However, these simulations should correspond with specific employee functions. This means helpdesk staff should encounter practice scenarios that require verification of caller identity before providing details to the ‘employees’ who are locked out and becoming increasingly frustrated.
The way hackers attack systems has grown in complexity, far beyond sending phishing emails. Now they investigate their targets to leverage authority and urgency which triggers a reaction. To be effective, your scenarios must reflect the same pressure employees would feel during an actual breach attempt.
Throughout these programs, behaviour is the metric for success. Employees who hesitate when something seems unusual, adhere to the verification protocols established by your organisation, and escalate to security when they feel uncertain should be recognised as showing the correct response to preventing attacks.
Connecting departments to embed change
Cyber resilience is a transformation initiative, not simply a checkbox exercise. It demands cross-functional ownership and continuous engagement at every level. L&D teams shouldn’t be facing the challenge of educating against cyber threats in a silo. It’s crucial that teams throughout the business are brought in to work together on what should be viewed as a collective initiative.
IT departments should support any simulations, line managers should be engaged to confirm any training corresponds accurately with specific roles and requirements, and management should be generating urgency on the topic across the organisation to successfully help accelerate education and change.
Evolving for a dynamic cyber environment
Cyber threats are growing more sophisticated by the hour, so your training should evolve accordingly. The goal shouldn’t be to just teach employees rote material, but to build an instinct in them, where even under pressure putting security first is embedded into their behaviour. It’s this mindset and muscle memory that separates those organisations that try to survive from those that thrive in this fast-moving threat environment.
Nick Petschek is EMEA MD at Kotter

