Security awareness

Security awareness people actually act on.

The “package on hold” text, the call from “IT support”, the customer spreadsheet pasted into a personal AI account. Your people practice those decisions in one-minute missions several times a year, and qlture runs the whole operation.

Quick answer

What is security awareness training?

Security awareness training is an ongoing set of actions that teaches people to recognize and respond to risks such as phishing, social engineering and credential theft. In a qlture program, people practice this in one-minute missions and team contests, and we run everything behind them.

Why security policies don’t stick

  1. 01

    People know. They do it anyway.

    In Proofpoint’s 2024 State of the Phish, 96% of people who took a risky action knew it was risky. They already have the information. What they lack is the habit when they are in a hurry.

  2. 02

    Annual training doesn’t change clicks.

    A UC San Diego study of more than 19,500 employees found no relationship between recently completing annual training and falling for simulated phishing.

  3. 03

    Attacks don’t only come by email.

    In simulations analyzed by the Verizon 2026 DBIR, text and voice lures had higher click rates than email. Verizon itself notes the sample is small.

  4. 04

    AI arrived before the rules.

    According to the Verizon 2026 DBIR, 45% of employees are regular AI users on corporate devices, and 67% access AI with non-corporate accounts.

Mission examples

Situations we might write for this topic. In your program, they come from your own policies.

IT support · 10:15 am

A call from “support”.

Someone from the “service desk” calls saying your account is locked and asks for the code that just reached your phone. Do you share the code or hang up and open a ticket through the official channel?

Mission 01

Marketing · 3:30 pm

A quick prompt.

You need to summarize a customer spreadsheet before the 4 pm meeting, and your personal AI account does it in seconds. Do you paste the data or use the tool your company approved?

Mission 02

Logistics · 8:40 am

Delivery on hold.

A text arrives: “Your package is on hold. Update your address.” You are expecting a delivery. Do you tap the link or check directly on the carrier’s website?

Mission 03

What qlture does with your security policy

01

Discovery with your team

We read the policy, listen to security and the most exposed teams, and pick a few high-impact behaviors to start with.

02

Missions built on real scenarios

We write scenarios from what has already reached your help desk and security team. If this month’s scam was a doctored invoice, the next mission is about it.

03

Team competitions

Departments compete in mission seasons. Scores are by team, so nobody is singled out.

04

Security champions

A few people in each department get training, ready-made missions and recognition, and become the ones colleagues ask before they click.

05

A reporting culture

Reporting fast beats never making a mistake. Missions build the reflex to report, and the program recognizes those who do.

What we track

  • Participation by team
  • Right calls per mission
  • Reporting rate
  • Time to report
  • Repeat risky choices
  • Champion engagement
  • Progress per cycle

Legal basis and references

Brazil’s LGPD, art. 46 ↗
Brazil’s data protection law requires technical and administrative security measures to protect personal data. Training people is one of the most direct administrative measures.
SANS Maturity Model (2026) ↗
Compliance-focused programs measure course completion. Mature programs measure behavior change. That is the stage qlture’s program aims for.
Forrester on human risk management ↗
In 2024, Forrester renamed the security awareness market human risk management: measuring behavior, quantifying human risk and building a positive security culture.

Frequently asked questions

01How do you build a security awareness program?

Start with a few high-impact behaviors, such as reporting suspicious messages and verifying payment requests. Then build a yearly calendar of short missions, campaigns and measurement by team. qlture builds and runs that calendar with you.

02Do missions replace phishing simulations?

No. The platform also runs phishing and smishing tests, and the two work together. Tests show who falls for it; missions train the decision and the report, including situations a test doesn’t cover, like a call from fake IT support. In a 15-month ETH Zurich study with more than 14,000 employees, what worked was employees acting as a reporting network: about 10% of reports arrived within 5 minutes.

03Which metrics show awareness is working?

Click rate alone is misleading. Track reporting rate, time to report, repeat risky choices and participation by team. In the SANS maturity model, compliance-focused programs measure completion; mature ones measure behavior.

04What is human risk management, and how is it different from security awareness?

In 2024, Forrester started calling the security awareness market human risk management: measuring behavior, quantifying human risk, triggering interventions and building security culture. The shift is in focus, from course completion to behavior.

05Who is responsible for security in a company?

The security team sets policies and controls. But every person decides when they click, share a file or approve a payment. The program involves leaders and champions from every department, well beyond IT.

06What should we do for Cybersecurity Awareness Month?

October is a good moment to open a season: team competitions, missions about current scams and recognition for the best reporters. In November the program keeps going, because October is one cycle inside it.

Other topics

Sources (6)
  1. Verizon, 2026 Data Breach Investigations Report
  2. Proofpoint, 2024 State of the Phish
  3. Ho et al., Understanding the Efficacy of Phishing Training in Practice (IEEE S&P 2025)
  4. Lain, Kostiainen and Čapkun, Phishing in Organizations (IEEE S&P 2022)
  5. SANS, Security Awareness and Culture Maturity Model (2026)
  6. Forrester, Introducing Human Risk Management (2024)

Shall we put this
into practice?

Tell us which policy people sign and then ignore. We design the program with you.

Let’s talk