There's a sentence we've been repeating for years in cybersecurity: "the human is the weak link." I've heard it from my clients, read it in reports, seen it everywhere online, and every time, it bothers me. Because it says something true, but in the wrong way.
First, it's extremely guilt-inducing. The human isn't a weak link. It's a decision-making system, with its biases and its automatisms… And as long as we keep treating it as a flaw to fix rather than a behaviour to evolve, we'll keep pouring fortunes into training that changes nothing.
The real problem isn't knowledge, it's the reflex. When someone clicks on a phishing link, it's (almost) never out of ignorance. Most people "know" you shouldn't click, that you should be vigilant. They saw it in training, they ticked it in a quiz… But knowing and doing are two different things.
At the moment of the click, no one consciously reaches for what they learned months earlier. We act on automatism: an email that looks like a legitimate email, a busy day, a request that seems urgent. The behaviour plays out in two seconds. That's exactly where classic awareness fails: it builds up knowledge one to four times a year, but it never touches the reflex.
Why the "annual training" format can't work (and it's nobody's fault)
Imagine being asked to run a marathon, but your training consists of three intensive two-hour sessions across the year. No one would sign up for that. We know physical performance is built through repetition, spacing and regularity.
The brain works the same way for behaviours. The science of learning is clear on this: knowledge seen once fades; a behaviour anchored by spaced repetition lasts over time. Mandatory annual training isn't a good idea badly executed. It's the wrong format for the goal. We're trying to anchor lasting reflexes with a tool designed to transmit one-off information.
What behavioural science says about it
When you take the subject by the right end, three behavioural levers change everything.
The first is spaced repetition. Not more content: the same message, seen several times, at short intervals. That's what moves information from memory to automatism.
The second is context. A reflex is anchored when it's trained in conditions close to the real thing. Recognising a suspicious email in a quiz isn't the same mental act as recognising it in your inbox, on a Tuesday at 5pm, between two meetings.
The third is the nudge. You change behaviours by making the right behaviour easier, more natural. None of these levers are new; they're just very rarely applied in cybersecurity, because we modelled awareness on compliance rather than on behaviour change.
The change that needs to happen
Stop measuring completion rates. Start measuring behaviours. A cyber culture isn't decreed in training: it's built through repeated micro-gestures, until the right reflex becomes the default reflex. It's slow, it's less spectacular than a big annual campaign, and it's the only thing that works.
And there's a dimension we almost always forget. We file cybersecurity under the same heading as mandatory annual training, ethics, compliance, an HR box to tick, disconnected from people's real lives. Except cyber isn't only a corporate stake. The reflexes we train at the office are the same ones that protect a bank account, family photos, the identity of loved ones. For once, what we ask of employees doesn't just serve the employer: it protects them, in their private lives.
That's an engagement lever classic awareness completely leaves aside. We talk about "compliance" and "risk to the organisation" to people who, deep down, mostly just want not to get their own account hacked.
When I designed Billow, I asked myself a simple question: what makes an app like Strava succeed at anchoring a habit? The answer isn't in the content. Strava doesn't teach you to run better than anyone. What it does is create a short, regular appointment, make progress visible, set challenges, and turn an isolated effort into a habit that lasts. The gesture becomes automatic because it's frequent, measured, and enjoyable. That's exactly the behavioural mechanism cyber awareness is missing.
I'll be honest: cyber starts with a handicap. No one gets up in the morning wanting to train at spotting a phishing email. That's precisely why the format matters so much. If the training is playful, quick, and you feel yourself progressing, you come back. If it's long, theoretical and mandatory, you endure it and forget it.
Because the human factor isn't a problem to fix: it's behaviours to support, day after day.