News & Views

Most employees forget their security induction within 24 hours. So why do we still rely on it to change behaviour?

Most employees forget their security induction within 24 hours. So why do we still rely on it to change behaviour?

A Member Blog by David Horn of CyberWhite

Security inductions are supposed to set the tone from day one.
They’re meant to show employees how to think about risk, what’s expected of them, and why it matters.
But the reality is, they rarely do.

For many people, security induction is just another box to tick, something to get through, not something to absorb. This is not because security isn’t important; it’s typically because the way we deliver it doesn’t align with how people really learn or behave.

The reality of day one.
Think about your first day in a new role.

You’re introduced to new systems, new colleagues, new processes. You’re trying to remember names, figure out how things work, and get comfortable in an unfamiliar environment.

Somewhere in the middle of all that, you’re given a security induction.

It’s usually a slide deck, a long e-learning module, or a video. It’s packed with policies, rules, and technical detail. By the end of it, you’ll struggle to remember much about what you’ve just seen.

This isn’t because you don’t care, it’s because it’s too much, too soon, and often not relevant.

Where security inductions fall short.

There are a few common reasons why these sessions miss the mark:

They aren’t relevant.
Most inductions adopt a one-size-fits-all approach.

Everyone receives the same content, regardless of role.

However, the fact is that risks faced by someone in finance are very different from those in IT, operations, or client-facing roles. When people can’t see how something applies to their day-to-day work, it’s simple for staff to tune out.

They focus on rules, not understanding.
“Don’t click suspicious links.”
“Don’t share passwords.”
“Lock your screen.”

These are all valid rules but without context, they quickly become background noise. 
If people don’t understand why these rules exist or what can go wrong, they’re far less likely to take them seriously.

They lack real-world context.
What’s often missing is the “so what?”
What does a phishing attack look like?
How can a small mistake escalate into a serious incident?

Without real examples, security can feel abstract, i.e. important in theory, but distant from everyday work.

The timing works against you.
Day one is overloaded by default. Even strong content struggles to land when it’s competing with everything else a new starter is trying to process.

They’re treated as a compliance exercise.
Once the induction is complete, it’s recorded, signed off, and largely forgotten.
The reality is that behaviour doesn’t change just because someone sat through a training session.

Shifting from compliance to impact.

The good news is that this isn’t a complex problem to fix. It simply requires a shift in approach.

1. Make it relevant.
Tailor content to different roles or teams. Even small adjustments can make a big difference.
Show people the risks they’re most likely to encounter and what they can do about them. When they see themselves in the scenario, they pay attention.

2. Keep it focused.
You don’t need to cover everything at once.
In fact, trying to do so is often part of the problem. Focus on a small number of key behaviours (the ones that matter most). Make them simple, clear, and memorable.

3. Make it interactive.
People learn far more by doing than by passively consuming content.
Show a phishing email and ask: What would you do?
Walk through a scenario and discuss the outcome.
Even brief interaction can be more powerful than an entire slide deck.

4. Use real examples.
Stories stick. A real incident, near-miss, or even an industry example makes the risk tangible. People are far more likely to remember a story than a list of rules.

5. Reinforce over time.
An induction should be the starting point and not the only touchpoint!
Short refreshers, team discussions, simulated phishing exercises all help keep security front of mind. Without reinforcement, even the best induction fades quickly.

6. Lead by example.
Culture is shaped by behaviour at the top.
If leaders and managers take security seriously (and demonstrate it), others will follow. 
If they treat it as a formality, that attitude also spreads just as quickly.

A missed opportunity… or a starting point?

Security inductions don’t fail because they’re unnecessary.
They fail because they’re designed for compliance, not impact.

Done well, security inductions can be so much more than a tick-box exercise. They can shape how people think about risk, influence everyday decisions, and lay the foundation for a stronger security culture.

To conclude, security inductions don’t fail because people don’t care.
They fail because we expect a single moment to change long-term behaviour.
The organisations that get this right don’t stop at day one.
They design security as something people experience regularly, not something they endure once.

So the real question is this:
“Are you designing for completion, or for behaviour change”? as only one of those reduces risk.