Security awareness
Programs that teach employees to recognize and report threats. Completing courses does not equal changed behavior: that is validated with a retest.
Full definition
Security awareness is the set of programs an organization uses to teach employees to recognize, avoid and report threats such as phishing and social engineering. For years it was synonymous with annual courses and mandatory videos.
Its limit is documented: peer-reviewed evidence, including studies presented at IEEE Security and Privacy in 2022 and 2025, shows that completing training does not by itself predict fewer failures against real attacks. Knowing what phishing is and resisting it on a Tuesday at 4 p.m. with a full inbox are different things.
That is why the discipline is evolving into human risk management: awareness remains one piece, but the standard of success is no longer course completion. It is behavior validated with simulations and retests.
Related terms
Human risk management (HRM)
The discipline that measures and reduces the security risk originating in people's behavior, using continuous data instead of annual courses.
Microlearning
Training in short, specific doses delivered at the moment of the mistake. It uses the instant when a person is most receptive to learning.
Retest
A new simulation of the same attack category, weeks after a failure and with a different template, to verify the person actually changed their behavior.
Security culture
What employees do about security when nobody is watching: reporting, verifying, asking. It is built through practice, not posters.
From definition to data: measure your company's human risk
Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.