The Problem With How Most Organizations Approach Security Awareness

Every year, the numbers get worse. Breaches increase. Costs rise. The human element remains the most exploited vulnerability in virtually every attack chain. And every year, organizations respond by spending more on the same things that failed them the year before.

I have trained security teams across the GCC, the US, and beyond. Corporate clients, government agencies, financial institutions. The technical skill levels vary enormously. But one problem appears almost universally, regardless of sector, size, or budget: organizations treat security awareness as a compliance exercise rather than a security control. Until that changes, the spending is largely wasted.

The Compliance Trap

Most corporate security awareness programs exist because something requires them. A regulatory framework, an insurance policy, an audit checklist. The organization commissions training, employees complete it, completion rates are reported, and the box gets ticked.

Organizations globally spent around $6 billion on security awareness training in 2025; the majority driven by regulatory compliance requirements rather than a genuine focus on risk reduction. A 2025 Huntress study found that 93% of organizations had increased their security awareness training budgets over the past three years. In that same period, 94% saw a rise in security incidents linked to employee mistakes.

Read that carefully. More investment. More incidents. The training budgets went up. The risk went up with them.

Research presented at Black Hat USA 2025 by UC San Diego Health confirmed what practitioners have known for years: annual, compliance-focused training alone does little to reduce the likelihood of employees falling for real attacks.

The problem is not a lack of training. It is a misunderstanding of what training is supposed to accomplish.

What Most Programs Actually Look Like

A typical corporate awareness programs runs once a year. Employees watch a module; sometimes animated, sometimes just slides, covering general topics like phishing, password hygiene, and data handling. They answer a short quiz. The system logs completion. Done.

This approach has three fundamental problems.

  1. First, it treats awareness as knowledge transfer rather than behavior change. Knowing that phishing exists does not make someone better at spotting a well-crafted spear phishing email tailored to their organization, their role, and their current projects. Knowledge and instinct are not the same thing.
  2. Second, it is generic when the threat is specific. Only 7.5% of security awareness programs personalize training to individual risk levels, despite research showing that 8% of employees drive 80% of security incidents. Finance teams face different attack scenarios than helpdesk staff. Senior executives are targeted differently than entry-level employees. A single module covering everyone covers no one adequately.
  3. Third, it is static when the threat is evolving. The social engineering techniques employees need to recognize today look different from those in last year's training content. AI-generated phishing emails, deepfake audio impersonating executives, pretexting scenarios built around real organizational details scraped from LinkedIn;  none of these feature in a compliance module written two years ago.

The GCC-Specific Problem Nobody Talks About

There is a dimension to this challenge that is particularly acute in our region and rarely addressed directly.

The GCC workforce is among the most diverse in the world. In the UAE alone, over 200 nationalities are represented in the working population. Saudi Arabia, Qatar, and Bahrain have equally complex workforce compositions: nationals, Arab expatriates, South Asian professionals, Western executives, all operating within the same organizations.

Security awareness training delivered exclusively in English misses a significant portion of that workforce. Training built around Western corporate contexts and examples does not resonate with an employee in Dubai or Riyadh whose daily working context is entirely different.

Attackers understand this. Social engineering attacks targeting GCC businesses are increasingly designed around regional business culture; using Arabic language, referencing local companies and ministries, and exploiting cross-border communication patterns specific to the Gulf. The training content defending against those attacks needs to reflect the same context. Most of it does not.

What Actually Works

I am not against awareness training. I am against awareness training that mistakes activity for outcomes.

Organizations that implement continuous, properly designed awareness programs can reduce phishing susceptibility by up to 86% within a year compared to their baseline. That is a meaningful result. But it requires a fundamentally different approach from annual compliance modules.

Effective programs do three things consistently.

  1. They simulate real attacks rather than theoretical ones, using current lures, regional context, and role-specific scenarios that reflect what employees actually encounter.
  2. They deliver immediate, contextual feedback when someone fails a simulation, turning the failure into a learning moment rather than a statistic.
  3. And they run continuously, monthly or quarterly touchpoints that keep threat awareness current rather than letting it decay between annual sessions.

Despite this, 69% of senior leaders say their employees still lack adequate security awareness, a figure virtually unchanged from 67% the previous year. Budgets increased. Programs continued. The gap did not close.

That is what happens when the measure of success is completion, not behavior change.

The Shift That Needs to Happen

Security awareness is not an HR function or a compliance deliverable. It is a security control. One that directly affects an organization's exposure to the most prevalent attack vectors in use today.

The organisations I have seen build genuine security culture treat it that way. They measure it the way they measure other controls: not by who completed the module, but by whether behavior has changed. Do employees report suspicious emails? Has the phishing click rate dropped? Are helpdesk staff questioning unusual access requests?

Those are the outcomes that reduce risk. Completion rates are not.

Until organizations in the UAE, Saudi Arabia, and across the GCC make that shift from compliance theatre to measurable behavior change, the investment will keep growing and the incidents will keep following it.

By: Tarek - Lead Trainer