Why Cybersecurity Awareness Alone Doesn't Stop Phishing: Lessons from a Human-Centred Study of 200 Users
Phishing has become the most common cybersecurity threat and increasingly exploits human factors rather than technical vulnerabilities. This study examined the relationships between cybersecurity awareness, training frequency, user cyber-hygiene behaviour, organisational culture, risk perception, and self-reported phishing vulnerability. and the theoretical basis of this research is the Technology Threat Avoidance Theory (TTAT). A quantitative correlational design was used for data collection and analysis with Pearson correlation in structured questionnaires. The results indicated that the five independent variables have a significant positive relationship with phishing vulnerability. The increased awareness and regular training correlate with greater recognition of the vulnerability, suggesting improved self-observation but not an increased risk. On the same note, users with high cyber-hygiene practices also perceived themselves as more vulnerable, suggesting that protective measures can be driven by risk perception. An organisational culture also significantly correlated with vulnerability, which requires institutions that are supportive to provide a key role in threat perception. Vulnerability was also impacted by risk perception, with those who perceived phishing to be serious and personalised tending to agree that they were vulnerable. The findings, in general, support the idea that phishing vulnerability is a multidimensional phenomenon shaped by cognitive, behavioural, and organisational factors.
Despite years of cybersecurity awareness campaigns, phishing remains one of the most successful attack techniques used by cybercriminals. Why do users still fall for phishing attacks even after completing training and understanding the risks?
This talk presents findings from a published cybersecurity research study investigating the relationship between cybersecurity awareness, training frequency, cyber-hygiene behaviours, organisational culture, risk perception, and phishing vulnerability. Based on data collected from 200 participants, the research reveals that phishing vulnerability is far more complex than a simple lack of awareness.
Attendees will explore how human behaviour, organisational environments, and psychological factors influence security decisions. The session will challenge common assumptions about awareness training and discuss why security knowledge alone does not always translate into secure behaviour.
Whether you work in security operations, awareness and training, governance, risk, compliance, or leadership, this talk will provide practical insights into reducing human-centred security risks and building more resilient security cultures.
Key takeaways include:
• Why awareness alone is not enough to stop phishing attacks.
• The role of cyber-hygiene and behavioural security practices.
• How organisational culture influences phishing susceptibility.
• The importance of risk perception in cybersecurity decision-making.
• Practical recommendations for strengthening human-centred cyber defence.
I am a cybersecurity and cloud infrastructure professional specialising in securing and optimising enterprise IT environments across multinational organisations.
My work focuses on cloud security, virtualisation, risk management and resilient infrastructure, supporting organisations in building scalable and secure digital systems. I have contributed to enterprise technology initiatives that improve operational efficiency, strengthen security posture and enable business growth.
Alongside my industry work, I actively contribute to the global technology ecosystem through research, public speaking and knowledge sharing. I have delivered an industry talk at a recognised international VMUG community event and regularly publish peer-reviewed cybersecurity research, with multiple journal articles currently under review and additional publications planned.
I collaborate closely with senior business and technology leaders, enabling me to bridge the gap between technical strategy and business outcomes. This experience has strengthened my ability to lead initiatives, share expertise and support the development of emerging professionals in the field.
My long-term goal is to contribute to the advancement of secure and innovative technology at an international level while supporting the growth of the wider tech community.