ISCAP Proceedings - 2026

Asheville, NC - November 2026



ISCAP Proceedings: Abstract Presentation


Knowing Is Only ½ The Battle: Examining the Impact of Cybersecurity Awareness Training On Employee Behavior


Nick Brenckle
Southern Connecticut State University

Abstract
Cybersecurity incidents continue to increase despite substantial investments in technical security controls. A growing body of evidence suggests that human behavior remains one of the most significant sources of organizational vulnerability, with employees frequently targeted through phishing, social engineering, and other forms of cyber deception. While cybersecurity awareness training has become a standard organizational response, questions remain regarding whether these programs produce meaningful and sustained behavioral changes rather than temporary increases in awareness or knowledge. This work-in-progress study investigates the extent to which cybersecurity awareness training influences employee behavior in organizational settings. The study seeks to address two central research questions: (1) Does cybersecurity awareness training have a short-term effect on employee behavior? (2) Does cybersecurity awareness training have a long-term effect on employee behavior? Existing research has largely focused on awareness, intentions, perceptions, or immediate post-training outcomes, leaving important questions regarding sustained behavioral change unanswered. Many of these studies rely primarily on self-reported measures, creating challenges in distinguishing short term knowledge acquisition from long term behavioral change. This research seeks to contribute to the increasingly important field of human-centered cybersecurity by examining both perceived behavior changes and objective behavioral indicators over time. Data collection will combine survey responses with anonymized phishing simulation results collected through a one-year period. Survey measures are adapted from validated cybersecurity behavior instruments, including the Security Behavior Intentions Scale (SeBIS), and assess training quality, engagement, retention, self-efficacy, cybersecurity behavior, perceived training impact, and organizational cybersecurity culture. Selected References Bada, M., Sasse, A. M., & Nurse, J. R. C. (2019). Cyber security awareness campaigns: Why do they fail to change behaviour? arXiv. https://doi.org/10.48550/arXiv.1901.02672 Fortinet. (2025). 2025 security awareness and training report. https://www.fortinet.com/content/dam/fortinet/assets/reports/report-2025-security-awareness-and-training.pdf Ifinedo, P. (2014). Information security policy compliance: An empirical study of the effects of socialization, influence, and cognition. Information & Management, 51(1), 69–79. Jansen, J., & Van Schaik, P. (2021). Persuading end users to act cautiously online: A systematic literature review. Computers & Security, 108, 102372. Parsons, K., Calic, D., Pattinson, M., Butavicius, M., McCormac, A., & Zwaans, T. (2017). The human aspects of information security questionnaire (HAIS Q): Two further validation studies. Computers & Security, 66, 40–51.