By Roberto Marzocca, Head of Cybersecurity di Kirey
For a long time, the cybersecurity sector has argued that people represent the weakest link in the chain, repeatedly stating that training is the only real solution to “human liability.”
Even today, the data confirms this: according to the Verizon DBIR 2025, 68% of incidents/breaches analyzed involve a human element (phishing, social engineering, errors, credential abuse), demonstrating that the vulnerable surface is not only technological but also significantly involves the human cognitive and behavioral sphere.
For over twenty years, cybersecurity awareness has therefore sought to teach people to recognize warning signs. This approach has resulted in a vast ecosystem of training programs, based on periodic assessments (often annual or monthly), and integrated training sessions, typically triggered after failing a phishing test.
But if phishing, which emerged in the second half of the 1990s, took nearly twenty years to become one of the dominant cyberattack techniques, following the mass adoption of email, today the IT innovation cycle is measured in weeks, sometimes days, and with it, the threat landscape evolves as well.
For this reason, we must ask ourselves whether training should not also evolve, moving from simple awareness to the development of the ability to make conscious decisions.
From awareness to decision making: the paradigm shift
With the arrival of artificial intelligence, the very concept of human error is changing. It is no longer just about clicking the wrong link, but about interacting with systems that can be influenced or manipulated.
Not by chance, the OWASP Foundation classified Prompt Injection (which allows malicious instructions to be “injected” into emails, PDFs, or web pages read by AI, leading it to bypass rules, prioritize incorrectly, and retrieve content from untrusted sources) as the number one vulnerability of LLM-based applications already in the first Top 10 of 2023, and confirmed it in the 2025 update.
The adoption curve of these AI-based techniques is impressive and has found an incredibly fertile ground in the phenomenon of Shadow AI, namely the growing adoption of AI tools by employees, often unauthorized, unsupervised, and not integrated into corporate security controls.
This is where a new gray area has opened for cybersecurity: conversations and documents may leave controlled perimeters, while operational decisions are accelerated by automatic suggestions that are not always verifiable.
People today must learn not only to use AI but to critically supervise it, and for this reason, the old training assumption is beginning to clearly show its limitations.
Phishing emails can be perfectly written, free of grammatical errors, and highly personalized. Calls can use voice cloning. Documents can be generated in a style consistent with corporate communications.
The question that cybersecurity training must therefore pose to its audience must evolve accordingly: not only “Can you recognize an attack?” but “Can you make safe decisions when you do not have enough information?” A paradigm shift that requires reflection both in terms of personalization of training content, and of timing and engagement methods.
- Adapting content: moving from generalist to personalized
In a rapidly changing context such as today’s, delivering the right training to the right person at the right time can make all the difference.
A CFO faces risks and potential damages linked to breaches of their role that are very different from those faced by HR, just as a metallurgical company has a different risk profile compared to a financial institution, and every organization has unique tools and processes compared to others.From this perspective, the first step cybersecurity awareness should take is to replace the “one-size-fits-all” approach with personalization, and in this regard, AI can prove to be a formidable ally.
- Training must become continuous, contextual and experiential
Although current training programs (instructor-led training, remote training with predefined content, and so on) have long been a fundamental strategy, research is increasingly moving toward new training models.
Some are strongly experiential, such as escape rooms, and they work because they transform cybersecurity from passive knowledge into a decision-making experience under stress, leveraging engagement and immediate learning, and showing measurable effects on knowledge and attitude. Others, supported by GenAI, automatically personalize content, offering decisive features such as micro-learning, real-time coaching, personalized simulations, and immediate feedback.
Thanks to AI, instead of receiving a one-hour course every twelve months, an employee can receive a thirty-second suggestion exactly when they are about to share a sensitive file, enabling a learning logic that shifts from just-in-case to just-in-time.
- Measuring behaviour, not completion
Finally, while historically many companies have used KPIs such as course completion rates, training hours, and final quizzes, it has also been repeatedly shown that cybersecurity training programs do not prevent employees from falling victim to phishing scams.
To bring cybersecurity awareness into the real field of resilience, attention must shift toward behavioral metrics such as phishing reporting speed, error frequency, correct use of tools, reduction of risky behaviors, and quality of decisions.
In this way, cybersecurity awareness becomes a discipline of behavior change, closer to behavioral psychology than to traditional training, further highlighting how AI does not eliminate the human factor in security but changes its role.
If previously people were mainly asked not to make mistakes, today they are asked to make correct decisions in collaboration with intelligent systems. True organizational resilience will therefore depend not only on the quality of algorithms but on the quality of the relationship between people, processes, and AI.
