By 2027, 50% of cybersecurity organizations will replace “individual awareness” in their secure behavior and culture program with a focus on “group norms for behavior,” in recognition of the lack of connection between awareness and secure behavior.

Legacy approaches delivering curriculum-based, awareness-centric programs are no longer effective. By 2030, all widely adopted cybersecurity control frameworks will focus on measurable behavior change rather than compliance-based training as the critical measure of efficacy for human risk management.

Cybersecurity leaders must embrace a human-centric approach rooted in UX, behavioral sciences and related disciplines to drive secure, risk-informed decision making.