From compliance to behavioural risk mitigation: A strategic framework for security awareness transformation
Abstract
Traditional security awareness programmes rely on annual training, phishing simulations, and engagement campaigns. These approaches generate activity and compliance metrics, but they do not effectively reduce human-driven security risk. This paper presents a strategic framework for shifting from campaign-based security awareness to behavioural risk mitigation, grounded in a decade of leading security awareness across one of the USA’s largest and most complex higher education systems. The framework addresses what prompted the shift, what analysis revealed about the limitations of traditional approaches, how buy-in was built to pivot toward behavioural risk mitigation, and what security leaders should consider when implementing similar transformations. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
The full article is available to subscribers to the journal.
Author's Biography
Cecelia Finney, SSAP, has more than 20 years’ experience in risk management and security. As Program Director of Systemwide Security Awareness and Human Risk Management at the University of California, she leads strategy across 10 campuses and 6 health systems, supporting more than 300,000 students and 265,000 employees. Her background in IT audit and internal controls, developed over nearly a decade at Verizon, informs her risk-based approach to security awareness. She has also served on the SANS Security Awareness Summit advisory board. Cecelia is the founder and principal advisor of Cecelia Finney Advisory, where she works with organisations to strengthen human risk management programmes and align security awareness with measurable risk reduction.