No more speedruns: Better security training (with what you have) - Susanna Haavisto
Susanna Haavisto (Customer Education Manager · Hoxhunt)
Disobey 2026 · Main Stage
Overview
In this insightful talk from Disobey, Susanna Haavisto, Customer Education Manager at Hoxhunt, tackles a pervasive challenge in organizational security: the "speedrunning" of cybersecurity awareness training. Drawing a humorous parallel to video game speedruns, Haavisto highlights how many employees rush through mandatory security modules, rendering the training largely ineffective. Her central thesis is that traditional, compliance-first training models fail to drive actual behavior change, leaving organizations vulnerable to human-centric risks.

Key moments
- 0:00 Introduction: Speedrunning cybersecurity training
- 2:00 Why training fails: Compliance-first approach
- 3:15 Understanding human risk and its vulnerabilities
- 5:50 The struggle of security awareness managers
- 7:15 AI amplifies human risk in cyberattacks
- 10:30 Behavior change: Ability, motivation, and triggers
- 12:15 Fixing low engagement: From compliance to value
No more speedruns: Better security training (with what you have)
Speakers: Susanna Haavisto, Customer Education Manager, Hoxhunt
Conference: Disobey
YouTube: https://www.youtube.com/watch?v=s1n1LiXBLCY
Overview
In this insightful talk from Disobey, Susanna Haavisto, Customer Education Manager at Hoxhunt, tackles a pervasive challenge in organizational security: the "speedrunning" of cybersecurity awareness training. Drawing a humorous parallel to video game speedruns, Haavisto highlights how many employees rush through mandatory security modules, rendering the training largely ineffective. Her central thesis is that traditional, compliance-first training models fail to drive actual behavior change, leaving organizations vulnerable to human-centric risks.
Haavisto passionately argues for a fundamental shift in approach, advocating for training that prioritizes education and engagement over mere checkbox compliance. She proposes that by understanding and applying principles from modern behavioral science, organizations can transform their "functional but forgettable" programs into truly impactful initiatives. The talk provides actionable strategies for fostering a security-aware culture, empowering employees with the skills and motivation needed to become an active defense layer against evolving cyber threats, particularly those amplified by artificial intelligence.
The importance of this topic cannot be overstated. As human error and social engineering continue to be primary vectors for breaches, effective security training is no longer a luxury but a critical component of an organization's defense strategy. Haavisto's call to action is to leverage existing resources and adopt a people-centric approach to build lasting security habits, turning employees from potential vulnerabilities into proactive protectors of organizational assets.
Background
▶ Watch: Introduction: Speedrunning cybersecurity training (0:00)
The genesis of the problem, as Haavisto explains, lies in the design philosophy behind most cybersecurity awareness training: it is compliance-first, not education-first. Organizations, understandably, need to meet regulatory requirements and industry standards, which often translates into generic, policy-heavy training modules. While these modules successfully "check the compliance box," they primarily focus on making employees "fluent in policy" rather than equipping them with the practical skills and ingrained behaviors necessary for genuine security. This leads to training that is "good enough" for compliance, but critically "not enough" for driving real behavior change and managing human risk.
Human risk is defined as the vulnerabilities stemming from everyday human decisions and actions. These vulnerabilities can arise from direct targeting by cyberattacks, such as sophisticated social engineering schemes like phishing campaigns, which exploit fundamental human traits like fear, ambition, curiosity, or the desire to help. However, human risk also encompasses unintentional exposures resulting from honest mistakes or simply a lack of awareness, such as employees openly discussing sensitive work matters in public spaces without privacy screens.
Managing human risk traditionally involves a combination of technical controls (e.g., firewalls) and compliance controls, under which security training falls. The responsibility for designing, managing, delivering, and reporting this training often falls to a security awareness manager or, more commonly, someone from the IT or security team who wears it as "just another hat" atop a pile of other duties. These individuals frequently operate with limited resources, caught between the imperative to comply and the struggle to create genuinely effective training. Consequently, many awareness programs remain merely "okay"—functional but ultimately forgettable, failing to instill crucial skills like recognizing phishing red flags.
The urgency of addressing this issue is underscored by current threat landscapes. Haavisto emphasizes that, even looking ahead to 2026, human risk remains one of the leading causes of breaches. The advent of Artificial Intelligence (AI) further exacerbates this, increasing the scale, speed, and credibility of attacks. Phishing, voice phishing, scams, and even deepfakes are becoming increasingly common and believable, often striking when individuals are most vulnerable—stressed, busy, or distracted. This necessitates the development of strong cybersecurity habits and routines that are almost instinctive.
However, changing ingrained habits is notoriously difficult, as evidenced by common struggles with New Year's resolutions. When this inherent human resistance to change is combined with the resource constraints faced by those in charge of security training, the task can seem like a "mission impossible." Haavisto challenges this perception, asserting that organizations likely already possess the foundational elements needed to create engaging, memorable, and behavior-changing training simply by shifting their mindset and approach. She highlights that cybersecurity, despite often being presented in boring, hour-long slideshows, is inherently interesting, full of compelling stories that are often underutilized in training.
Key Findings
▶ Watch: Understanding human risk and its vulnerabilities (3:15)
Susanna Haavisto's talk distills the essence of effective security training into several key findings, rooted in modern behavioral science and practical application. The overarching conclusion is that successful training moves beyond mere knowledge transfer to foster genuine behavior change, which requires a multi-faceted approach.
- Three Key Ingredients for Behavior Change: Haavisto identifies three critical components, according to modern behavioral science, that must be present for individuals to adopt desired behaviors:
- Ability: People must know how to do the thing you want them to do. This goes beyond policy knowledge to practical skills.
- Motivation: People must want to do it. This involves understanding the personal relevance and impact of their actions.
- Trigger: People need a reminder or a nudge to know when to do the right thing. This ensures the behavior is consistently reinforced.
Most current cybersecurity training, Haavisto notes, focuses almost exclusively on policy-related knowledge (ability), often neglecting the crucial elements of motivation and triggers, leading to ineffective outcomes.
- Addressing Low Engagement and Low Reporting Rates: Two common challenges in security awareness programs are low engagement with training modules and low reporting rates of suspicious activities (simulated or real). These issues stem from training that is perceived as repetitive, irrelevant, or disconnected from employees' personal responsibilities. The solution lies in shifting focus from compliance to providing real value to the individual.
- The Power of Relevance and Stories: To boost motivation and engagement, training must be made relevant to employees' everyday lives—both their working roles and their personal lives. Role-based training (e.g., password security for software developers protecting code) and connecting security practices to personal well-being (e.g., protecting family social media accounts from scams like the "hey mom/dad WhatsApp scams") significantly increases buy-in. Furthermore, using compelling stories—whether from recent headline breaches, white-hat hacker successes, or even internal, blameless post-mortems of organizational incidents—makes training memorable and impactful.
- Building Ownership and Recognition: Low reporting rates often indicate a lack of ownership, where employees perceive cybersecurity as solely the IT team's responsibility. Building ownership involves asking employees about their security worries and curiosities, and showing them how their actions have a tangible impact. Rewarding and recognizing desired behaviors, even through simple gestures like a shout-out in a town hall or a custom diploma, significantly reinforces positive actions and builds a culture of shared responsibility.
- Combating the Forgetting Curve with Continuous Microtraining: The forgetting curve, a psychological concept introduced by Hermann Ebbinghaus, demonstrates how quickly people forget newly learned information without reinforcement. Haavisto cites that without reiteration, people forget 70% of information from an annual, hour-long module within 24 hours, and 90% within a week. The key finding here is the necessity of moving from infrequent, long training sessions to a continuous training drip. This involves breaking down longer modules into 2-3 minute microtrainings delivered frequently (ideally 30+ trainings per year, or 2-3 per month). This approach not only makes training easier to fit into busy schedules but also provides the essential "trigger" to keep security topics top-of-mind throughout the year.
In summary, Haavisto's key findings advocate for a paradigm shift: from passive, compliance-driven education to active, people-centric training that leverages behavioral science to build capability, foster motivation, and provide consistent triggers, thereby effectively managing human risk.
Technical Deep Dive
▶ Watch: The struggle of security awareness managers (5:50)
While Susanna Haavisto's talk isn't "technical" in the sense of discussing code vulnerabilities or network protocols, it offers a deep dive into the technicalities of human behavior change within a cybersecurity context. This section will elaborate on the practical, methodological "how-to" of implementing the behavioral science principles she outlines.
The core technical framework for behavior change, as presented, revolves around ensuring individuals have the ability, motivation, and trigger to perform desired security actions. Most traditional training fails because it overemphasizes abstract knowledge (often policy-centric) without addressing the other two crucial elements.
Cultivating Ability Beyond Policy Fluency:
Instead of merely stating policies (e.g., "don't use USB devices"), effective training must teach the practical skills. For instance, a module on password security (an "evergreen topic") should cover not just how to create strong passwords or passphrases, but also why and how to implement multi-factor authentication (MFA). The "technical deep dive" here is in connecting these generic best practices to specific, tangible scenarios. For a team of software developers, the training should emphasize the importance of protecting software development environments to prevent code leaks or product information compromise. This contextualization transforms abstract rules into concrete, actionable steps relevant to their daily workflows and potential impact.
Igniting Motivation Through Relevance and Narrative:
Motivation is arguably the most neglected ingredient. Haavisto proposes several "technical" methods to spark it:
- Personal and Role-Based Relevance:
- Role-based training: Tailoring content to specific job functions. For instance, a finance team might focus on invoice fraud or BEC (Business Email Compromise) scams, while HR might focus on data privacy regulations.
- Personal relevance: Connecting security practices to employees' personal lives. The example of the "hey mom/dad WhatsApp scams" in Finland resonated deeply because it affected employees' loved ones. Teaching password security can extend to protecting personal social media accounts, gaming accounts, or streaming service accounts, making the learned skills directly applicable and valuable outside of work.
- Leveraging Stories:
- External Stories: Utilizing real-world breaches making headlines can provide compelling context. A security team member could share insights into how a breach happened, and more importantly, what lessons can be learned and how to prevent similar incidents internally.
- Internal Stories (Blameless Post-Mortems): One of the most powerful motivators is sharing internal breach experiences. A cybersecurity leader who openly discussed why a breach happened, how it was detected and contained, and crucially, what the organization learned from it—without assigning blame—transformed a negative event into a collective learning opportunity. This builds a narrative of shared responsibility and collective defense, fostering a sense of ownership.
- Fostering Ownership:
- Instead of nagging, "cybersecurity is your job, too," engage employees by asking about their cybersecurity worries or curiosities. This bottom-up approach uncovers genuine concerns and interests, allowing training to address perceived gaps and increase personal investment. The desire to protect loved ones is a powerful motivator for ownership.
Establishing Triggers Through Continuous Reinforcement:
The "forgetting curve" dictates that infrequent training is ineffective. The technical solution here is a structured, continuous reinforcement mechanism:
- Continuous Training Drip:
- Cadence: Move from annual or semi-annual training to a continuous training drip, ideally 30+ trainings per year (roughly 2-3 per month). This high frequency is critical to keeping security topics "top of mind."
- Microtrainings: To achieve this cadence without overwhelming employees, break down traditional hour-long modules into 2-3 minute microtrainings. This makes training easily digestible and fit into busy schedules without requiring dedicated calendar bookings. Each microtraining serves as a "trigger," reinforcing a specific security concept.
- Strategic Timing:
- Deliver training when it's most relevant. For example, reminders about holiday season scams are far more effective when sent in November or December, just before the holidays, rather than in May. This contextual timing acts as an immediate and relevant trigger.
Reinforcing Desired Behaviors:
Beyond formal training, the talk emphasizes "technical" approaches to reinforce positive actions:
- Involvement and Teaching:
- "One of the best ways to learn something really is to teach it to someone else." Implement a rotating schedule where team members briefly teach a cybersecurity concept in weekly or monthly meetings. This actively engages employees, deepens their understanding, and builds confidence.
- Reward and Recognition:
- Simple, yet powerful, "technical" gestures:
- Public Acknowledgment: Highlight individuals who report the most phishing attempts or real threats in town halls or all-hands meetings. Bonus points if leadership provides a shout-out.
- Tangible Rewards: Gift cards, sweet treats, or even personalized items like a custom diploma and t-shirt for an individual who significantly improved their phishing reporting behavior. The story of the security leader recognizing a click-prone employee who improved illustrates the profound, long-lasting impact of such gestures. This creates positive feedback loops and encourages desired actions.
In essence, Haavisto's "technical deep dive" is a blueprint for integrating behavioral psychology into the operational design of security awareness programs, shifting from a passive knowledge transfer model to an active, engaging, and continuously reinforced system for building a robust human defense layer.
Demo / Proof of Concept
▶ Watch: Behavior change: Ability, motivation, and triggers (10:30)
While Susanna Haavisto's talk did not feature a live software demonstration or a complex technical proof of concept in the traditional sense, she presented a highly practical and actionable "proof of concept" for her proposed behavioral change model. This "demo" illustrated how an organization could transform a single, ineffective traditional training module into a dynamic, multi-format learning experience that incorporates all three ingredients for behavior change: ability, motivation, and triggers.
The example she provided focused on the evergreen topic of password security, which typically might be covered in a generic, hour-long module. Haavisto outlined how to break this down into a series of interconnected, engaging activities:
- Phishing Simulation as a Trigger and Assessment: The first step is to launch a phishing simulation. Specifically, she suggested an "urgent password reset simulation," a common and often successful tactic used by attackers. This serves multiple purposes:
- Trigger: It immediately puts employees in a real-world scenario, creating a sense of urgency and direct relevance.
- Assessment: It measures current susceptibility and identifies individuals who might need more targeted intervention.
- Motivation: For those who fall for it, it provides a tangible, immediate reason to learn. For those who don't, it reinforces good behavior.
- Microtraining Module for Ability and Motivation: Following the simulation, a short microtraining module is deployed. This module specifically covers "how people can recognize the red flags a message like this would contain" – essentially, teaching the practical ability to spot a phishing attempt. By directly linking the training to the recent simulation, motivation is heightened as employees understand the immediate relevance of the information. This addresses the "ability" component by providing concrete knowledge and the "motivation" by demonstrating its practical application.
- Slack or Teams Tip for Reinforcement and Trigger: To further reinforce the learning and provide an additional "trigger," a quick tip is disseminated via internal communication platforms like Slack or Teams. This tip would reiterate "three signs, how can you know that this password reset email is fake?" This bite-sized reinforcement keeps the topic top-of-mind and provides an easily accessible reminder, fulfilling the "trigger" requirement in an unobtrusive way.
- Mini Challenge with Rewards for Motivation and Ownership: Finally, to foster ongoing engagement, motivation, and ownership, a mini challenge is introduced. For example, "all the people who report the fish get a sweet treat at the end of the quarter." This gamified approach provides a clear incentive and recognition for desired behavior, directly addressing the "motivation" component and building a positive association with security actions.
Haavisto emphasized that "all of these different formats of training that now meet the requirements, the ingredients for behavior change, have been created with just a little bit of effort." This "demo" effectively showcased how existing topics and minimal new content creation, when strategically repackaged and delivered, can yield significantly more impactful results than traditional, passive training methods. It illustrates a tangible pathway from a compliance-driven, speedrun culture to an engaged, security-conscious workforce.
Defensive Implications
▶ Watch: Fixing low engagement: From compliance to value (12:15)
The defensive implications of Susanna Haavisto's proposed approach to security training are profound, shifting the paradigm from a reactive, technology-centric defense to a proactive, human-centric security posture. By focusing on behavior change rather than mere compliance, organizations can significantly strengthen their overall security stance and reduce their susceptibility to a wide array of cyber threats.
- Empowering the Human Firewall: The most significant implication is the transformation of employees from potential weakest links into a robust "human firewall." When individuals possess the ability to recognize threats, the motivation to act, and are consistently triggered to apply security best practices, they become an active, intelligent layer of defense. This is particularly crucial against social engineering and phishing campaigns, which bypass technical controls by targeting human psychology.
- Reduced Human Risk and Breach Likelihood: By directly addressing the root causes of human risk—unintentional mistakes, insecure habits, and susceptibility to manipulation—organizations can expect a measurable reduction in incidents stemming from human error. Effective, continuous training that builds practical skills and fosters vigilance directly translates to fewer successful phishing attempts, better password hygiene, and a more cautious approach to suspicious communications, ultimately lowering the likelihood of a breach.
- Proactive Threat Detection and Reporting: A culture that encourages ownership and rewards reporting leads to earlier detection of actual threats. Employees who feel empowered and recognized for reporting suspicious emails or activities become valuable sensors within the organization. This proactive intelligence gathering can allow security teams to identify and mitigate emerging threats more swiftly, before they escalate into significant incidents.
- Enhanced Resilience Against AI-Powered Attacks: With the rise of AI amplifying the scale, speed, and credibility of attacks (e.g., deepfakes, advanced voice phishing, hyper-realistic scams), human vigilance becomes even more critical. Traditional training struggles against these sophisticated threats. Haavisto's model, with its emphasis on continuous, relevant, and habit-forming education, prepares employees to identify the subtle cues of increasingly convincing AI-generated attacks, making them more resilient.
- Building a Strong Security Culture: Beyond specific skills, the approach fosters a pervasive security culture. When cybersecurity is seen as a shared responsibility, relevant to both work and personal lives, and when leaders openly discuss incidents without blame, it cultivates trust and collaboration. This cultural shift means security is embedded into daily operations and decision-making, rather than being an isolated IT function.
- Optimized Resource Allocation: While implementing a continuous training drip requires initial effort, it ultimately optimizes security resource allocation. By making employees more self-reliant and proactive, security teams can potentially reduce the time spent on reactive incident response related to human error, freeing up resources for more advanced threat hunting, architecture review, and strategic initiatives. The investment in effective training becomes a force multiplier for the security team.
- Data-Driven Improvement (Future State): Haavisto briefly mentions that for organizations aiming higher, leveraging behavioral data and threat intelligence with automation can create even more targeted and well-timed training. This implies a future defensive posture where training is dynamically adapted based on real-time threat landscapes and individual employee performance, moving towards a truly adaptive and intelligent human defense system.
In essence, the defensive implications underscore that a truly secure organization cannot rely solely on technical safeguards. By investing in and strategically designing human-centric security training, organizations can cultivate a resilient, aware, and proactive workforce that actively contributes to defense, significantly reducing the attack surface presented by human factors.
Key Takeaways
- Compliance-First Training is Insufficient: Traditional cybersecurity awareness training, designed primarily for compliance, often leads to "speedrunning" by employees and fails to drive genuine behavior change, leaving organizations vulnerable to human risk.
- Behavior Change Requires Ability, Motivation, and Triggers: Effective security training must move beyond mere knowledge transfer. It needs to equip individuals with the practical skills (ability), foster a desire to act securely (motivation), and provide timely reminders (triggers) to apply those skills.
- Relevance and Storytelling Boost Engagement: To increase motivation and engagement, training must be made relevant to employees' specific job roles and personal lives. Using compelling stories, whether from public breaches or internal, blameless post-mortems, makes the content memorable and impactful.
- Foster Ownership and Reward Positive Behaviors: Building a sense of personal responsibility for cybersecurity, by asking about employee concerns and connecting security to their personal well-being, is crucial. Publicly recognizing and rewarding desired security actions (like reporting phishing) reinforces positive habits and builds a stronger security culture.
- Combat the Forgetting Curve with Continuous Microtraining: To overcome the forgetting curve (70-90% of information forgotten within a week for annual training), organizations should adopt a continuous training drip. This involves breaking down longer modules into frequent (e.g., 30+ per year), short (2-3 minute) microtrainings delivered at opportune times.
- Shift to a People-Centric Approach: The ultimate goal is to shift focus from checking compliance boxes to putting people at the center of training design. This active, engaging, and culturally integrated approach builds essential security skills, sparks curiosity, and empowers employees to become an active and effective line of defense against evolving cyber threats.
About the Speaker(s)
Susanna Haavisto is the Customer Education Manager at Hoxhunt, a company specializing in human risk management and security awareness training. She has dedicated her career to understanding and influencing people's decision-making and behavior, a passion she brings to the critical field of cybersecurity. Haavisto is personally very passionate about the concept of human risk and advocates for a proactive, people-centric approach to security education, moving beyond traditional compliance-driven models. Her insights are drawn from extensive experience in driving behavior change and fostering a security-aware culture within organizations.
Reviews
Dr. Zero (Offensive Security Researcher) — WEAK
A vendor education manager from Hoxhunt delivers a polished pitch for behavior-based security awareness training dressed as a conference talk. The content is competent and internally consistent, but it's a repackaged version of arguments the awareness training industry has been making for a decade — Ebbinghaus forgetting curve, microlearning cadence, BJ Fogg-adjacent ability/motivation/trigger framing — with Hoxhunt's product philosophy baked into every prescription.
Heather Calloway (CISO) — SOLID
Haavisto correctly diagnoses a real and persistent failure in security awareness programs — compliance-driven training doesn't produce behavior change — and offers a coherent, behaviorally grounded alternative. The content is practical and well-structured, but it stops at the program manager level and never reaches the governance or institutional accountability questions that make this problem persistent in the first place.