Keepnet Labs Logo
Menu
HOME > blog > unveiling the evolution of security awareness and the road ahead

Gartner PIPE Framework: Evolution of Security Awareness

A recent reseach made by Gartner titled "Security Awareness Is Dead! Now What?" boldly highlights the limitations of conventional approaches and offers a glimpse into the future of cybersecurity awareness.

Gartner PIPE Framework: Evolution of Security Awareness

At a time when digital threats are evolving as quickly as the technology itself, the concept of traditional security perception is being challenged. Recent research by Gartner titled "Security Awareness Is Dead! Now What?" boldly highlights the limitations of conventional approaches and offers a glimpse into the future of cybersecurity awareness. This article dives into the key takeaways from this research and explores how organizations can adapt to this changing landscape.

What is Gartner's PIPE Framework?

Gartner's PIPE Framework is designed to enhance security behavior and culture programs (SBCPs) by focusing on four key components:

  • Practices: Implementing specific actions and routines that promote secure behaviors among employees.
  • Influences: Identifying and leveraging factors that affect employee behavior, such as organizational culture and peer dynamics.
  • Platforms: Utilizing tools and technologies that support and reinforce secure practices, like security awareness training modules and monitoring systems.
  • Enablers: Providing resources and support mechanisms, including leadership commitment and policy frameworks, to facilitate and sustain security initiatives.

By integrating these elements, organizations can move beyond traditional awareness campaigns to foster a culture where secure behaviors are ingrained and consistently practiced.

42.jpg

The Fallacy of Security Perception

Over the years, security awareness programs have become fundamental in the fight against cyber threats. However, the presentation highlighted a disturbing fact: despite significant investment in security awareness training, breaches by human error remain a leading problem. Surprisingly, 82% of breaches are due to human error, proving that current methods are not as effective as expected

Several important issues contribute to the mismatch of traditional security perceptions:

  • Wrong Metrics: Companies often measure the success of their awareness programs using metrics that don't actually measure changes in employee behavior, such as completion or bounce rates.
  • Lack of Formalization: Some programs lack formalization, leading to inconsistent implementation and reduced efficiency.
  • Lack of Resources: The limited number of dedicated security awareness staff leads to insufficient resources and staff training efforts.

Future of Cybersecurity Awareness

what is the future of cybersecurity.webp

To deal with the shortcomings of traditional security perception, a shift to innovative strategies is imperative. The Gartner research suggested three strategic approaches to prepare for the future:

  1. Security Behavior and Culture Program (SBCP): Besides traditional security awareness training, organizations should consider implementing SBCP. This program targets tangible changes in employee behavior through a multi-dimensional approach.
  2. New Capabilities: Implementing SBCP requires new capabilities, including behavioral science, automation, data integration, multichannel interactions, personalized interactions, and management change.
  3. Metrics Reinvention: Developing new metrics to measure authentic behavioral outcomes is essential. This involves assessing the risk associated with different employee segments and accurately assessing the results of the fraud simulation.

Cultivate Positive Cybersecurity Habits

Traditionally, negative reinforcement has been at the heart of safety awareness initiatives. The Gartner report emphasized the importance of moving to positive incentives such as recognition, gamification, and participation. In addition, the correlation between secure behavior and positive business outcomes demonstrates the tangible value of cybersecurity efforts.

phishing awareness training.png

As one can see from the graphics above, despite 95 of organizations conduct a sort of awareness program but still 70% of employees demonstated insecure behaviour. Hence, the Gartner reseach emphasized the need to go beyond traditional methods and adopt innovative approaches rooted in behavioral science and with quantifiable results. That way, organizations can arm themselves to reduce the risk of human error and establish a more secure digital environment.

Gartner's Proposal For a Secure Future

The presentation concluded with a series of recommendations drawn from Gartner's extensive research:

  1. Shift Away from Tradition: Relying solely on traditional outreach programs may not yield different results. A new approach is needed.
  2. Foster New Capabilities: Creating a safe behavior and culture program requires new capabilities that adapt to a changing context.
  3. Measure What Matters: Developing metrics that accurately measure behavioral outcomes is critical to success.
  4. Simplify Security: Reduces obstacles associated with security controls, making security measures a natural and easy way to work

In-depth Gartner Research

For those wanting to understand the future of security awareness better, Gartner offers several research resources:

  • "Innovation Insight on Security Behavior and Culture Program Capabilities"
  • "Security Awareness Efforts Fall Short! Now What? (Survey Results Analysis)"
  • "Build a Culture of Security Consciousness: Introducing the Gartner PIPE Framework"
  • "Use Behavioral Economics to Influence Security Behavior and Individual Decisions"
  • "Infographic: How to Drive Secure Behavior When Security Awareness Falls Short"

The traditional era of security awareness has come under scrutiny, prompting organizations to redefine their strategy. Businesses are better positioned to meet cybersecurity challenges in an ever-changing digital landscape by applying behavioral science, new capabilities, and results-based metrics. The way forward requires adaptability and innovation, ensuring a safer digital future for all.

Keepnet’s Human Risk Management Platform

Keepnet offers a comprehensive suite of tools designed to address the human element of cybersecurity. Explore their range of products:

Manage Your Human Risk with Expert Guidance!

Navigating the complexities of human risk in cybersecurity can be challenging. Let our experts show you how we can help. Schedule a personalized one-to-one demo call today and take the first step towards a safer, more secure organization.

Editor's Note: This blog was updated on February 6, 2025.

SHARE ON

twitter
linkedin
facebook

Schedule your 30-minute demo now

You'll learn how to:
tickAutomate behaviour-based security awareness training for employees to identify and report threats: phishing, vishing, smishing, quishing, MFA phishing, callback phishing!
tickAutomate phishing analysis by 187x and remove threats from inboxes 48x faster.
tickUse our AI-driven human-centric platform with Autopilot and Self-driving features to efficiently manage human cyber risks.

Frequently Asked Questions

What is the main challenge with traditional security perception?

arrow down

Traditional security awareness programs, despite significant investments, have not effectively reduced breaches due to human error. A staggering 82% of breaches are attributed to human mistakes.

How do companies typically measure the success of their security awareness programs?

arrow down

Many companies use metrics that don't genuinely reflect changes in employee behavior, such as completion or bounce rates.

What are the primary shortcomings of traditional security perceptions?

arrow down

The main issues include using the wrong metrics, a lack of formalization in programs, and insufficient resources and staff training efforts.

What does Gartner's research suggest for the future of cybersecurity awareness?

arrow down

Gartner recommends a shift to innovative strategies like the Security Behavior and Culture Program (SBCP), developing new capabilities rooted in behavioral science, and reinventing metrics to measure authentic behavioral outcomes.

How can organizations cultivate positive cybersecurity habits?

arrow down

Instead of relying on negative reinforcement, organizations should use positive incentives such as recognition, gamification, and participation.

What does the data say about the effectiveness of current awareness programs?

arrow down

Even though 95% of organizations conduct some form of awareness program, 70% of employees still demonstrate insecure behavior.

What are Gartner's key recommendations for a secure future?

arrow down

Gartner advises shifting away from traditional methods, fostering new capabilities, measuring what truly matters, and simplifying security to make it a natural part of work.

How can businesses redefine their cybersecurity strategy?

arrow down

By applying behavioral science, introducing new capabilities, and using results-based metrics, businesses can better address cybersecurity challenges in a dynamic digital landscape.

What tools does Keepnet offer to address human risk in cybersecurity?

arrow down

Keepnet provides a range of products, including Phishing, Vishing, Smishing, and MFA Phishing Simulators, an Awareness Educator, Incident Responder, Threat Sharing, Threat Intelligence, and an Email Threat Simulator.

How can I get expert guidance on managing human risk in cybersecurity?

arrow down

You can schedule a personalized one-to-one demo call with Keepnet's experts to understand how they can assist in navigating the complexities of human risk.