Creating Effective Feedback Loops for Stronger Security Culture During Awareness Month
European Cyber Security Month - Feedback loops @channel Last week, we talked about the importance of a full Communications Plan for your Security Awareness Month. After all, security programmes are built to push messages out - training, education, policy updates. What we may not be so good at is listening ๐. That imbalance sits at the centre of security culture work: we measure click rates and completion percentages and call it engagement, but true engagement isn't one-directional ๐. If we want people to believe security is done with them, not to them, we have to value listening as much as broadcasting. Consider the difference between two scenarios:
- 1.
A mandatory module is pushed to all staff telling them about a new process or policy;
- 2.
A question is issued to all staff - โwhat gets in your way when you try to report a security concern?โ
Only the second suggests their experience matters enough to shape what happens next. Employees don't conclude โsecurity cares about usโ because of a well-produced campaign; they conclude it because, at some point, they said something was broken and we fixed it โ . Without that loop, even the best-designed awareness content reads as friction from someone who doesn't care ๐คทโโ๏ธ. The trouble is, one channel can't do this job. ๐ฉโ๐ผExecutives rarely respond to a survey - listening to them means being in the room; ๐งโ๐ญ Operational staff live with legacy technologies that resist changes, so we need to walk the floor, not just email a policy; and ๐งโ๐ผOffice workers leave a trail in help desk tickets and everyday grumbling about workplace process frictions that quietly drive workarounds. Treating all three as one audience is how we lose the connection, and the trust, we're trying to build. Collecting feedback is the easy part. What changes behaviour and creates culture is visibly acting on it. A control adjusted because the factory floor flagged it as unworkable, or a reporting process simplified because people kept giving up halfway through - these are the moments that convert feedback into evidence of care. A feedback loop that goes nowhere is worse than none at all โฏ๏ธ- it teaches people not to bother. If users don't get a valid, personalised response to every suspicious email they report, they'll simply stop. Security culture isn't something a campaign announces into existence. It accumulates as the residue of hundreds of small moments where the organisation either responded to what people told it, or didn't. The key question isn't how to communicate security better - it's how well we listen, and what we're prepared to change because of what we hear ๐. So, during Security Awareness Month, capture the voices, feedback and complaints from each person, and record who said what. Investigate, and circle back with personalised responses and explanations. We may not fix everything, but if people understand how, why and when, that's the basis for trust ๐ซถ.
