Technology
Trending

While External Threats Are Driving Security Awareness, Internal Risks Are Growing 

By Melonia Da Gama, Director of Training and Learning Programs at Fortinet.  

External threats remain among the primary reasons organizations invest in security awareness and training. Phishing, ransomware, credential theft, social engineering, and attacks on peer organizations all reinforce the same point: Employee behavior directly affects an organization’s cyber risk. 

According to the Fortinet Training Institute 2025 Security Awareness and Training Global Research Report, 41% of respondents cite external threats as the primary driver for implementing security awareness and training programs. Organizations face a threat landscape shaped by organized cybercrime, ongoing reconnaissance, shorter time-to-exploit, and the growing use of stolen credentials and access paths. These pressures help explain why external threats remain the top motivator for cybersecurity training in 2025. 

But organizations increasingly recognize that workforce risk no longer begins and ends with external attackers. 

Cyber risk now moves through everyday employee workflows, data-handling practices, cloud applications, collaboration platforms, and AI tools. As digital environments become more interconnected, organizations are shifting their focus to the operational behaviors that can unintentionally expose sensitive information or create exploitable gaps. The result is a broader understanding of workforce risk, one that extends beyond phishing awareness. 

Internal Risk Is Becoming Harder to Ignore 

The 2025 findings show that 27% of survey respondents have adopted security awareness and training to protect against insider risks, up from 4% in 2024. The addition of new insider risk options in the 2025 survey may account for some of that increase, but the shift also reflects a growing recognition that internal exposure now accounts for a larger share of organizational cyber risk. 

Most insider-related incidents are not driven by malicious intent. They often stem from routine workplace actions: mishandling sensitive data, using unapproved applications, sharing information via unauthorized tools, reusing credentials, or falling for increasingly sophisticated social engineering attempts. 

This concern aligns with findings from Fortinet’s 2026 Cybersecurity Skills Gap Global Research Report, which found that more than half of respondents reported breaches caused by insufficient cybersecurity awareness. That finding underscores why internal risk is receiving more attention. Many breaches still stem from human decisions, such as clicking malicious links, mishandling data, reusing credentials, or using unapproved tools. 

The issue is not employee intent but the growing complexity of modern digital workflows. Employees frequently switch between systems, data, and external services. Cloud apps, remote work, collaboration platforms, personal devices, and generative AI have increased the number of points at which sensitive information can be mishandled or exposed. As digital workflows expand, the risk of accidental exposure rises. 

Security awareness programs can no longer focus solely on identifying obvious scams or suspicious emails. Training must equip employees to navigate risk in their everyday work activities. 

Data Security Has Become the Behavioral Battleground 

This heightened emphasis on internal risk is reflected in the topics organizations consider most important. In 2025, data security was the top focus for awareness and training, cited by 51% of respondents. Data privacy ranked second at 43%, and AI-based tools and threats ranked third at 41%. 

Training activity largely reflects those priorities. In the past year, 50% of organizations provided employee training on data security, 43% on data privacy, and 42% on AI tools and threats. 

This alignment is important because data security is where security policy translates into employee behavior. Data security and privacy shape daily decisions about where information is stored, who has access, which applications are approved, and what information can be shared externally. Employees therefore need practical guidance for moments when risk arises, not just reminders to protect sensitive information. 

Practical guidance matters in everyday workplace situations: uploading a document, approving access, using a collaboration tool, responding to a request, or deciding whether to enter information into an AI prompt. These are the moments when employees can reduce risk, but only if they understand what secure action looks like. 

AI Accelerates Internal Exposure Risk 

AI adds another layer of complexity to internal exposure. Employees use AI tools to summarize documents, generate content, analyze data, write code, and support customer interactions. These tools can boost productivity, but they also create new pathways for sensitive information to leave approved workflows. 

An employee may use an unapproved AI tool because it seems convenient. Another may paste internal data into a prompt without recognizing the risk of exposure. Still others may assume that AI-generated summaries, recommendations, or code are reliable without sufficient review. As AI becomes more integrated into everyday work, these risks become increasingly difficult to manage through policy alone. 

Organizations need training that helps employees understand both how to use AI safely and how attackers may exploit AI to enhance phishing, impersonation, and social engineering attacks. Employees should know which tools are approved, what data can be shared, when outputs require human review, and when additional guidance is needed. 

As AI adoption grows, security awareness programs must address both sides of the challenge: enabling employees to use AI responsibly while helping them recognize AI-enabled threats that are increasingly difficult to detect. 

Training Must Evolve from Awareness to Operational Decision-Making 

Security awareness training is often framed as a compliance requirement, but the 2025 findings point to a more practical role. Training helps organizations reduce risk across the workforce by equipping employees with the knowledge and habits to make safer decisions. 

Employees still need to understand external threats, but they also need guidance on internal actions that increase risk. That includes safeguarding sensitive data, reporting suspicious activity, using AI tools responsibly, adhering to access policies, and recognizing when a routine request may be unusual. 

The research also shows that employee and leadership support remain strong. Eighty-eight percent of employees view security awareness and training positively, while 95% of corporate leaders support it to some degree. This support provides organizations with a strong foundation to build on. The next step is to ensure that training keeps pace with the risks employees face. 

Organizations Need Scalable Behavior-First Readiness 

Even when organizations recognize the value of security awareness training, implementation can be challenging. According to the 2025 report, personnel limitations were the primary barrier to earlier adoption, with 34% of respondents citing them as the reason for delayed implementation. Budget constraints were the next most common obstacle at 19%, followed by competing security priorities at 18%. 

These obstacles are understandable. Security teams already manage incident response, compliance, cloud security, vulnerability management, identity controls, and digital transformation initiatives. When teams are short-staffed or pressed for time by urgent operational demands, training can be deprioritized. 

But delaying awareness training can leave an important risk-reduction opportunity untapped. Employees continue to face phishing attempts, suspicious requests, credential theft, unsafe data practices, and emerging AI risks, even when formal training is in place. The key question is whether they are prepared to identify and handle these risks when they arise. 

Organizations need scalable training that reinforces secure behavior over time. That means shorter, more frequent learning experiences; role-specific guidance; practical scenarios; and regular updates as threats, tools, and policies evolve. The goal is to build readiness into how employees work, rather than treating security awareness as a once-a-year exercise. 

The challenge for organizations is no longer simply teaching employees to recognize threats. It is enabling them to make secure decisions across increasingly complex digital workflows. As AI, cloud applications, and collaboration platforms become more deeply embedded in everyday work, security awareness programs must evolve from information delivery to workforce risk management. 

Security Awareness Training Must Address Both External Attacks and Internal Risk 

External threats will continue to drive investment in security awareness and training. At the same time, organizations recognize that cyber risks often stem from routine employee interactions with data, applications, collaboration tools, and AI systems. Consequently, security awareness initiatives need to do more than just teach employees how to recognize attacks. They need to enable employees to make safer decisions in their everyday tasks. 

Fortinet Security Awareness and Training helps organizations address this challenge from both sides. Employees are trained to identify phishing, impersonation, business email compromise, and other common attack methods. They also learn to manage sensitive information properly, use approved tools, adhere to security policies, and respond appropriately to security risks. 

By integrating awareness, simulation, assessment, and role-specific training, organizations can reinforce secure behaviors where they matter most: within everyday workflows. The result is a more educated and resilient workforce that helps reduce risk across users, data, applications, and AI-enabled environments. 

Related Articles

Back to top button

Adblock Detected

Please Turnoff the adblocker!