Why knowledge alone does not protect your organization

#
Awareness Measurement
#
Awareness Kampagnen
#
Awareness Strategy
#
Security Awareness
‍Three people are holding a meeting around a table, with a laptop in the middle

For over two decades, companies have been working to train their employees on information security issues. Phishing simulations, e-learning modules, mandatory annual training—the repertoire has grown, and so have the investments. And yet, in practice, it becomes clear time and again: Security incidents often occur not despite training, but despite knowledge.

What the data shows

Using TreeSolution’s Security Awareness Radar (SAR), a total of 88 organization-wide surveys were conducted between 2004 and 2025, involving over 100,000 participants and approximately 4.5 million individual responses. The result is clear: The domains of "Knowledge" and "Values" are at a comparatively high level across all maturity levels. Even organizations with an “insufficient” security culture score an average of 62 points on a scale of 0 to 100 in the “Knowledge” domain—and as high as 83 points in the “Values” domain.

So what explains the difference between a mediocre and an excellent safety culture? The answer lies in other domains. The largest gaps between “insufficient” and “very good” are found in:

  • Communication: 29 → 68 points (difference: +39)
  • Training (Quality & Integration): 28 → 69 points (difference: +41)
  • Leadership by example: 32 → 63 points (difference: +31)
  • Work and Technology Design: 49 → 76 points (difference: +27)

The paradox of the well-informed organization

Many organizations have created a paradox in which their employees know very well what they should be doing—but still fail to do it consistently in their day-to-day work. The reason: knowledge and behavior are not the same thing. Standing between understanding a safety rule and applying it in daily practice is the organizational reality: unclear processes, a lack of role models, cumbersome reporting channels, and a corporate culture that does not truly prioritize safety.

The consequence: Beyond a certain point, producing more training content yields diminishing returns. Those who want to achieve the next leap in maturity must adjust other levers.

Attention instead of content

The Security Culture Code describes this shift as the transition from knowledge transfer to organizational attention. It’s not about giving employees even more information. It’s about making security visible, manageable, and second nature in everyday life.

In concrete terms, this means: Leaders discuss security incidents in meetings. Security-related processes are integrated into daily work, not added on as an afterthought. Incident reports are used as learning opportunities, not punished. And security regularly appears on the agenda of leadership bodies—not just when something has gone wrong.

Conclusion: training remains necessary—but it is not enough

Training and education form the necessary foundation. They provide basic knowledge, raise awareness, and establish minimum standards. But the real leap forward in maturity only occurs when security culture is understood as a leadership responsibility and becomes part of the organization’s communication and decision-making routines. Anyone who wants to decipher the Security Culture Code must think beyond the logic of training.

You can request the full report on 20 years of SAR and the insights it provides HERE free of charge.

Reach us using our contact form

If you need support write a short description of the problem in the “Message”.

Thank you very much! We will answer your request as soon as possible.
Oops! Something went wrong when submitting the form.

Please contact us directly at info@treesolution.com.
Newsletter

Don't miss any more news about cyber security awareness and get tips and tricks for employee training in your company.

Thank you for subscribing to our newsletter.
Something went wrong when submitting the form.

Related blog articles

#
Awareness Measurement
#
Information Security
#
Security Awareness
#
Awareness Strategy

The glass ceiling of security culture—and how to break through it

#
Awareness Strategy
#
Security Awareness
#
Information Security
#
Cyber Security

What are the real benefits of security awareness and how to demonstrate the ROI of prevention

#
Trends
#
Cyber Security
#
Awareness Kampagnen
#
Security Awareness

Phishing 2025: How modern social engineering attacks work—and how to spot them

Umschlagsymbol

Form, E-mail, Phone

You can fill out a short form or send us an email. We will get back to you within two working days. You can also call us directly. Click on "Contact" and you will receive all the necessary contact details.

Kalendersymbol

Free online consultation

If you would prefer to book a specific appointment, you can do so by clicking on the blue button below. The online booking system will open in a new window and you can schedule your free consultation.