Healthcare Cybersecurity Success Kit
This Healthcare Cybersecurity Success Kit is packed with the information, tools, and guidance you need to keep your organization running smoothly and, most importantly, your patients safe.
Joshua Stern, Ph.D. — Joshua Stern Educational Consulting
In cybersecurity, we often imagine the villains as shadowy figures hunched over glowing screens, hammering away at firewalls and ruthlessly stealing passwords. But the truth is both simpler and more unsettling—the “bad guy” doesn’t need to hack into your systems at all. All it takes is someone inside your organization to make a mistake.
Cybersecurity incidents related to the human element rarely stem from malice. They happen because of normal human psychology. For example, people are wired to respond quickly to perceived urgency, especially when a message appears to come from an authority figure when a deadline is looming. In fast-paced environments, the instinct to act fast can trump critical thinking. Likewise, people typically want to be helpful and cooperative; however, these seemingly positive traits are easily exploited with messages that appeal to trust, empathy, or the desire to please. Additionally, many people hesitate to admit when they’re uncertain and hide if they make a mistake. The fear of embarrassment, judgment, or disciplinary action is powerful and can lead well-meaning employees to conceal a mistake or try to fix a problem themselves, which often makes things worse. This combination of psychological triggers—urgency, helpfulness, and shame—can be expertly exploited by bad actors who understand that the softest target in any network is the human mind.
According to the 2025 Verizon Data Breach Investigations Report (Verizon, 2025), nearly 60% of breaches involve the human element: missteps like credential misuse, phishing clicks, or just good old-fashioned human error. Imagine a car manufacturer boasting about its world-class brakes, even though the majority of accidents still happen because drivers press the wrong pedal. That’s where we are with cybersecurity today. Our critical investments in security solutions can be easily circumvented in minutes by an employee's mistake.
Here’s the emotional reality most leaders don’t talk about: when those mistakes happen, employees aren’t just endpoints on a risk chart. They’re people. They’re fallible humans who feel embarrassed, ashamed, even afraid. They replay the pivotal moment over and over in their head, “Why did I click that link!? Why didn’t I notice!?” Meanwhile, the IT team scrambles, frustrated that no matter how many warnings they send out, it seems like the message is never received.
This is precisely why Security Awareness Training (SAT) isn’t optional—it’s essential. Simply put, the goal of SAT is to educate learners in a way that leads to real security outcomes like lowering human risk and reducing the likelihood of security incidents. SAT should lead to lasting behavior change. To accomplish this, you want training that employees actually start (and complete!) and content they truly retain. SAT should catalyze behavior change that improves your security posture and leads to a culture where employees see security as valuable to the business rather than just "that thing IT keeps bugging us about.”
Unfortunately, the traditional SAT that most organizations know falls woefully short. It’s once a year. It’s boring. It’s compliance theater. And it treats employees like checkboxes instead of adults who want to do the right thing. When training feels irrelevant, people tune out, and mistakes keep happening.
Imagine you're sitting at your computer rereading another email from your manager “gently” reminding you to complete your annual security training. You’ve procrastinated and avoided it for weeks now. You fixate on the word “mandatory,” as a feeling of dread rises within you, and you think about all the “real” work you actually need to get done today…
The sad fact is that most SAT feels like a chore. Long lectures. Static content. No follow-up. This kind of training is painfully misaligned with how adults actually learn. We know this because back in the 1970s, a pioneering educational researcher named Malcolm Knowles explained that adults learn differently from children. In contrast to “pedagogy,” which in Greek means “to lead the child,” Knowles introduced his adult learning theory known as “andragogy,” which identified specific principles for educating adult learners (1970; 1973).
Pedagogy assumes that young learners are dependent on the teacher for direction, knowledge, and evaluation. The instructor is the authority who dictates how the learning will occur in a top-down fashion. As you likely remember from grade school, this pedagogical approach typically relies heavily on lecture, rote memorization, and external motivation in the form of grades. Adults, however, aren’t just big children. Knowles made clear that adults require a distinct approach, and his insights remain as true today as they were when he introduced them over 50 years ago:
Self-Direction: Adults crave control over how they learn. They want to understand why they should learn something before investing effort.
Experience: Adults bring a lifetime of experience to their learning, and this experience is a valuable resource to capitalize on.
Relevance: Adults engage most when learning ties directly to real-world challenges and is relevant to their professional or personal lives.
Application: Adults prefer problem-centered approaches and want to learn things that they can apply immediately.
Intrinsic Motivation: Adults are motivated most by internal drivers. Learning should be rewarding, meaningful, and aligned with learners’ values and goals.
Furthermore, many of today’s popular behavioral science models are built on Knowles’ andragogic principles. For example, the Fogg Behavior Model (Fogg, 2009) says behavior occurs when motivation, ability, and a prompt align. Fall short at any one of these points, and change doesn’t happen. Similarly, the ADKAR Model (Hiatt, 2006) tells us that awareness is only the starting point of behavior change. Desire, knowledge, ability, and reinforcement must follow awareness for it to have an impact. Despite this information being readily available, most SAT programs never go beyond awareness—they simply present a bunch of information and stop there. But when it comes to adult learning, the “how” matters just as much as the “what.” When done right, your SATcan be more than informative; it can be transformative.
Now that we know how adults learn best, let’s apply theory to the practice of SAT. Believe it or not, your employees really do want to learn how to keep the company safe. Since SAT is the most direct defense against human error, it follows that you want to provide the very best SAT possible. The good news is that there are evidence-based best practices for doing this. Let’s look at some of them now through the approach taken by Huntress Managed SAT:
When SAT is done right, it doesn’t just change knowledge; it changes culture. Culture is the most powerful security control you have. Tools can fail. Processes can fail. But culture is collective behavior that lasts. Effective SAT isn’t just about compliance; it’s about mindset. I believe that Huntress helps you change behavior and build a culture of security by providing robust, diverse, and customizable training options grounded in adult learning best practices.
In a strong security culture, employees don’t think of security as “that annoying IT checklist.” They think of it as part of their career and their lifestyle. They talk about it in the breakroom. They report suspicious emails without fear. This is how security transcends compliance and becomes resilience.
Let’s be honest. No employee dreams of more training in their lives. Nobody wakes up excited to click through a security module. But when training is designed with respect for adult learners’ preferences, when it’s grounded in real-life experiences, and it’s delivered with mindfulness and creativity, something shifts. Employees lean in instead of hiding, and positive outcomes follow.
So, imagine if you will, SAT that really works. SAT that people actually enjoy. It may sound like a fantasy, but it’s not—it’s a choice. A choice that Huntress makes possible with engaging, story-based episodes, realistic phishing scenarios, immersive threat simulations, just-in-time phishing defense coaching, and behavior-based assignments designed to be fun and memorable. All this while also remaining true to the goal of educating learners about security awareness, promoting more secure behaviors to reduce risk, and improving your organization's overall security posture.
Joshua Stern, Ph.D. — Joshua Stern Educational Consulting
I am an adult learning and online education expert with 25 years of increasingly responsible professional experience in a variety of academic and corporate settings. After receiving my B.A. from the University of California Berkeley, I completed my M.A. and Ph.D. in Education at UCLA. My main area of interest is adult learning (andragogy), specifically as relates to online program design and delivery. My passion for education and belief in the transformative power of online learning have led me to dedicate my career to creating unique and engaging learning experiences for adults around the globe. For the past decade, I have been running Joshua Stern Educational Consulting. On a daily basis, I am fortunate enough to do what I love—helping organizations, large and small, create or improve their educational offerings.
Related Resources