why-security-training-fails-and-how-to-fix-it

Greater Connectivity Should Not Lead to Greater Risk

Workplace technology is naturally becoming more connected. Devices report telemetry, platforms sync data across locations, and cloud services link together to automate everyday tasks. That connectivity brings genuine productivity gains from faster collaboration and better visibility to smoother experiences for employees and customers.


It also creates a simple trade-off that many organisations are only now confronting - every new connection expands your attack surface, and every additional supplier or cloud dependency increases the number of places security can fail. The answer isn’t panic, and it isn’t buying yet another tool. The answer is building proportionate governance, risk and compliance (GRC) that matches how your organisation operates.


Connectivity increases capability, and exposure
The modern workplace runs on ecosystems - endpoints connect to identity platforms, apps connect to other apps, and third parties connect into your environment through integrations, support access, or shared data flows.


What this means is risk doesn’t just sit inside IT anymore, it spreads across:


•    Devices (laptops, mobiles, printers, meeting rooms, IoT and smart building tech)
•    Cloud services and SaaS (where configuration and access are often the real vulnerabilities)
•    Suppliers and partners (who may hold your data, connect to your systems, or influence your resilience)
•    Users (who are asked to make more security decisions, more often, in more tools)


As attacker automation and AI accelerate the speed of discovery, highlighted by debates around Anthropic’s reported “Claude Mythos” capability, the organisations most exposed won’t necessarily be facing superhuman hacks. They’ll be the ones with unclear ownership, patching delays, blind spots in their supplier estate, and response plans that aren’t operationalised.

The fix isn’t more tools
When security programmes struggle, it’s rarely because teams don’t know what good looks like. It’s usually comes down to control ownership being fragmented, decision-making being inconsistent, and risk being discussed in technical terms rather than business impact.


A proportionate GRC approach focuses on three fundamentals:


1.    Clear ownership: who is accountable, and for what?
Connectivity creates shared responsibility. If nobody has end-to-end control, it degrades over time.
For most organisations, the immediate win is defining ownership for the basics:
•    Who owns patching across endpoints, servers, network devices and cloud services?
•    What’s the SLA for critical updates, and how are exceptions approved and reviewed?
•    What’s the process for legacy systems that can’t be patched quickly?
•    Who owns identity and access, including privileged access and joiner/mover/leaver hygiene?


Clarity matters, but so does automation. Wherever possible, patching and configuration should be enforced through policy and managed platforms, so you’re not relying on individuals clicking ‘update’ at a convenient moment and leaving avoidable windows of exposure.


2.    Visibility: you can’t protect what you can’t see
As environments become more connected, visibility becomes the foundation of sensible risk decisions. That includes:
•    Knowing what assets you have (including shadow IT and unmanaged endpoints)
•    Understanding what is connected to what (integrations, APIs, admin access paths)
•    Maintaining an accurate view of where data lives and who can access it
•    Monitoring for early signs of compromise, not just preventing it


This is where many organisations get caught out. It’s not always a single big failure, but by a build-up of smaller blind spots that attackers can chain together.


3.    Risk decisions based on business impact
Not every system needs the same controls, not every risk needs to be eliminated, but every material risk should be owned, understood, and treated in a way that aligns with business priorities.


A practical approach is to agree, at leadership level, what matters most:
•    Which systems would stop the business operating if disrupted?
•    Which data would create regulatory or reputational damage if exposed?
•    Which suppliers or cloud services would be hardest to replace quickly?


Once those are defined, security investment becomes more rational: fewer checkbox activities and more focus on the controls that reduce likelihood and limit impact.

Pair strong controls with a culture that enables people
Security culture becomes more important as connectivity grows, because employees are interacting with more systems, more prompts, and more decisions. If the culture is blame-led, employees will resort to hiding mistakes. If it’s supportive, employees will feel more comfortable to report issues early, when problems are still containable.


That’s why awareness and training should be treated as a performance enabler. The goal is to build habits that work in real conditions - spotting social engineering, questioning unusual requests, reporting suspicious activity early, and understanding why controls exist.


Sharp research has consistently shown that workplace behaviours and hidden cyber habits can create unintended exposure, often not through malice, but through friction, time pressure and unclear expectations. Fixing that means designing security around how people work, then making the secure path the easy path.

Turning connectivity into resilience
Greater connectivity is how modern organisations now operate. The question is whether your security approach has kept pace.


If your first instinct is to buy another tool, pause. Start by tightening ownership, improving visibility, and making risk decisions based on business impact. Pair that with a culture that supports employees rather than punishing them, and you’ll be far better positioned, whether the next headline is about Mythos, deepfakes, or the next wave of supplier breaches.


If you’d like to strengthen the human side of cyber resilience, explore Sharp’s Security Awareness Training