Search
Close this search box

Why do security reports spike only after we send out a training reminder?

shares

Every FSO knows the pattern: You send out a quick refresher on reporting foreign travel or suspicious contacts, and suddenly your inbox explodes with reports.

It’s easy to get frustrated and ask, “Why didn’t they report this weeks ago?”

But the reality isn’t that employees don’t care. It’s that they are focused on their primary mission, whether that’s engineering, project management, or software development. Security isn’t their default baseline; it’s a layer on top of it.

When we send a reminder, we aren’t just giving information. We are providing the cognitive trigger that shifts security from their long-term memory into their active working memory.

If you want to close the gap between the reminder and the report, we have to do two things:

  • Lower the friction: Make the reporting process so simple that it takes less than 60 seconds. If it’s hard to find the form, people will procrastinate.
  • Normalize the cadence: Instead of annual or quarterly info-dumps, use micro-reminders. Keep the trigger active.

To my fellow security professionals: The post-training spike isn’t a failure of your program. It’s proof that your communication is working.

How do you keep security at the forefront of your team’s mind without causing “reminder fatigue”?