A Single Partner for Everything You Need With more than 450 technology partners in its ecosystem, Optiv provides clients with best-in-class security technology and solutions that equip organizations to detect and manage cyber threats effectively and efficiently in today's growing attack surface. Optiv's Partner of the Year Awards recognize forward-thinking innovation, performance and growth, and unparalleled technology solutions.
We Are Optiv Security Greatness is every team working toward a common goal. Winning in spite of cyber threats and overcoming challenges in spite of them. It’s building for a future that only you can create or simply coming home in time for dinner. However you define greatness, Optiv is in your corner. We manage cyber risk so you can secure your full potential.
Closing the Gap During Cybersecurity Awareness Month: Aligning Perceived and Actual Human Risk Breadcrumb Home Insights Blog Closing the Gap During Cybersecurity Awareness Month: Aligning Perceived and Actual Human Risk September 28, 2025 Each October, Cybersecurity Awareness Month gives security awareness leaders an opportunity to assess the human risk landscape within their organizations. Cybersecurity awareness has improved in recent years. More organizations provide employee training, conduct phishing simulations and promote security best practices. User-friendly tools and greater public awareness have also made it easier for employees to recognize suspicious activity and protect organizational data. But 2026 has changed the equation. Generative and agentic AI are now in the hands of both attackers creating personalized lures and synthetic media, and employees using AI assistants and agents in their daily work. A persistent gap remains between the perception and reality of human risk, and AI is widening faster than many awareness programs are evolving. Perceived Human Risk vs. Actual Human Risk in CybersecurityHuman risk is the potential for employees to compromise security by falling for phishing scams, using weak passwords, mishandling sensitive data, ignoring protocols or misusing technology. Today, it also includes how employees use AI: what they enter into an assistant, how much they trust an agent’s output and whether they recognize inappropriate automated behavior. The human risk gap is the difference between the risk organizations believe employees pose and the risk they actually pose. The Verizon 2026 Data Breach Investigations Report analyzed more than 31,000 security incidents and 22,000 confirmed breaches across 145 countries. It found that the human element was present in 62% of confirmed breaches, up from 60% the previous year. That figure has remained above 60% across four consecutive reports. Two findings in the report should reshape awareness programs. First, exploitation of software vulnerabilities has overtaken credential abuse as the leading initial access vector, meaning human risk cannot be evaluated separately from patching and asset hygiene. Second, generative AI is now bolstering attack techniques across the kill chain, and mobile devices draw materially higher click rates than email. This has attackers moving to a channel most awareness programs still don’t simulate. Overconfidence can leave significant vulnerabilities unaddressed. Training often becomes a predictable checkbox rather than preparation for evolving threats. For example, phishing simulations may still teach employees to spot spelling mistakes and awkward grammar, signals AI-assisted attackers can easily eliminate. A workforce trained against older tactics may achieve a high simulation pass rate and still be unprepared for what reaches their inbox. The Leadership Disconnect in Cybersecurity AwarenessA primary contributor to the human risk gap is insufficient leadership prioritization. The 2025 Cybersecurity Threat and Risk Management Report from Ponemon Institute and Optiv surveyed 620 IT and cybersecurity professionals about industry trends, investments and risk-management priorities. Among respondents whose organizations were changing cybersecurity budgets, 71% reported increases, bringing the average budget to $24 million. Yet incidents continued to rise: 66% said cybersecurity incidents increased in the previous year, up from 61% the year before. As investments grow, security leaders should examine how much of that funding directly addresses the human layer. Leaders set the tone for security culture. Without a strong mandate from the top, awareness initiatives can lose momentum even when organizations invest in supporting technologies and services. The Upskilling and Reskilling Gap Is a Security Awareness ProblemThe most consequential gap in 2026 is not only awareness. It is skills. The World Economic Forum’s Future of Jobs Report 2025 projects that approximately 59% of the global workforce will require reskilling or upskilling by 2030, and 85% of employers plan to reskill existing employees. AI literacy, analytical thinking, creative thinking and resilience are among the skills expected to grow in importance. These capabilities affect security behavior. They can determine whether an employee recognizes a synthetic voice during a payment call, questions an AI-generated response or escalates an agent that is behaving unexpectedly. Security awareness is therefore no longer an isolated annual compliance obligation. It is part of workforce development. Employees need AI literacy as a security control, including knowing what data should never enter a prompt, how to verify AI-generated output and when to escalate or override an automated action. The U.S. Department of Labor’s AI Literacy Framework and the NIST NICE Workforce Framework for Cybersecurity provide structures organizations can use to define these expectations. Enterprises should plan awareness and upskilling together. They must understand what employees can do, identify gaps against emerging threats and invest accordingly. Upskilling security analysts on agentic operations while training the broader workforce only on legacy phishing tactics relocates human risk rather than reducing it. Steering Cultural ChangeIt’s proven that organizations with a strong security culture experience fewer incidents and faster recovery times when breaches do occur. To close the gap, it is the responsibility of security awareness training leaders to drive a cultural shift in your organization. Here’s how: Leadership CommitmentLeaders should visibly advocate for end-user cybersecurity. Security awareness leaders can build support by connecting initiatives to business objectives, presenting meaningful risk data and sharing relevant examples of human risk. Continuous Real-World SimulationsSimulations should reflect current threats and channels, including AI-generated lures, synthetic voice and video, AI-assisted business email compromise and mobile attacks. Programs should evaluate how simulations are delivered, measured and addressed, with an emphasis on reinforcing positive security behaviors. Build In AI LiteracyGive employees practical guidance about what they may share with AI systems, how to validate AI-generated output and how to respond when an automated workflow behaves unexpectedly. Clearly define the human role in observing, questioning and reporting automated activity. Expand Avenues to AwarenessTreat education as an ongoing effort rather than an annual event. Integrate awareness into organizational communication channels and offer varied learning experiences, such as interactive e-learning, workshops and personalized training paths. Open Communication and Employee EmpowermentCreate an environment where employees can report mistakes and suspicious activity without fear, including inappropriate data sharing or actions based on synthetic communications. Invite feedback, provide clear guidance, make secure behavior easy and recognize employees who demonstrate strong cybersecurity habits. Closing the GapCybersecurity Awareness Month offers a timely opportunity to move from awareness to measurable action. By strengthening leadership engagement, modernizing simulations, building AI literacy, expanding learning opportunities and simplifying secure behavior, organizations can better close the gap between perceived and actual human risk. Cybersecurity remains a collective effort that requires continued commitment. Use Cybersecurity Awareness Month as a turning point for building the skills, behaviors and culture needed to address today’s human risk. Want to learn more about creating a cybersecurity education and awareness program tailored to your organization? Reach out to our experts. By: Holly Fuemmeler Manager of Cybersecurity Education | Optiv Share: Cybersecurity Awareness Cybersecurity Awareness Month Cybersecurity Cybersecurity Training Cyber Risk Management