Cultivating Security Awareness
This year, my family harvested over 500 giant onions. Here’s the proof:
.jpeg?width=4031&height=3023&name=Image%20(62).jpeg)
I’d love to take full credit (so would my kids), but it all comes down to my grandparents.
I learned directly from them growing up in Indiana, hands in the dirt and experiencing the weary tedium of weeding from an early age. They taught me how to read the garden as the season unfolded, not just when to plant and water.
One of their best onion tips: when a bulb starts pushing through the soil, it might look ready to harvest, but if you’re going for excellence, it usually pays to wait. Rain can wash dirt away from a growing bulb, exposing it before it finishes developing. The answer isn’t to pull it early. Cover it back up, keep an eye on it, and give it time.
Now I get to pass some of that experience on to my own kids.
Sometimes while I’m gardening, work ticks over in the back of my mind, connecting outdoor dots with desktop ones. This time, it made me think about security awareness.
The most valuable lessons don’t come from a checklist. They come from seeing real-world conditions, recognizing what matters, and helping others make good decisions before a small problem becomes a much bigger one.
The best programs, I think, are cultivated, not downloaded.
Experience helps people read the situation
A gardening blog can tell you the basics of growing onions: planting depth, watering, sunlight parameters. Useful information! But it can’t stand beside you, point to a bulb that looks ready, and explain why you should leave it alone for another few weeks.
That part comes from experience. And security awareness needs that same kind of experience.
Most employees understand the broad ideas behind cybersecurity. The bigger gap is between general knowledge and recognizing a real threat.
A generic cybersecurity course may tell employees to ‘watch for phishing.’ A practitioner-led program can show them what phishing is likely to look like in their department: an invoice-change request sent to finance, a fake password-reset message directed at a remote employee, or an urgent request that appears to come from a senior executive.
Practitioners bring perspective from real environments, incidents, and people making decisions under pressure. They turn “be careful” into concrete guidance employees can use when something doesn’t look quite right.
Same seed. Different soil. (See how this parallel grew? Very fruitful! Or… vegetal??)
Don’t mistake early signs for the final result
It’s true: we could’ve harvested our onions a month earlier. We still would’ve had 500 completely usable onions.
But they wouldn’t have been as big. And they wouldn’t have been as sweet.
Letting them mature gave us more of what we were hoping to grow.
Security awareness programs can be “harvested early,” too.
A completion dashboard may look great. Employees may pass a quiz. A phishing simulation may show improvement. Those are positive signs, and they should be measured. But they aren’t the full result.
The stronger question is whether people are developing habits they can use in the moment:
- Do they know how to report a suspicious message?
- Do they pause to verify an unusual request before acting?
- Do they feel comfortable asking for help when something seems off?
Those behaviors take time and reinforcement. People need realistic examples, an understanding of why the right action matters, and confidence to participate.
A training program can produce completions quickly. A security culture takes longer to grow.
So…
Build for the garden you have
A growing plan that works in one garden may not work in another. Soil, sunlight, weather, space, and what you’re hoping to grow all matter. If you want melons and green beans, you wouldn’t follow advice for growing giant sunflowers.
Security awareness is like that, too.
A healthcare organization, a manufacturer, and a professional-services firm may all face similar risks. But their employees make different decisions, use different systems, and encounter different pressures.
A finance team may need guidance on validating payment-change requests. Employees with access to sensitive client information may need scenarios focused on data handling and impersonation. A distributed team may benefit from training tied to collaboration tools and remote work routines.
That’s why practitioner-led awareness is more valuable than a one-size-fits-all content library. Practitioners can connect training directly to the risks employees are most likely to face rather than treating every security message as equally relevant to everyone.
The best program gives people useful information at the right moment, in a form that makes sense for their work.
Pass the experience forward
One of my favorite parts of this year’s planting, weeding, and harvesting has been my kids’ involvement. They’ve learned a lot about what it can mean to “touch grass.”
They got their hands dirty, asked questions, helped with the work, and saw the payoff at harvest. Maybe they’ll remember the onions. More importantly, I hope they’ll remember the value of learning from people who’ve done it before.
That’s what a strong awareness program can do inside an organization: pass practical experience from security practitioners to employees in a way that builds confidence and helps people recognize when something isn’t right and know what to do next.
Those lessons are useful at work and at home. The instinct to verify an unexpected request can prevent a fraudulent invoice payment, but it can also help someone avoid a convincing package-delivery scam text message.
Cybersecurity awareness doesn’t have to be grim, generic, or limited to an annual compliance task. It can be relevant, useful, and human.
My grandparents taught me how to grow big onions. Now I get to share that knowledge with my kids.
In cybersecurity, we have a similar opportunity: use real-world experience to help people build safer habits, then give those habits time to grow.
That’s a harvest worth cultivating.
PS - we also filled the freezer with sweet corn!
.jpeg?width=4031&height=3023&name=Image%20(63).jpeg)
Michael Milroy