Issue024 7 July 2026

Knowing Was Never The Problem

Amy Stokes-Waters 3 min read

During the course of doing research for my book (yeah, I wrote one, you don’t have to go on about it)… there was a number I found that left me shocked. And it’s one that barely gets mentioned.

96%.

That’s the share of people who took a risky action and knew, as they did it, that it was risky. Not “didn’t realise”. Not “were never told”. Knew. And did it anyway.

So if almost everyone who does the dangerous thing already knew it was dangerous… what exactly is more information supposed to fix?

That’s the question the whole industry has been very politely NOT asking. We’ve built something enormous on a single assumption: that people behave badly because they don’t know better. So we tell them. We test them. We remind them once a year with a module and a deadline and a little green tick at the end. Tick the box. Move on. And then the one number that actually matters, the human element in breaches, went UP last year. 62% now. A year of everyone’s awareness training later… and it went the wrong way.

I’ve sat in enough rooms watching real people make real decisions under real pressure to know why, and it’s got almost nothing to do with what they know. The person who clicks the thing at 4pm on a Friday isn’t missing a fact. They’re tired. They’re behind. The email looks close enough to real, the request feels plausible, and the part of the brain that would have caught it on a calm Tuesday morning has already clocked off. Knowledge was sitting right there the whole time. It just wasn’t driving.

Because under pressure, people don’t rise to the level of their training. They fall to the level of their instinct. And instinct isn’t built by being told things. You can’t read your way to a reflex. You can’t sit through a slideshow and come out the other side with a different gut response at the exact moment one is needed. That’s not how any of it works, and somewhere deep down we all know it… we’ve just been too invested in the dashboards to say it out loud.

So what does build it? That’s the part we don’t really want to make eye contact with, because the honest answer is harder than commissioning another module. It’s experience. Pressure, stakes, consequence, repetition. The same way you build instinct for anything that matters. A pilot doesn’t get briefed on turbulence and then sent up in the air with a plane full of passengers. They rehearse the emergency, over and over, until the right move happens before conscious thought catches up. We accept that everywhere it counts. Everywhere except the one place where 62% of the risk actually lives.

I’m not going to pretend this is an easy thing to say over and over again. It means a lot of what gets sold as security culture isn’t culture at all. It’s activity. Logged, measured, reported upward, and changing almost nothing about the moment that decides everything.

So over the coming weeks I’m going to lay out what does work instead. Properly. One idea at a time. And in a fortnight, we’re gonna stop arguing about it and start showing you some of the stuff we’ve built.

That's it for this week. Reply and tell me what you think.

Amy

Amy Stokes-Waters · Founder, The Cyber Escape Room Co.