Issue021 16 June 2026

The L&D Blindspot

Amy Stokes-Waters 4 Minute Read

Ask ten organisations how their security team and their learning team work together and you’ll get ten different answers… which is a polite way of saying you’ll get no real answer at all.

I’ve sat with countless companies talking about training. In some orgs, the head of learning is in the room from the first conversation, shaping how the whole thing lands before a single decision gets made. In others, security defers to L&D entirely… nothing reaches an employee without going through them. Their templates. Their calendar. Their sign-off. And in plenty of places? The two functions have simply never met on this. The phishing programme gets built, the modules get commissioned, the completion rates get reported upward, and the people whose entire profession is behaviour change find out the way everyone else does. From the email telling them to complete it by Friday.

What’s strange isn’t that any one of these models exists. It’s that they ALL exist, side by side, across organisations that are otherwise trying to do exactly the same thing. No agreed answer. No default. No sense anywhere that one of these arrangements is right and the others are accidents.

So think about what that actually means. The relationship between the people who own security risk and the people who own behaviour change has been left almost entirely to chance. To personality. To who happened to know who. To whether someone three years ago thought to send an invite.

And it matters, because these two functions are circling the exact same problem from opposite directions.

Security understands the risk. They know what the threats are, how attackers work, where the organisation is exposed. What they’ve rarely been trained to do is change what thousands of people actually do, day to day… which is a discipline in its own right, with decades of evidence behind it. L&D (in the main) has that bit covered. They know about the forgetting curve and spaced repetition and the difference between telling someone a thing and getting them to live it. What they often lack is the security context to know which behaviours are even worth the effort.

So each team holds half of what the problem needs. And whether those halves ever come together is, in a lot of companies, a coin toss.

You can see the consequences in the output. Where the collaboration is real, security awareness stops looking like security awareness. It starts looking like learning… designed for how memory actually works, built around participation rather than completion, woven into how people are onboarded and managed rather than bolted on once a year. And where the collaboration never happened? You get exactly what you’d expect. Technically accurate content that nobody remembers, delivered in the one format L&D would have talked them out of… if anyone had thought to ask.

Now, the point here isn’t that L&D should always lead, or that security should hand over the keys. There’s no universal model and I’m not going to pretend there is one. Defer everything to L&D and you can end up just as stuck, turning your whole security culture into whatever happens to fit the existing programme. That’s not collaboration…. that’s surrender with a content calendar.

The point is that almost nobody made the decision deliberately. They’ve got a relationship between two critical functions that was never designed… only inherited. And then they’re surprised when the results are all over the place.

So this is less a recommendation than a question worth actually just thinking about, I guess. Not whether your security and learning teams TALK… but whether anyone has ever decided what that relationship is actually for. Does L&D shape the behaviour, or just host the content? Does security set the risk and then get out of the way, or stay in the room for the part it was never trained to do?

The organisations building real culture aren’t the ones who got lucky with the org chart. They’re the ones who looked at this relationship and CHOSE what it should be… instead of leaving it as the one piece of the whole system that nobody ever bothered to define.

That's it for this week. Reply and tell me what you think.

Amy

Amy Stokes-Waters · Founder, The Cyber Escape Room Co.