Borrowed, Part 3: Ideas taken from outside security and applied to awareness practice.
Part one of this series covered product design, part two covered memory research. This one goes to marketing, and a decades-old fix for a problem security awareness still hasn't solved: sending the same message to audiences who need completely different things from it.
No marketing team would send the same campaign to two audiences with completely different motivations, risk exposure and daily behaviour, and call it a strategy. Security awareness does this constantly. One phishing simulation, one training module, one set of messaging, sent to finance and engineering and everyone in between, as if a single narrative fits every job function equally well. It doesn't, and treating it as if it does is why so much content lands flat with at least half the audience it's aimed at.
Marketing solved this problem decades ago
Segmentation has a specific origin. Marketing consultant Wendell Smith proposed it in a 1956 paper as an alternative to treating the whole market as one audience, arguing that a mixed, varied market is really a number of smaller, more similar groups once you split it by what actually differentiates people, need, behaviour, risk tolerance, rather than averaging everyone into a single message. The idea won an industry award as the most significant marketing article of that year. Seventy years on, it's still how every marketing team builds a campaign. Security awareness never got the memo.
Security awareness rarely does this. Most programmes segment, if at all, by department name on a spreadsheet rather than by anything that actually changes what content should look like. The result is one invoice fraud simulation sent to a team that's never near an invoice, and one credential harvesting exercise sent to a team that would never fall for it because their day job already trains them to be suspicious of exactly that pattern.
I've built this properly before, and it works. HR gets targeted training on recruitment scams and payroll diversion fraud, the specific patterns that show up in their inbox and nowhere else. Finance gets contract fraud and business email compromise aimed at invoice changes, a completely different attack shape. Same organisation, same overall threat landscape, but a recruiter and an accounts payable clerk are never going to fall for the same email, so there's no reason to train them against it.
Why finance and engineering are not the same audience
Finance teams are targeted with invoice fraud, payment redirection, CEO impersonation asking for an urgent transfer. The attack exploits process and urgency, not technical naivety. The right simulation for finance tests whether someone will pause and verify a payment change through a second channel, not whether they can spot a dodgy link.
Engineering teams are targeted differently. Credential harvesting aimed at source code repositories, fake dependency packages, social engineering through developer tools and platforms like GitHub or package registries. The right simulation here looks nothing like an invoice email. It looks like a fake pull request notification or a spoofed CI/CD alert.
Send the invoice simulation to engineering and it barely registers, because it's not a pattern they encounter. Send the credential harvesting simulation to finance and the same problem applies in reverse. Both teams end up with simulation stats that look fine, and neither team has actually been tested against the thing most likely to catch them out.
Building segments that are actually usable
Full personalisation for every team isn't realistic for most programmes, and it isn't necessary. Marketers rarely go further than a handful of well-built segments, and the same applies here. Three or four groups, built around genuine differences, cover most of what matters:
By risk exposure - Groups handling money, sensitive data, source code or privileged access face different threats than groups that don't. Segment by what an attacker would actually want from that team, not by department name.
By technical fluency - A team that spends all day in ticketing systems and terminal windows will read a phishing attempt differently to a team whose main tool is email and a shared drive. Content pitched at the wrong fluency level either patronises or loses people.
By prior behaviour - Anyone who has clicked, reported well, or shown a pattern over time is a different audience to someone starting from scratch. Reusing the same content regardless of history wastes the people who've already progressed past it.
By day-to-day workflow - What tools does this team actually live in. What would a convincing attack look like inside that workflow specifically, rather than in a generic inbox.
The one campaign, two audiences problem
Anywhere else in a business, sending identical messaging to audiences with opposite needs and calling it strategy would be seen as a failure of basic targeting. In security awareness it's still the default. Building even three or four real segments, based on exposure and workflow rather than org chart labels, does more for engagement than another year of the same simulation sent to everyone at once.
Coming up in Borrowed, Part 4: What SaaS products get right about onboarding that HR gets wrong on a new starter's first day.