Security awareness training in India is mostly a compliance artefact: an annual module, a completion certificate, and no measurable change in what anyone does. It satisfies an auditor and it does not survive contact with a convincing email on a Friday afternoon.
Training changes behaviour when it is specific to the person's job, short enough to be absorbed, practised rather than watched, and reinforced through the year rather than delivered once. A developer needs different content from an accounts payable clerk, who needs different content from an executive whose identity gets impersonated.
We assess where the gaps actually are, build a role-specific programme, run interactive sessions rather than slide decks, and measure whether behaviour moved, using phishing simulation as the instrument. The completion certificate still gets issued; it is a by-product rather than the objective.