Breach fatigue: Why your team has switched off and how to fix it

Breach fatigue blog banner

Cybersecurity continues to face continued challenges in the Australian environment. The Australian Signals Directorate’s (ASD's) Annual Cyber Threat Report 2024–25 revealed that there were more than 84,700 cybercrime incidents and over 42,500 calls to the Australian Cyber Security Hotline, representing a 16% increase in comparison to the previous reporting period. More threats. More notifications. More training events. Yet, surprisingly, employee vigilance is continually decreasing. As such, we have a difficult question to ask ourselves: If the danger posed to our organisation is undeniable, then why do some employees quietly “tune out” security-related issues?

The answer isn’t indifference but rather breach fatigue—a growing psychological desensitisation that occurs when individuals are subjected to excessive volumes of warnings, alerts, and security-related training. The purpose of this article will be to explore what breach fatigue really is, where it is occurring in organisations throughout Australia, and more importantly, what you can do as a leader to build the engagement and vigilance needed to protect your organisation before the next security incident.

Key takeaways  

  • Breach fatigue is a specific form of disengagement, often invisible, that differs from general burnout. It happens when employees are overwhelmed by security alerts and repetitive training.

  • ASD data confirms that the average self-reported cost of cybercrime per report for mid-sized Australian businesses was around $97,200 in 2024–25, making the stakes of disengagement very real.

  • The main drivers of fatigue are alert overload, one-size-fits-all training, and the cry wolf effect—none of which are improved by more training sessions.

  • Effective re-engagement strategies include role-based micro-learning, positive reinforcement, psychological safety, and AI-assisted threat prioritisation.

  • According to the IBM Security Cost of a Data Breach Report 2025, companies leveraging AI and automation saved an average of $1.9 million per breach, making a compelling case for smarter tooling.

What is breach fatigue, and why does it matter?  

Breach fatigue represents the psychological state of being desensitised to security risks. The risks remain present, however, the frequency of alerts, warnings, and security training are becoming repetitive enough to cause employees to filter out security messages as irrelevant. In essence, breach fatigue is similar to a car alarm sounding for 20 minutes. At first the noise draws attention, but after a while, it becomes background noise.

What distinguishes breach fatigue from general workplace burnout is its domain specificity. A person could be actively engaged in all aspects of their job, including productivity and performance. However, that same person may not even consider themselves involved in terms of their company's cybersecurity. It is precisely this disconnect that creates the illusion of complacency, and ultimately creates a serious risk. Employee negligence is cited as one of the primary reasons behind data breaches worldwide—not due to apathy, but due to the systems surrounding them which condition employees to ignore these types of threats.

The costs associated with these lapses in vigilance are substantial. The ASD’s Annual Cyber Threat Report 2024–25 indicated that the average cost per self-reported cybercrime for a mid-sized business was AUD 97,200 and AUD 202,700 for larger corporations. These statistics demonstrate the economic impact of having an employee fatigued by repeated warnings and training. Similarly, the cost of a single employee clicking the wrong link could be catastrophic.

What are the main contributing factors behind breach fatigue among organisations in Australia?  

To understand breach fatigue, we need to identify its root causes. Typically, there are multiple factors contributing simultaneously.

Alert overload  

One of the most obvious contributors to breach fatigue is alert overload. ISC2’s research indicates that 47% of cybersecurity professionals are experiencing burnout and feel overwhelmed with their workload. With high volumes of alerts surpassing any individual’s ability to effectively analyse each alert, triage quality decreases. Eventually, false positives are ignored, and true threats are also ignored.

Generic, repetitive training  

Another major contributor to breach fatigue is generic, repetitive training. Years ago, annual compliance modules were introduced as a method to provide employees with required knowledge. Today, however, these same modules have changed very little. San Diego State University research repeatedly demonstrates that infrequently conducted, generic training sessions create minimal behavioural changes. Individuals attend these presentations, complete them, and continue working the same way as before.

Lack of perceived control  

Verizon’s 2026 Data Breach Investigations Report identifies that humans play a part in 62% of breaches. Without providing context regarding what caused breaches (i.e., human error), many employees conclude that breaches will occur regardless of their actions. Once employees reach this conclusion, they lose motivation.

The cry wolf effect  

Additionally, repeated false positives also contribute to breach fatigue. Too many times, an employee receives a warning that turns out to be legitimate (e.g., a phishing test that flags an authentic vendor email). Or, an employee receives an alert for no apparent reason each morning. Eventually, employees lose trust in the entire system and simply disregard warnings. A 2023 Kaspersky study revealed that 26% of cyberattacks occur due to employees deliberately violating security policies. If nothing happened on other occasions when a staff member had gone against a security policy, they may wonder why this would be any different on subsequent occasions. Employee disengagement does not represent defiance, but rather it represents employees choosing the path of least resistance.

Poor leadership communication  

Finally, poor leadership communication eliminates any remaining enthusiasm employees may possess toward cybersecurity practices. Employees require clarity and understanding as to why specific protocols exist (i.e., what threats they address and what penalties exist if these procedures are neglected).

What are some successful ways to get your employees involved again?  

Successful re-engagement strategies are not merely repeating what failed previously. Instead, successful re-engagement requires adopting new methods altogether.

Customised training based on role and risk profile  

A key strategy for improving training effectiveness involves customising training based on the role and risk profile of each employee group. For example, a finance manager may encounter materially different types of threats than a marketing co-ordinator; a phishing attempt targeting either would differ significantly. Guidance provided by the Australian Cyber Security Centre (ACSC) in developing an organisation's security awareness culture outlines models for categorising training by role and risk level—and the approaches that demonstrate this achieve superior results compared to training all employees collectively.

Positive reinforcement  

An additional strategic approach involves shifting focus away from negative reinforcement (fear-based messaging) toward positive reinforcement (recognising and rewarding secure behaviour). Although threats and consequences may attract initial attention, they do not promote long-term behavioural changes. Behavioural science and policy research supports the findings that positive reinforcement produces sustainable behaviour changes. Identify the successes and highlight them.

Micro-learning  

Gartner® emphasises the use of micro-learning techniques for changing security behaviours. Micro-learning refers to providing small amounts of contextual education on an ongoing basis relative to existing workflow processes as opposed to removing employees from their workflow activities for extended periods (hours) for annual compliance training.

Constructive simulations vs. punitive ones  

Phishing simulations have significant utility—as long as they are constructed as learning opportunities rather than as “gotcha” moments. When an employee selects incorrectly, the subsequent reaction should be brief, supportive, and educative. Shaming reinforces disengagement; curiosity stimulates re-engagement.

Clear escalation pathways  

Employees may feel hopeless—unaware of what action(s) they should take when something appears suspicious and therefore choose to do nothing. Clearly defined pathways for escalating unusual occurrences dramatically improve the chances of preventing disengagement.

Building an organisation-wide proactive security culture rather than merely compliant  

It is critical to recognise that compliance does not equal culture. A compliant organisation consists of employees who perform according to established rules when observed by management personnel. A proactive security-aware culture comprises employees who think critically when no one is observing.

This differentiation is important given that sophisticated threats are specifically designed to capitalise upon human judgment during stressful conditions.

According to the ACSC’s Small Business Cyber Security Guide, technology alone cannot sufficiently safeguard an enterprise. Cultural considerations, i.e., collective values or beliefs regarding how employees will react when confronted with uncertainty, form the foundation of organisational security.

Companies within Australia are beginning to acknowledge the disparity between stated policies and actual practices, recognising that those organisations achieving meaningful improvements in securing their assets treat security culture as a responsibility belonging to senior managers—not solely as a function performed by the IT department.

How can technology reduce alert fatigue without adding to it?  

The question is: Can we use smart technology to help stop (or at least minimise) alert fatigue? Security solutions designed to safeguard organisations are commonly one of the biggest contributors to fatigue. Many security technologies produce dozens of alerts per day; dashboards are typically fragmented and contain many elements; and the background noise is almost always present. All of these factors contribute to the condition of desensitisation.

Currently, the best way to alleviate some of this fatigue is through AI-assisted threat prioritisation. Instead of sending all alerts to an analyst for review, intelligent systems can analyse, filter, correlate, and highlight only the most critical alerts worthy of analysis by a human. According to The IBM Security Cost of a Data Breach Report 2025, organisations utilising AI and automation within their security operations were able to save an average of USD 1.9 million per breach in comparison to those organisations that did not utilise AI and automation.

In addition to AI-assisted threat prioritisation, the idea of human-centred security design builds upon the concept of reducing the number of alerts. Human-centred security design focuses on designing systems that take into account cognitive limitations—i.e., fewer alerts, better contextual information, and cleaner user interfaces. The ACSC has also created a list of recommended and approved security products and services for Australian organisations to evaluate their own stack.

The ultimate objective is not to eliminate humans from the process entirely. It's to make sure that when humans do enter the decision-making process, they are working with relevant and actionable data.

How do you know if your organisation’s security culture has improved?  

Measuring performance is important—but only if you’re using the measurements to drive improvements and not to create fear and punishment. Organisations that rely heavily on performance measures to monitor employee behaviour will ultimately increase the fatigue they’re attempting to mitigate.

Some of the key metrics to track include:

  • Predictive phishing simulation click-through rates—tracked over time (not as a benchmark for each individual)

  • The volume of voluntary security incident reports—a growing number indicates greater levels of trust and engagement

  • Time to report suspected security incidents—a quicker response rate indicates higher levels of vigilance

  • Survey results related to employee confidence in the organisation’s security program and psychological safety—the potential exists for employees to indicate feelings of vulnerability or anxiety regarding reporting

  • Drop in repeated policy violations—this represents behavioural changes due to education and training programs

Getting from fatigued to vigilant  

Fatigue is a systemic issue. It cannot be solved by providing additional training, increasing the number of alerts, or applying increased pressure. However, fatigue can be reduced through a focused effort by organisations to create a new understanding of the connection between their people and their security practices.

It's obvious what needs to happen—organisations need to implement role-specific training based on digestible content, provide positive reinforcement for employees exhibiting secure behaviours, leverage AI-powered security solutions that respect human cognition, foster psychological safety among employees so that they feel comfortable reporting suspected security incidents, and measure the organisation's progress towards creating a healthy security culture versus simply meeting regulatory requirements.

Here's where you can start: Before your next scheduled security training event, ask your team members about their thoughts on the security policy to facilitate an open discussion. Ask them honestly and without expectations or agendas:

  • What are your thoughts about our current security policies?

  • What aspects of our policies confuse you?

  • Which parts of our policies do you choose to ignore?

  • What would you like us to explain or clarify for you?

The responses will likely be far more valuable than any compliance-related report.

Use the ASD's Annual Cyber Threat Report 2024–25 along with the ACSC’s entire resource catalogue as starting points for developing or redeveloping your security culture. They are both completely free and offer practical guidance.