Publishing a security policy tells people what's expected. It rarely changes what they actually do day to day, because behaviour change and information transfer are genuinely different problems that need different solutions.
Real behavioural change programmes borrow from what actually works in habit formation elsewhere: small, consistent reinforcement over time, clear and immediate feedback, and content that connects to something people care about rather than a rule handed down from above.
Applied to security, that means training people can actually finish and remember, phishing simulations that give immediate, constructive feedback, and leadership that visibly treats security as a priority rather than a checkbox: all sustained over time, not delivered once and left to fade.
See how goDeep turns thinking like this into training your team will actually remember.