Enjoy fast, FREE delivery, exclusive deals and award-winning movies & TV shows with Prime
Try Prime
and start saving today with Fast, FREE Delivery
Amazon Prime includes:
Fast, FREE Delivery is available to Prime members. To join, select "Try Amazon Prime and start saving today with Fast, FREE Delivery" below the Add to Cart button.
Amazon Prime members enjoy:- Cardmembers earn 5% Back at Amazon.com with a Prime Credit Card.
- Unlimited Free Two-Day Delivery
- Instant streaming of thousands of movies and TV episodes with Prime Video
- A Kindle book to borrow for free each month - with no due dates
- Listen to over 2 million songs and hundreds of playlists
- Unlimited photo storage with anywhere access
Important: Your credit card will NOT be charged when you start your free trial or if you cancel during the trial period. If you're happy with Amazon Prime, do nothing. At the end of the free trial, your membership will automatically upgrade to a monthly membership.
Buy new:
$23.31$23.31
FREE delivery: Friday, July 28 on orders over $25.00 shipped by Amazon.
Ships from: Amazon Sold by: ayvax
Buy used: $8.99
Other Sellers on Amazon
+ $3.99 shipping
82% positive over last 12 months
FREE Shipping
+ $3.99 shipping
91% positive over last 12 months
Usually ships within 2 to 3 days.
Download the free Kindle app and start reading Kindle books instantly on your smartphone, tablet, or computer - no Kindle device required. Learn more
Read instantly on your browser with Kindle for Web.
Using your mobile phone camera - scan the code below and download the Kindle app.
Transformational Security Awareness: What Neuroscientists, Storytellers, and Marketers Can Teach Us About Driving Secure Behaviors 1st Edition
| Price | New from | Used from |
|
Audible Audiobook, Unabridged
"Please retry" |
$0.00
| Free with your Audible trial | |
|
Audio CD, MP3 Audio, Unabridged
"Please retry" | $27.29 | — |
Purchase options and add-ons
Transformational Security Awareness empowers security leaders with the information and resources they need to assemble and deliver effective world-class security awareness training programs that drive secure behaviors and culture change.
When all other processes, controls, and technologies fail, humans are your last line of defense. But, how can you prepare them? Frustrated with ineffective training paradigms, most security leaders know that there must be a better way. A way that engages users, shapes behaviors, and fosters an organizational culture that encourages and reinforces security-related values. The good news is that there is hope. That's what Transformational Security Awareness is all about.
Author Perry Carpenter weaves together insights and best practices from experts in communication, persuasion, psychology, behavioral economics, organizational culture management, employee engagement, and storytelling to create a multidisciplinary masterpiece that transcends traditional security education and sets you on the path to make a lasting impact in your organization.
- Find out what you need to know about marketing, communication, behavior science, and culture management
- Overcome the knowledge-intention-behavior gap
- Optimize your program to work with the realities of human nature
- Use simulations, games, surveys, and leverage new trends like escape rooms to teach security awareness
- Put effective training together into a well-crafted campaign with ambassadors
- Understand the keys to sustained success and ongoing security culture change
- Measure your success and establish continuous improvements
- ISBN-101119566347
- ISBN-13978-1119566342
- Edition1st
- PublisherWiley
- Publication dateMay 3, 2019
- LanguageEnglish
- Dimensions6 x 0.83 x 9 inches
- Print length368 pages
Frequently bought together

What do customers buy after viewing this item?
- Highest ratedin this set of products
People-Centric Security: Transforming Your Enterprise Security CulturePaperback
Editorial Reviews
From the Inside Flap
"I love seeing graduates of my Boot Camp use Behavior Design to address real-world problems. Perry does just that in Transformational Security Awareness, and the results are compelling."
BJ FOGG PHD, Researcher and Founder of the Stanford University Behavior Design Lab, Author of Tiny Habits: The Small Changes that Change Everything
DO YOU CARE MORE ABOUT WHAT YOUR EMPLOYEES KNOW, OR WHAT THEY DO?
Transformational Security Awareness offers a fresh, multidisciplinary approach to building a vital culture of awareness and secure behavior. Weaving together insights and best practices from experts in communication, persuasion, psychology, behavioral economics, organizational culture management, employee engagement, and storytelling, author Perry Carpenter empowers organizations to focus on the human element. The tools he provides let you create behavior change that enhances security at every level.
What good is awareness if your people still don't care or behave in ways that reflect the security values that you are training on? Building secure users requires an intentional focus on behavior and cultural supports, finding actionable ways to intersect with users in the ways that will be most impactful; from relevant information, to behavioral interventions, to cultural and social supports and pressures. This book helps you optimize your security program to include and work with the realities of human nature. Using the insight provided by behavioral and marketing disciplines, you'll learn to engage users, shape behaviors, and foster an organizational culture that encourages and reinforces security-related values. Don't just change what your employees know, change what they do because actions not knowledge will determine whether your organization is breached or secure.
With Transformational Security Awareness, you'll learn to account for the most important factor of your in your security program: the human factor. Discover how to:
- Overcome the knowledge-intention-behavior gap
- Teach security awareness using simulations, games, surveys, and other methods
- Recognize why technological security tools aren't enough
- Develop a well-crafted security awareness program that leverages effective training, behavior shaping techniques, and a network of 'culture carriers'
- Understand the keys to sustained success and ongoing culture change
- Measure your success and establish continuous improvements
Here's what I know:
"A transformational security awareness program will pay-off. In the same way that a steady stream of water over time will create a canyon; or that small amounts of money invested will, through the magic of compound interest, turn into large sums of money, your efforts do make a lasting impact!"
Perry Carpenter
From the Back Cover
"I love seeing graduates of my Boot Camp use Behavior Design to address real-world problems. Perry does just that in Transformational Security Awareness, and the results are compelling."
BJ FOGG PHD, Researcher and Founder of the Stanford University Behavior Design Lab, Author of Tiny Habits: The Small Changes that Change Everything
DO YOU CARE MORE ABOUT WHAT YOUR EMPLOYEES KNOW, OR WHAT THEY DO?
Transformational Security Awareness offers a fresh, multidisciplinary approach to building a vital culture of awareness and secure behavior. Weaving together insights and best practices from experts in communication, persuasion, psychology, behavioral economics, organizational culture management, employee engagement, and storytelling, author Perry Carpenter empowers organizations to focus on the human element. The tools he provides let you create behavior change that enhances security at every level.
What good is awareness if your people still don't care or behave in ways that reflect the security values that you are training on? Building secure users requires an intentional focus on behavior and cultural supports, finding actionable ways to intersect with users in the ways that will be most impactful; from relevant information, to behavioral interventions, to cultural and social supports and pressures. This book helps you optimize your security program to include and work with the realities of human nature. Using the insight provided by behavioral and marketing disciplines, you'll learn to engage users, shape behaviors, and foster an organizational culture that encourages and reinforces security-related values. Don't just change what your employees know, change what they do because actions not knowledge will determine whether your organization is breached or secure.
With Transformational Security Awareness, you'll learn to account for the most important factor of your in your security program: the human factor. Discover how to:
- Overcome the knowledge-intention-behavior gap
- Teach security awareness using simulations, games, surveys, and other methods
- Recognize why technological security tools aren't enough
- Develop a well-crafted security awareness program that leverages effective training, behavior shaping techniques, and a network of 'culture carriers'
- Understand the keys to sustained success and ongoing culture change
- Measure your success and establish continuous improvements
Here's what I know:
"A transformational security awareness program will pay-off. In the same way that a steady stream of water over time will create a canyon; or that small amounts of money invested will, through the magic of compound interest, turn into large sums of money, your efforts do make a lasting impact!"
Perry Carpenter
About the Author
Product details
- Publisher : Wiley; 1st edition (May 3, 2019)
- Language : English
- Paperback : 368 pages
- ISBN-10 : 1119566347
- ISBN-13 : 978-1119566342
- Item Weight : 1.05 pounds
- Dimensions : 6 x 0.83 x 9 inches
- Best Sellers Rank: #602,014 in Books (See Top 100 in Books)
- #320 in Privacy & Online Safety
- #400 in Computer Network Security
- #888 in Internet & Telecommunications
- Customer Reviews:
Important information
To report an issue with this product, click here.
About the author

Perry Carpenter, C|CISO, MSIA, has been a recognized thought leader on security awareness and the human factors of security for well-over a decade. His broad background makes him uniquely positioned to understand nuances of awareness strategy that can be elusive.
Perry’s security awareness-related experience spans multiple pivotal roles: from being a general employee receiving awareness training; to being an awareness program manager running complex global programs; to being the primary market analyst advising security leaders about awareness trends, success practices, and vendor platforms; to now helping lead the efforts of the world’s largest and most successful security awareness and simulated phishing platform. Perry draws from this experience, along with cutting-edge research in the fields of marketing, communication, behavior science, and organizational culture management to inform his perspectives and advice for creating awareness programs that are transformational.
Perry currently serves as Chief Evangelist and Strategy Officer for KnowBe4, the world's most popular security awareness and simulated phishing platform. Before joining KnowBe4, Perry led security awareness, security culture management, and anti-phishing behavior management research at Gartner Research, in addition to covering areas of IAM strategy, CISO Program Management mentoring, and Technology Service Provider success strategies. With a long career as a security professional and researcher, Carpenter has broad experience in North America and Europe, providing security consulting and advisory services for many of the world’s best-known brands.
Perry holds a Master of Science in Information Assurance (MSIA) from Norwich University in Vermont and is a Certified Chief Information Security Officer (C|CISO).
You can connect with Perry on LinkedIn at: https://linkedin.com/in/perrycarpenter.
Customer reviews
Customer Reviews, including Product Star Ratings help customers to learn more about the product and decide whether it is the right product for them.
To calculate the overall star rating and percentage breakdown by star, we don’t use a simple average. Instead, our system considers things like how recent a review is and if the reviewer bought the item on Amazon. It also analyzed reviews to verify trustworthiness.
Learn more how customers reviews work on AmazonReviewed in the United States on September 9, 2019
-
Top reviews
Top reviews from the United States
There was a problem filtering reviews right now. Please try again later.
I’ve known Perry Carpenter for more than 10 years now. From the early days of his remarkable Gartner Analyst career, I always knew that he was interested in the human side of “identity”, along with obviously cybersecurity, but was enamored with his breadth of knowledge in completely foreign areas such as neuroscience, psychology, and even the dreaded M word (apologies to my techie readers) -marketing.
I am not sure if author realizes that, but full acronym of the title is TSA. Maybe it is an unconscious result of constant traveling, but for me it is as symbolic as the picture (you can find the explanation by reading the introduction). While the TSA (Transportation Security Administration) we are accustomed to ensures our safety and security on the ground before our flight takes off, the author’s version of TSA does the same for organizations where “ground” is a company culture and approach towards “security hygiene”.
Readers could also find surprise information about Perry in the Introduction section, which sheds some light on why he looks at the world differently than most of us. It is a must read!
Chapter 1 sets the stage to build the case. It starts with familiar phrases like “humans are the last line of defense”, and the “human factor must be a critical part”. A list of regulations, scary-telling, (i.e. story telling about data breaches due to human errors), negligence or malicious insider activity and an unfamiliar term “continuum of behavior” with a dash of Gartneresque’s not-so-magic Quadrant to describe it. My first instinct was to ask the author about the cardinality of this continuum set (an inside math joke), and although I am a mathematician with a heart, let’s skip that portion until the next book. Fortunately, the author prequels all of that with statements like: “use the information presented here to justify your investment … on end-user training” and “it provides enough ammo to shut down any naysayers who might argue that security awareness is a waste of time”. This is the ROI chapter, the first step of shifting into storyteller mode. Again, only the first step, because the reader still needs to become wise (Chapter 2), helpful (Chapter 3), a human behavior subject matter expert (Chapters 4 and 5), a successful designer (Chapter 6), an organization experience analyzer (Chapter 7) and executor of the TSA (Transformational Security Awareness) program (Chapter 8 and 9). Once read, you can congratulate yourself with graduating the TSA course in Chapter 10. Throw your hat into the air if you’re wearing one.
The author sends the reader into a fruitful journey of getting more knowledgeable with each paragraph and page. Chapter 2 lays down the “foundation of transformational approach” with the “reasons why organizations create security awareness program”, what “security strategy should always account for”, defining “key components and tools” and describing “a map of what’s to come”. In the following chapters, the author is masterfully interweaving the notions and knowledges from several disciplines (psychology, neuroscience, sociology, marketing, etc.), projecting them into the world of cybersecurity and presenting this mix as a logically constructed story of making the TSA program work with human nature, not against it.
There are so many golden nuggets of wisdom sprinkled all over the book that it would be difficult to provide tips of where to find them all. Indulge and discover them on your own. However, I’d like to point out a couple key things which are close to my heart and way of thinking. First of all, its focus on natural human curiosity as a double-edge sword: on one side, it’s a cause of trouble and exploitation by social engineers, and on the other, it’s a main source of why we would like to learn. As described in the book: “One of the most useful states we can induce within our audience is curiosity. Curiosity isn’t an emotion; it’s a feeling”. The author gives us the means and methods on how to use the positives of curiosity and helps to deal with the negatives while at the same time drastically transforming a stale formal “security training” into an adventure for a better understanding of the “why” and “what” of cyber security.
The second is organizational culture: “The power of culture lies in the fact that humans are social creatures”. I could not agree more with this statement. The author encourages “to influence the larger organization culture and to influence the people within it”. So “you’ll have to work on the culture and in the culture simultaneously” and “you need to find ways to go viral” are critical to the overall success of an organization according to the author.
I would like to mention one more thing which was not the focus of the author’s research, but adjacent to the main theme of the book: the art of security policy making. Every security awareness program assumes that policies are already there and the goal is to teach people how to adhere them. We can go deeper by researching how policies were made, what are their main goal and what kind of disruptions and cost they bring to the business, and if it is even feasible from a human standpoint. Some research was already done in this area (including my own work on Costidity – the cost of the human factor in security policy implementation and enforcement), but in my opinion, applying principles, theories and methods described in this work to the security policy creation would benefit not only the research, but also a practical use for many organizations.
This book is a must read for all security practitioners and leaders of modern organizations who are interested in making their security awareness program live, vibrant and successful.
There is no doubt in my mind that any reader will be repeating many of Perry's commonsense mantras, like "Just because you are aware doesn't mean you care." I've always liked Perry, but I wouldn't write such a glowing recommendation if I didn't truly believe it. It's a great book, well-written, and full of great, useful information. Perry transformed me and my understanding of what it takes to do great computer security...and this is after 32 years of being in the field and thinking I was already an "expert". Perry taught me that even an old dog can learn new tricks. If you're in computer security there is a "you" before reading this book and a "you" after reading this book. The latter will be transformed into a better computer security thinker.
With the controversy and debates over phishing simulations, I was surprised that this chapter was rather thin.
If you are looking for a book that will guide you systematically, then this isn't the book for you.
If you are looking for a book with ideas on the subject and you are new to it, then this might be for you.
Top reviews from other countries
The book delves deep into not only what we need to do differently, to raise awareness of Cyber Security, we are given real world tools and ideas that we can adapt and utilise. The book is packed with resources and web links which will take me an age to research and learn from! But that’s the point... This book is your ‘launch pad’ to improving security and how we ourselves develop our approach to the topic.
You can see from the picture I have posted that I have now been given a heap of new ideas to take with me into my next engagement! It has also confirmed some of the things I ‘kind of’ knew instinctively, so that was great too.
If you have been given the task of being the Security, Risk, Compliance, Data Protection lead... Then you should read this book! If you know you need one of these people; Buy this book for them. You’ll be doing yourself, and them a favour!
Reviewed in the United Kingdom 🇬🇧 on May 31, 2020
The book delves deep into not only what we need to do differently, to raise awareness of Cyber Security, we are given real world tools and ideas that we can adapt and utilise. The book is packed with resources and web links which will take me an age to research and learn from! But that’s the point... This book is your ‘launch pad’ to improving security and how we ourselves develop our approach to the topic.
You can see from the picture I have posted that I have now been given a heap of new ideas to take with me into my next engagement! It has also confirmed some of the things I ‘kind of’ knew instinctively, so that was great too.
If you have been given the task of being the Security, Risk, Compliance, Data Protection lead... Then you should read this book! If you know you need one of these people; Buy this book for them. You’ll be doing yourself, and them a favour!












