Everyone's a Builder Now. That Changes Security Training.

Fran Roberts | Jul 31, 2026

I've spent my career figuring out what makes content stick, from early work for brands like Apple and onward across two decades across film, animation and generative AI. Different tools every few years, same question underneath. What makes someone lean in instead of tuning out?

Turns out that question sits at the center of a problem the security industry has wrestled with for 15 years. How do you build a culture where people actually change how they behave? Not comply. Not click "complete." Change.

For most of that history, the answer focused on one kind of person: the employee at the keyboard. The one who gets the convincing email, reuses the same password everywhere, approves the MFA prompt they didn't request because it's 4:55 on a Friday. That work is essential, and KnowBe4 has led it for a decade and a half.

But there's a second person we've mostly left out of the conversation. The developer.

The engineer shipping code under deadline pressure. Or pasting in an AI-generated function without reading it closely. The team that bakes broken access control into an app on day one and never sees it. These aren't reckless people. They're good at their jobs and were never trained for this particular risk at the moment they needed it.

We've treated security awareness and secure coding as two separate worlds. One for the workforce, one for the technical teams. Attackers have never once respected that line. Neither should we.

AI Moved the Line

Here's what changed. 72% of developers now use AI in their daily work. That's an enormous productivity gain, and it comes with a new failure mode: AI writes vulnerabilities as fluently as it writes working code, and it does it at a speed that leaves almost no room to catch the problem before it ships.

Pieter Danhieux, Co-Founder and CEO of Secure Code Warrior, framed the trajectory better than I could: "As software development shifts from human-written code, to AI-assisted development, to fully agentic systems, every employee will become a builder of applications and AI agents."

Read that again. Every employee becomes a builder. The wall between "technical" and "non-technical" isn't just lowering. It's coming down. Which means the population that needs secure-building instincts is about to include almost everyone you employ.

That's why the Secure Code Warrior partnership matters to me, and why it belongs inside KnowBe4's work rather than beside it.

What We're Putting in Your Hands

Thirty-one learning activities across nine series, now in the KnowBe4 ModStore:

  • Application Security 101

  • The OWASP Top 4: Broken Access Control, Security Misconfiguration, Software Supply Chain Failures, Cryptographic Failures

  • The OWASP Top 10 for Large Language Model Applications

  • Coding with AI, Data Protection, Threat Modeling.

Ten programming languages, eight spoken ones.

The catalog matters. What I care about more is the experience of the thing.

I've believed one idea my whole career: engagement is the entire game. Not a garnish on top of the "real" content. The game itself. Disengaged people don't learn, and people who don't learn don't change, so training that bores them fails at the only thing it was built to do. Secure Code Warrior was built on that same conviction. Developers practice inside the actual languages and tools they work in, hands on the keyboard, in context. That's the standard I want under everything Studios makes.

Or, as our Chief Product Officer Greg Kras put it: "Our customers need more than just static resources. They are asking for fresh, real-time content and fast-paced interaction to make sure their technical teams don't fall behind."

Security Culture Doesn't Split in Two

So here's what I'd leave with any CISO reading this. A security culture that covers only general awareness is a house with one wall missing. It doesn't matter how sharp your people are at spotting a phishing email if the code underneath them is shipping holes. The attack surface runs through all of it at once: the inbox, the browser, the codebase.

The fix for both is the same shape. Training that's relevant, role-specific and good enough that people actually want to do it. The developer who ships an OWASP Top 10 flaw and the employee who clicks the link have the same thing in common, and it isn't carelessness. It's that nobody gave them the right reps at the right time.

Both are fixable. Neither gets fixed by training that people grit their teeth through.

At KnowBe4 Studios we hold every piece of content to that line, whether it's an award-winning narrative series like The Inside Man or a hands-on secure coding module built with Secure Code Warrior. The format changes constantly. The bar never moves.

The content is live now for KnowBe4 Diamond and SAT Advanced customers. If you don't know where your developers stand on secure coding fundamentals, this is the best way to find out.

KnowBe4 Agent Risk Manager

Eliminate the AI security blind spot with KnowBe4’s Agent Risk Manager. Get real-time visibility, automated threat detection, and active control over AI agents.

Learn more

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.