Skip to main content
An old rusted wrench, hammer, plyers and other tools lay on a dirty metal surface.
Analyst Insights

Employee security training is way overdue for a shake-up. Here’s the fix

Odds are your employee security training just isn’t cutting it. Researchers advise replacing or supplementing the usual methods with skills-based approaches that allow workers to practice, get feedback, and retain what they learn on a regular basis. Follow these tips to make training part of your culture.

It’s October, and that means scores of companies are marking Cybersecurity Awareness Month with the same old routine: Employees log in to portals, click through animated videos or slide decks, and take quizzes about phishing emails. The rituals are meant to make networks and data more secure.

The reality? It isn’t working.

Research shows this common approach is insufficient, and experts recommend a major shake-up in the training process—involving skill-building and continuous engagement—to improve recognition and reporting of phishing scams (increasingly powered by AI), business email compromise, and other suspicious activity.

A recent UC San Diego Health study starkly indicted the old approach. Nearly 20,000 employees received eight rounds of simulated phishing emails over eight months. Some who took the bait and clicked on an embedded phishing link were routed to anti-phishing training material and notified that they’d fallen for a simulated phishing email while others, the control group, were routed to a dead-end 404 (Not Found error) page. After retesting to see if employees would again click on phishing lures, the failure rate of “trained” employees was just 1.7% better than those who’d received no training.

Explanation? Most people closed the training pages within seconds of receiving them. More than a third didn’t even look.

“It turns out a lot of people do not spend time on the training,” said Ariana Mirian, a co-author and current senior security researcher at Censys. “Essentially, the page opened up and they closed it, which implies they weren’t actually doing the training.”

Employee security training: the root (and history) of the problem

That approach has barely changed in two decades, even as the volume of emails, the sophistication of scams, and the underlying technology have all risen dramatically.

It’s like every organization is being given a box of pills that they’ve been told will solve their phishing problems. They keep taking them, but… they’re not really diagnosing the problem.
Arun Vishwanath, security consultant and author of the anti-phishing guidebook The Weakest Link

In 2007, West Point cadets who received phishing lessons were still just as likely to fall for scams days later. In 2009, Carnegie Mellon researchers found emailed anti-phishing tips were ignored, while embedded lessons worked only modestly better. And in 2022, the National Institute of Standards and Technology (NIST) concluded most awareness programs “fall short of producing meaningful, long-term improvements in secure behavior.”

Notably, NIST helped entrench the very practices it criticized. Its guidance urges organizations to perform awareness programs and recommends phishing simulations followed by training. Many chief information security officers (CISOs) default to that guidance, assuming NIST knows best, even with phishing attacks rising 202% in the second half of 2024 and evidence suggesting such methods are flawed.

“CISOs fall in line with NIST and other standard guidance because they don’t have time to do much else,” said Arun Vishwanath, a security consultant and author of The Weakest Link: How to Diagnose, Detect, and Defend Users from Phishing. “It’s like every organization is being given a box of pills that they’ve been told will solve their phishing problems. They keep taking them, but in doing so, they’re not really diagnosing the problem. So, they can’t possibly solve it. Without diagnosis, you’re just generalizing the problem.”

[Read also: CISO success story—the best cure for boring cybersecurity training]

Vishwanath believes academics, vendors, and organizations need to spend more time looking at why people click in the first place. His research points to habits, shortcuts, and misplaced trust as root causes. People handle email on autopilot, rely on quick visual cues like logos or familiar names, and often suppress suspicions when distracted.

Without addressing those underlying behaviors, training will never change outcomes, he said.

Employee security training 2.0 goes beyond compliance theater

Part of addressing those behaviors comes down to shaking up the training itself, which is what a recent MITRE study set out to address.

Authored by researchers Deanna Caputo, Lura Danley, and Nathaniel Ratcliff, the 2024 paper looked at “malicious elicitations,” a sophisticated form of social engineering that uses ordinary conversations to extract sensitive information. Employees were divided into two groups: One received traditional awareness-based training, and the other took part in a new skills-based model. Instead of slides, the skills group practiced spotting suspicious conversations in realistic settings and received feedback. It turned out that skills training improved recognition and reporting with the effects lasting at least a year.

How training is delivered counts. In recent years, security training firms have tried to up their game by producing more engaging training videos with cinematic, Netflix-worthy storytelling and special effects. The “how often” question also matters, said Lance Spitzner, director at workforce cybersecurity training at the SANS Institute.

“The most common failure is when organizations run training once a year and think they’re done,” he said. “That does not work.”

[Read also: I almost fell for this online scam—why even tech pros can be taken]

What does work, he said, is continuous engagement. Short, simple, over time. Podcasts, infographics, micro-videos, phishing simulations. “It has to be part of the culture,” Spitzner said.

One and done is not “done”—the new rules for employee security training

Training must also reflect the reality of daily work, where employees often have more pressing matters on their mind than adhering to sensible security measures, Spitzner warned.

“I have a client who gets 400 to 500 emails every week,” said Vishwanath. “Training him to look through all of these emails and spot every instance of phishing is a lot to ask of a person.”

Accidental clicks are bound to happen and should never result in any punishment. In some organizations, they do. An effective program, Spitzner counters, encourages openness, treats mistakes as learning opportunities, and makes employees partners in defense.

“Nobody should be reprimanded,” he said. “A big part of security awareness is creating a culture where people feel safe to report mistakes, if they happen. You don’t want to be punitive.”

You also don’t want to rely on training alone. Even educated employees miss things. Take that chap swamped by hundreds of emails.

“No amount of training is going to help reduce that load,” said Vishwanath. “He absolutely needs some technical support to reduce the friction and cognitive load.”

Tech matters—why employee security training is about more than training

Technology must support workers with tools like multifactor authentication (MFA), strong spam filters, and anomaly detection.

Training should be one layer in a defense-in-depth strategy, not the foundation, he said. Systems should be designed with human fallibility in mind. The assumption should not be that employees will always spot the threat but that some will miss it and the system will contain the damage.

That design imperative has only grown with the rise of generative AI. Phishing emails are now fluent, persuasive, and cheap to produce at scale. Attacks are also moving to new channels: text messages, phone calls (vocal phishing, a.k.a. vishing), even deepfake voices impersonating a worker’s colleagues and bosses.

The problem with Cybersecurity Awareness Month

So where does all this leave Cybersecurity Awareness Month? On its own, the annual observance risks reinforcing the box-checking mentality. Training modules get dusted off, compliance records get updated, and organizations reassure themselves that they are safer. Then they’re back to business as usual come November, and security training isn’t scrutinized for a year.

The most common failure is when organizations run training once a year and think they’re done. That does not work.
Lance Spitzner, director at workforce cybersecurity training, SANS Institute

That routine is no longer good enough. Researchers are increasingly calling for training to be replaced or supplemented with skills-based approaches delivered on a rolling basis throughout the year. This reinforcement every few weeks or months will allow employees to practice, get feedback, and retain what they learn. They argue it should be continuous, delivered in bite-sized pieces, and embedded in daily workflows. Employees should be encouraged to report, not punished for mistakes. And organizations should balance human training with stronger systemic protections.

[Read also: Another CISO success story—how LA County trains (and retrains) workers to fight phishing]

That change will only come when frameworks evolve, Vishwanath said.

“As long as NIST tells people to do phishing awareness training, CISOs will keep buying it,” he said. “It’s easier to follow the checklist.”

In all fairness to NIST, there’s nothing wrong with a checklist, per se. The real challenge, experts argue, is breaking free from that checklist mindset and treating security as a living practice.

“Good training is continuous. It’s cultural,” Spitzner said. “It’s not about perfection. It’s about improvement.”