Security Awareness Training Isn’t Dead, but It Needs a Rethink
A close examination of security awareness training reveals that its effectiveness is being questioned by experts in the field. Despite being a staple in every enterprise’s cybersecurity arsenal, successful attacks continue to rise, casting doubt on whether this type of training actually works.
At its core, security awareness training aims to educate employees about potential threats and equip them with the skills to avoid falling prey to malicious social engineering tactics. However, many experts believe that current approaches are woefully inadequate. According to Stefan Dasic, senior malware research engineer at Malwarebytes, most training programs fail because of their design and delivery. “They’re repetitive, generic, and often seem pointless,” he says.
One major issue is the emphasis on compliance over actual effectiveness. Many companies view security awareness training as a checkbox exercise to meet regulatory requirements or satisfy insurance obligations. This approach reduces the value of training to mere formality, rather than a genuine effort to improve employee knowledge and behavior.
Robert Costello, chief digital and information officer at Merlin Group, shares similar concerns. “Too much of today’s training is compliance-focused and doesn’t reflect the sophisticated social engineering and AI-enabled attacks organizations face today.” Mike Lyman, senior security consultant at Black Duck, expands on this point, noting that re-taking identical courses across multiple employers can lead to a culture of checkbox completion rather than actual behavior change.
Despite these criticisms, not everyone believes that security awareness training is entirely ineffective. Drew Thompson, global lead for training and enablement at UltraViolet Cyber, argues that awareness training works, but primarily in specific situations. The problem, he notes, is that attackers are constantly evolving their tactics, making it challenging to keep training programs up-to-date.
To address this challenge, experts recommend a more nuanced approach to security awareness training. Thompson suggests making training more frequent and tailored to the employee’s role within the organization. He also emphasizes the importance of behavioral training, which focuses on reaction to suspicious messages rather than mere knowledge acquisition.
Josh Bartolomie, VP, global head of threat intelligence at Doppel, agrees that security awareness training still has a place in modern cybersecurity strategies. However, he stresses that it cannot be the only line of defense and should be backed by good processes, identity protections, technical controls, and clear verification procedures.
Ultimately, the takeaway from this discussion is that security awareness training needs to evolve to keep pace with the rapidly changing threat landscape. Rather than relying on generic, compliance-driven approaches, companies should focus on creating more effective, role-specific training programs that complement robust cybersecurity architectures. By doing so, they can help reduce the risk of successful attacks and protect their employees from increasingly sophisticated social engineering tactics.
Source: SecurityWeek — 2026-10-08