Security Awareness Training Isn’t Dead, but It Needs a Rethink

Cybersecurity Awareness Training: Time for a Reboot

The effectiveness of cybersecurity awareness training has been a hotly debated topic in recent years. While many organizations continue to invest heavily in these programs, empirical evidence suggests that successful attacks are on the rise, leading some to question whether this type of training is truly making a difference.

At its core, security awareness training aims to educate employees on how to identify and respond to potential threats, such as phishing attempts or social engineering schemes. However, a growing number of experts believe that these programs have become little more than “compliance theater” – a checkbox exercise designed to meet regulatory requirements rather than actually improving employee behavior.

One of the main issues with current awareness training is its repetitive and generic nature. According to Stefan Dasic, senior malware research engineer at Malwarebytes, many training programs fail because they are poorly designed and lack relevance to employees’ everyday work lives. “Some of that repetition isn’t just poor design though – a lot of it is driven by compliance and insurance requirements that mandate the same content be re-delivered to every employee every year, regardless of whether they already know it,” he explains.

This focus on compliance has led some experts to argue that awareness training has become more about checking boxes than actually improving security. Robert Costello, chief digital and information officer at Merlin Group, notes that “too much of today’s training is compliance-focused and doesn’t reflect the sophisticated social engineering and AI-enabled attacks organizations face today.” Similarly, Mike Lyman, senior security consultant at Black Duck, suggests that re-taking identical courses across multiple employers can be a sign that training has become more about meeting regulatory requirements than actually changing behavior.

However, not all experts are convinced that awareness training is a lost cause. Drew Thompson, global lead for training and enablement at UltraViolet Cyber, believes that these programs can be effective – but only if they are tailored to specific situations and delivered in a way that is relevant to employees’ work lives. “The attackers keep changing what they are doing, and the training is often trying to prepare people based on what we already know,” he notes.

To make awareness training more effective, experts recommend several key changes. These include more frequent training sessions, training that evolves in line with emerging threats, and a greater focus on behavioral training – teaching employees how to react when they encounter suspicious messages or emails. “Training cannot be the only control,” Thompson emphasizes. “It needs to be backed by good processes, identity protections, technical controls, and clear verification procedures.”

In short, cybersecurity awareness training is not inherently flawed – but it does need a rethink. Rather than relying on generic, compliance-focused programs that fail to account for emerging threats, organizations should focus on delivering targeted, relevant training that complements more robust security measures.

Practically speaking, what can you do as an employee or IT professional? First and foremost, look beyond the checkbox approach to awareness training. Instead of simply checking off compliance requirements, seek out programs that are tailored to your organization’s specific needs and delivered in a way that is relevant to your work life. Additionally, consider pairing awareness training with more robust security measures – such as technical controls, identity protections, and verification procedures – to create a comprehensive defense strategy.

Ultimately, cybersecurity awareness training is not a one-size-fits-all solution. By recognizing its limitations and working towards a more nuanced approach that combines behavioral training with technical security measures, we can begin to make progress in reducing the risk of successful attacks.


Source: SecurityWeek — 2026-10-08