Security Awareness

Why Annual Security Training Doesn't Stick (And What the Research Says Works Better)

Most organizations run security-awareness training once a year, usually as a compliance requirement tied to an employee's hire date. It's an easy box to check. The evidence on whether it changes anything is not encouraging.

What the research found

A large field study published by researchers affiliated with UC San Diego and the University of Chicago tracked more than 19,500 employees at a healthcare organization over eight months, across ten simulated phishing campaigns.1 The study looked at two common training approaches: annual compliance-style training, and embedded training shown immediately after someone clicked a simulated phishing link.

The findings were blunt. The researchers found no significant relationship between how recently an employee had completed annual awareness training and whether they failed a phishing simulation.1 Embedded, in-the-moment training performed better, but the improvement was still small: a reduction in average failure rate of only about 2 percentage points.1 The paper's own conclusion was that, as commonly deployed, these programs are "unlikely to offer significant practical value" relative to their cost in time and effort.1

Separately, Verizon's 2025 Data Breach Investigations Report found a human element present in roughly six in ten confirmed breaches in its dataset, which is consistent with the idea that awareness gaps remain a persistent, not shrinking, problem.2

Why the annual model struggles

None of this means people can't learn to spot phishing. It means a once-a-year video, watched under time pressure and rarely revisited, doesn't match how attacks actually change. Phishing themes shift with the season, current events, and whatever software your team happens to be using this quarter. A training module written in January says nothing about the vendor-impersonation attempt someone receives in October.

It also doesn't help that annual training is usually delivered without much connection to a person's actual job. A generic "don't click suspicious links" message is easy to forget. A short explanation tied to a real, recent attempt against your own organization tends to land differently.

What tends to work better

The same body of research that's critical of annual, one-off training points toward a different pattern: frequent, low-stakes practice rather than a single annual event. A 2024 review pooling 42 separate studies on this topic pointed to training intensity, active engagement, and detailed feedback as the factors most associated with better outcomes, rather than any single training format.3

In practice, that tends to look like:

This is the reasoning behind running security awareness as an ongoing, managed cycle rather than a once-a-year training assignment. It doesn't guarantee a lower click rate for any specific organization, and no program can promise that. But the direction the research points is consistent: frequency and relevance matter more than any single piece of content.

Curious what a managed cadence looks like in practice? See how the CyberNest program structures the cycle.

See the Program

Sources

  1. Ho, G., et al., "Understanding the Efficacy of Phishing Training in Practice," IEEE Symposium on Security and Privacy, 2025
  2. Verizon, 2025 Data Breach Investigations Report — Executive Summary
  3. Summary of a 2024 scoping review of 42 studies on security-awareness training effectiveness, as reported in "Why cyber security awareness training fails: the research," Lively