Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Cisco warns of critical flaws allowing Nexus switch takeover

    October 8, 2026

    Standard Chartered To Offer Crypto Custody In Singapore

    October 8, 2026

    FDA-approved epilepsy drug may help reverse osteoarthritis damage

    October 8, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Cisco warns of critical flaws allowing Nexus switch takeover
    • Standard Chartered To Offer Crypto Custody In Singapore
    • FDA-approved epilepsy drug may help reverse osteoarthritis damage
    • Can hope save the planet? An endangered parrot that is beating the odds can help us find out | Helen Pilcher
    • The Conservatives – not Labour
    • BBC pays compensation to PinkNews couple over false sexual misconduct allegations | BBC
    • UK and Israel broker compromise over East Jerusalem consulate – POLITICO
    • Racial and religious hate crimes at record high in England and Wales, data shows | Hate crime
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, October 8
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Security Awareness Training Isn’t Dead, but It Needs a Rethink

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 8, 2026 Cybersecurity No Comments12 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    All enterprises conduct security awareness training for their employees. But whether this has tangible benefits is debatable.

    Empirical evidence suggests that security awareness training isn’t working – successful attacks keep increasing. But opinions on the efficacy of awareness training range from it doesn’t work to it does work, with sometimes, perhaps and depends between the two extremes.

    Awareness training focuses on two tasks: to reduce the effect of bad judgment turning an employee into an insider threat; and to harden employees against falling to malicious social engineering. We focus on social engineering.

    Compliance theater

    The majority opinion is that awareness training is important but not always effectively delivered – and not necessarily at the fault of the company concerned. Stefan Dasic, senior malware research engineer at Malwarebytes, suggests, “Most training programs fail because of how they’re run.” He believes they are repetitive and generic, making them seem pointless.

    “Some of that repetition isn’t just poor design though – a lot of it is driven by compliance and insurance requirements that mandate the same content be re-delivered to every employee every year, regardless of whether they already know it.” The danger here is that awareness training is reduced to an annual legal checkbox.

    Robert Costello, chief digital and information officer at Merlin Group, has similar concerns. “Too much of today’s training is compliance-focused and doesn’t reflect the sophisticated social engineering and AI-enabled attacks organizations face today.”

    Advertisement. Scroll to continue reading.

    Mike Lyman, senior security consultant at Black Duck, expands on this concern. “Re-taking identical courses across multiple employers is a good concrete illustration of training-as-compliance-theater: the kind of thing that produces checkbox completion without any behavior change and may explain why some studies find weak or null effects even where completion rates are high.”

    The problem with compliance requirements, and not just in awareness training, is that it provides a level that can be viewed as a target to achieve rather than a baseline that can be improved.

    Where and when training works

    Drew Thompson, global lead for training and enablement at UltraViolet Cyber, believes awareness training works, but primarily for the specific situations covered by the training. The problem, however, is, “The attackers keep changing what they are doing, and the training is often trying to prepare people based on what we already know.” 

    Josh Bartolomie, VP, global head of threat intelligence at Doppel, agrees. “Security awareness training still works, but many organizations are expecting it to solve a problem that’s changed.”

    Thompson suggests training should be more frequent, should evolve more in line with the evolving attacks, should include direction on reaction to suspicious messages (behavioral training), and be more focused on the employee’s role in the business.

    “And,” he adds, “training cannot be the only control. It needs to be backed by good processes, identity protections, technical controls, and clear verification procedures.”

    Bartolomie adds, “Awareness remains essential, but it can’t be the only line of defense. We can no longer expect humans to be the final line of defense against threats. Technology should be that.”

    Costello says, “Security awareness training still has a role; however, it should reinforce a modern security architecture, not compensate for the lack of one.”

    [ Read: Social Engineering Detection Moves Into the Live Conversation ]

    Biswajit De, co-founder and CTO at CleanStart, adds, “Awareness should complement engineering, not replace it. Good engineering assumes things will fail, and good security should assume people occasionally will too.”

    Jim Dolce, CEO at Lookout, believes training can be useful, “but is fundamentally outmatched within today’s mobile AI threat landscape. The attempt to turn employees into a human firewall through training belongs to the earlier desktop-centric age.”

    Frontier AI has completely changed the threat landscape and weaponized social engineering – generating hyper-personalized, flawless phishes and voice clones across mobile channels like SMS, WhatsApp, and messaging apps at machine speed. “Security awareness training fails because we are asking humans to defeat AI on a 6-inch phone screen. You cannot train away a structural architectural problem.” 

    Mike Aalto, co-founder and CEO at Hoxhunt, points to a 14-fold surge in AI-generated phishing at the turn of 2025 to 2026. “The big shift isn’t brand-new tactics and zero-day messaging, it’s the modernization of old attacks. Traditional phishing kits are being upgraded with cleaner formatting, better writing, and more personalized messaging that can be generated at scale.”

    Mike Aalto, Hoxhunt

    He has a valid point: defense against attack remains fundamentally a game of whack-a-mole. The problem is primarily a huge increase of better formed (deep-faked moles) delivered at greater speed and scope courtesy of LLMs. But it’s still whack-a-mole.

    He believes ‘behavioral’ training needs to be added to awareness training. Focusing on and rewarding a few measurable core behaviors like threat reporting and MFA usage establishes a cultural bedrock of secure behaviors. “By replacing fear and heavy-handed surveillance with fun, continuous learning and automated behavioral interventions, you don’t just reduce the likelihood of negligence. You fundamentally transform your workforce into an active, intelligent human sensor network that catches the threats your technology misses.”

    However, Sanny Liao, co-founder and CPO at Fable Security, says bluntly, “For the most part, security awareness training as done today does not work. Social engineering continues to succeed because attackers exploit context, timing, and psychology, while most training remains generic, infrequent, and removed from the moments when employees are actually making decisions.”

    She hints at a novel approach. “One place the industry can look for inspiration is adtech. Marketers have gotten remarkably good at changing behavior by delivering the right message at the right time based on context. Security awareness has largely done the opposite by giving everyone the same training at the same time, regardless of the decisions they’re making or the risks they face. When organizations change behavior instead of simply raising awareness, employees stop being viewed as the weakest link and start becoming an active part of the organization’s security defenses.”

    Lyman points to the contradiction faced by awareness trainers. KnowBe4 data has shown that training with simulated phishing can produce real reductions in phish-prone rates. But academic studies show that this effect fades fast. “Effects that look strong right after a course can disappear within months.”

    So, does security awareness training work? “Yes,” says De, “but expecting security awareness training alone to stop cyberattacks is like expecting airport security posters to prevent hijackings.”

    Advantage to the attacker

    Social engineers have three primary advantages over security awareness training: asymmetry, attack is proactive while defense is reactive, and psychology.

    Asymmetry. ‘Defenders must be right every time; attackers only need to be right once.’ That’s the standard description of the asymmetry between cybersecurity attack and defense. To combat social engineering, each person must be right every time against every attacker, always, at machine speed. Every single attacker, out of hundreds of thousands, assisted by AI in performance and scale at machine speed, need only succeed once.

    Biswajit De, CleanStart

    “Attackers don’t need everyone to fail,” says De, “they just need one distracted person on one busy afternoon.”

    Predicting the future. Trainers primarily teach how to recognize yesterday’s attacks. It is conceivable that excellent training can teach how to recognize today’s attacks. It is hard to imagine how awareness training can teach how to recognize the new and evolving attacks that will come tomorrow. You cannot teach what you don’t know. By the time awareness training is delivered, it could be obsolete.

    Psychology. Psychology is complex, including intangibles like memory and motivation. Here, we’ll just ask a single question: can you expect a person whose full-time job is bean counting to be as aware of trickery as a person whose full-time job is trickery? And that’s without delving into the complexities of human memory retention and loss.

    Asymmetry is a fact we cannot change and can only reduce with a limitless budget. Predicting the future is largely impossible and never long term. Psychology, however, is current. We can learn and improve from it.

    The psychology of awareness training

    To explore this angle of security awareness training, we talked to cognitive psychologist Jordan Richard Schoenherr, PhD, a scientist at Humanix and adjunct professor at the University of New South Wales.

    Schoenherr’s belief is that security awareness training is largely not working. That’s not to say it cannot work, or at least be improved, but it is difficult owing to the complexities of the human mind and memory. The purpose of awareness is to instill information into long-term memory, coupled with the correct behavioral response to that memory. But, comments Schoenherr, “Forgetting (or entropy) is the default state of memory – and it occurs rapidly.”

    Frequently refreshing the learning is necessary to maintain that memory. Even if this is successful, “It doesn’t necessarily mean that someone is going to know, in the moment, when and where to use it. So, the complementary approach, behavioral nudges, attempts to reactivate that information in a particular context.”

    So, the subject of the training must be able to recognize a situation, relate the situation to long-term volatile memory and activate it in the present, while recalling the correct behavioral response (accept, ignore, report, etcetera). 

    This training must necessarily teach the student how to recognize a phish. Such training is largely, of necessity, limited to known social engineering patterns – and that in itself can be problematic.

    For illustration purposes only, if the training is limited to recognition of the old ‘Nigerian scams’ and riddled with spelling and grammatical mistakes, ‘Nigerian scams’ will be easily recognized. The danger is that a lack of these flags might be translated as proof of validity. The reality, of course, is that the absence of proof is not proof of absence; and that applies to all awareness training.

    Jordan Richard Schoenherr, Humanix

    So, a major priority for the training is that it must be up-to-date with current social engineering practices. The difficulty here is that up-to-date today may be historical next week.

    We know that criminals change and adapt their attack processes rapidly. There is no guarantee that training on known methods can prepare people for social engineers’ latest disruptive innovations. Training for disruptive innovations requires predicting the future, which is something both trainers and cybersecurity vendors consistently attempt. Predicting the future is possible (otherwise we wouldn’t have people making money on trading stocks and shares), but it is difficult, never guaranteed, and probably short-term only.

    Schoenherr explains: “When we give people creative tasks [such as predicting the future], it basically activates two main regions of the brain, the inferior temporal lobe where long-term memories are stored, and the prefrontal cortex for executive functions. All the building blocks in your memory are getting pulled into that prefrontal cortex, which is trying to rearrange them, manipulate, and come up with what we would call a mental model. The extent to which that mental model is going to work or not is based on analogical reasoning. Find the right shape in your long-term memory, or reconstruct one that looks like the situation, and predict into the future.”

    (This is basically the same mental process used by an employee wondering if a communication is valid or malicious.)

    Back to the future, we know from stock analysts that this can be done for the short term, but we also know that these predictions are poorly calibrated for the long term. “In the short run, you can find people that are very effective at predicting the state of the world because they are aware of the variables that exist,” he continued. “They seem to have some kind of magical trick. It’s not magic; it’s because they have a mental model which is congruent with the situation. But then new variables come into play, and they lose the hot streak of prediction.”

    So, can an organization predict the future? Yes. Will those predictions and plans based on them be effective? Depends how well the organization handles and incorporates what is known as ‘decision making under deep uncertainty’. “The decision-making under deep uncertainty approach assumes you should develop as many potential scenarios as possible based on the variables you have, and then run simulations to see which scenario produces the best outcomes across many different iterations. That ‘best outcome’ is the scenario that you’re going to run with.” 

    It’s the scenario needed to predict probable/possible future styles of social engineering. “It will be imperfect, it will not necessarily predict the state of the world perfectly, but you need to build up these scenarios,” Schoenherr continued. But it is difficult. “People will always be fighting the last war and are not necessarily capable of thinking what will happen in the future.”

    Cognitive psychology helps us understand how to navigate the complexities of maintaining and retrieving memories, and how best to project current knowledge to predict likely future scenarios – both of which are essential for effective awareness training.

    Summary

    Understanding the psychology of cognition cannot solve the asymmetry of the social engineering threat. That can only be solved or reduced with a limitless security budget when most budgets are maintained at the minimum possible. It can, however, assist in predicting the future direction of social engineering. More particularly, however, it can help in the design of awareness training methodologies likely to be more effective.

    Combining lessons learned through current awareness training (awareness training and behavioral conditioning backed by refresh frequency and technology) with the human cognitive processes we learn from science, can help us develop new or improved training. It will never be perfect, but awareness training cannot be abandoned. And it can always be improved.

    Related: CyberNut Closes $5M Growth Capital for K-12 Security Awareness Training

    Related: Jericho Security Gets $15 Million for AI-Powered Awareness Training

    Related: Vista Equity Partners to Acquire Security Awareness Training Firm KnowBe4 for $4.6B

    Related: Huntress Acquires Security Awareness Training Startup Curricula for $22M

    awareness Dead isnt rethink Security Training
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Cisco warns of critical flaws allowing Nexus switch takeover

    Attackers Target Critical Atlassian Vulnerability Within Hours of PoC Publication

    US Seeks Alleged Chinese Hafnium Hacker With $10 Million Reward

    Rein Security Raises $25 Million to Guard AI Agents at Runtime

    TP-Link Faces State Lawsuits and New Scrutiny Over ISP Router Flaws

    Fake Decryption Tools Masked $11M Markup in Ransomware Recovery Scheme

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Cisco warns of critical flaws allowing Nexus switch takeover

    October 8, 2026

    Standard Chartered To Offer Crypto Custody In Singapore

    October 8, 2026

    FDA-approved epilepsy drug may help reverse osteoarthritis damage

    October 8, 2026

    Can hope save the planet? An endangered parrot that is beating the odds can help us find out | Helen Pilcher

    October 8, 2026
    Latest Posts

    Wisconsin’s partisan primary election is Tuesday. Learn more about who’s on your ballot.

    August 10, 2026

    Gabon ends fisheries partnership agreement with EU

    August 10, 2026

    Science backs calls for limiting screens in schools

    August 10, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Cisco warns of critical flaws allowing Nexus switch takeover

    October 8, 2026

    Standard Chartered To Offer Crypto Custody In Singapore

    October 8, 2026

    FDA-approved epilepsy drug may help reverse osteoarthritis damage

    October 8, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.