TrainingBehaviorScientific Evidence

    December 28, 2025 · 6 min read · By José Vicente Chávez

    Why your security training program is not working

    Leer en español

    $6.74 Billion on Something That Does Not Work

    The security awareness training market is valued at $6.74 billion in 2026 according to Mordor Intelligence, and is projected to reach $14.66 billion by 2031, with a compound annual growth rate of close to 16.82 percent.

    There is a fundamental problem with that investment: peer-reviewed evidence shows that completing training does not on its own predict that a person will fail less against a real attack.

    We are not talking about opinions or anecdotes. We are talking about large-scale studies run inside real organizations and published in peer-reviewed academic venues.

    Human risk is managed automatically.

    Turn human risk into your first line of defense.

    Book a demo

    Free demo · 30 minutes · No commitment

    What the Peer-Reviewed Evidence Says

    Ho et al. published in the 2025 IEEE Symposium on Security and Privacy a large-scale study on the efficacy of phishing training in practice, inside a real organization and sustained over months.

    The finding is uncomfortable: having completed the training did not on its own predict a lower likelihood of falling for a real phishing attack. Training activity and behavior change are two different variables, and measuring the first says nothing about the second.

    This means organizations reporting course completion are not reporting what they think they are reporting. They are reporting attendance.

    The ETH Zurich Study: Training and Assuming the Change

    If the work of Ho et al. shows that training is not enough, the study by Lain, Kostiainen and Čapkun, presented at the 2022 IEEE Symposium on Security and Privacy, adds the most uncomfortable nuance. It was a large-scale, long-term study inside an organization, and it found that training delivered inside the phishing exercise itself, as the industry deploys it today, does not on its own make employees more resilient.

    Our reading of why this happens, and we write it as a reading and not as a finding of the study: generic training produces a sense of competence that does not match the real ability to detect an attack. Whoever completed the module feels covered, and that confidence does not translate into attention when the real message arrives.

    What does demonstrate change, in both papers, is testing the behavior again.

    The Channel Problem: Training Covers Less Ground Than the Adversary Attacks

    Email is the front door. According to CISA, more than 90 percent of successful cyberattacks begin with a phishing email. And it is not a channel in retreat, it is a channel that got more dangerous: the Microsoft Digital Defense Report 2025 documents that AI-driven phishing is now three times more effective than traditional campaigns.

    On top of that base, social engineering added fronts. It now also arrives by voice and by SMS, and it chains channels into coordinated sequences:

    • Vishing (voice phishing)
    • Smishing (SMS phishing)
    • Coordinated multi-channel attacks
    Most industry training treats email as an annual module and leaves the other fronts uncovered. The result is a preparation that does not look like what the person is going to face.

    Voice cloning tools lowered the barrier so much that a short sample of public audio is enough to produce a convincing call. The adversary already operates this way. Training, in general, does not yet.

    Why Timing and Context Matter More Than Content

    The fundamental failure of current training is not the content. It is the timing and context.

    Humans do not learn from generic videos watched weeks before facing a real attack. They learn when they make a mistake and receive immediate feedback on what they did wrong and why.

    This is the critical difference:

    Current model (ineffective): "I was trained last year" = lost context, unmodified behavior

    Effective model: "I made this error 3 minutes ago and the system showed me exactly the signals I ignored" = proven behavior change

    Memory consolidation and behavior change require:

  1. Immediate relevance (the error just occurred)
  2. Specificity (this specific email, these specific signals)
  3. Emotional consequence (the impact of "I almost fell for it")
  4. Spaced repetition (re-evaluate weeks later)
  5. Generic annual training meets none of these requirements.

    Cases That Demonstrate the Failure of the Current Model

    Snowflake (2024):

    • Large-scale losses and a wide number of affected corporate customers
    • Employees had completed security training
    • Attack vector: contractor credentials
    MGM Resorts (2024):
    • Severe financial impact and several days of paralyzed operations
    • Trained employees
    • Attack vector: a vishing call to the helpdesk
    In each case, employees had received training. In each case, training did not prevent the attack.

    What Does Work: The Contextual Learning Model

    If generic training does not work, what does?

    Evidence points to a different model with five components:

    1. Continuous Testing, Not Periodic Training

    Instead of an annual course, regular simulations that test real vulnerability under realistic conditions.

    2. Immediate Feedback

    When an employee fails a simulation, they receive training at that moment, not weeks later. Context is fresh, the error is specific, emotional impact is maximum.

    3. Multi-Channel

    Test email, SMS, voice. Attackers do not limit themselves to email. Preparation should not either.

    4. Personalization by Risk Profile

    Not all employees have the same vulnerability profile. A CFO who resists generic phishing but falls for authority pretext needs different intervention than a developer vulnerable to false technical requests.

    5. Change Validation

    Re-test weeks later to validate that behavior actually changed. Do not assume "completed the module" equals "changed their behavior."

    The Question Every CISO Must Ask Themselves

    The average CISO reports to their board: "most of our employees completed the annual training."

    The question the board should ask (and the CISO should be able to answer):

    "What percentage of our employees demonstrated secure behavior under a realistic simulated attack in the last 30 days?"

    If the answer is "we don't know," then the organization has a critical visibility gap.

    Completing a course is not evidence of secure behavior. It is evidence of having watched a video.

    The Real Cost of the Current Model

    The current security training model has three hidden costs:

    1. Direct Cost

    Platform licenses, employee time, program administration. In a mid-sized company the annual sum is not trivial, and it is paid in full even when behavior does not change.

    2. False Security Cost

    A program that gets completed but never re-tested leaves the organization with the confidence of being covered and no evidence of it.

    3. Opportunity Cost

    Every dollar spent on ineffective training is a dollar not invested in solutions that do generate measurable behavior change.

    What to Look for in an Effective Solution

    If you are evaluating alternatives to traditional training, these are the capabilities that evidence suggests matter:

    • Multi-channel simulations (email, SMS, voice)
    • Training delivered at the moment of error, not scheduled
    • Per-person metrics, not just per department
    • Automatic re-evaluation to validate change
    • Adaptive escalation based on individual resistance
    The question is not whether you should invest in employee preparedness. The question is whether you will continue investing in a model that peer-reviewed evidence does not support.

    Sources and references

    • CISA, "4 Things You Can Do To Keep Yourself Cyber Safe". cisa.gov
    • Microsoft, "Microsoft Digital Defense Report 2025". microsoft.com
    • Mordor Intelligence, "Security Awareness Training Market Size & Share Analysis (2026-2031)". mordorintelligence.com
    • Ho, G. et al., "Understanding the Efficacy of Phishing Training in Practice", 2025 IEEE Symposium on Security and Privacy. ieeexplore.ieee.org
    • Lain, D., Kostiainen, K. and Čapkun, S., "Phishing in Organizations: Findings from a Large-Scale and Long-Term Study", 2022 IEEE Symposium on Security and Privacy. ieeexplore.ieee.org

    Human risk is managed automatically.

    Turn human risk into your first line of defense.

    Book a demo

    Free demo · 30 minutes · No commitment