Security awareness training became a standard corporate obligation in 2008, and it arrived through compliance rather than conviction. Card industry rules required a formal awareness programme. Auditors asked for evidence. Evidence meant completion records, so completion records became the product. The result was an entire industry built around a metric that measures nothing: the percentage of staff who clicked through a training module before the deadline. Seventeen years and a great deal of research later, the picture is clearer and less comfortable than most security programmes acknowledge. Awareness training does something. It does considerably less than its budget implies, and the things that actually reduce human-factor risk are mostly not training at all.
What 2008 Built
The first generation of programmes had a recognisable shape: an annual computer-based module with a multiple-choice quiz, a poster campaign, a welcome-pack policy acknowledgement, and an intranet page nobody visited. Phishing simulation as a commercial service was just emerging, and the early tests produced alarming click rates that made excellent board slides. Every element of it was designed to demonstrate that training had occurred. None of it was designed to determine whether behaviour had changed — and that distinction is the whole story.
What the Evidence Now Shows
The research has caught up, and it is unflattering. A large-scale study of enterprise training, covering roughly nineteen thousand employees over eight months, examined both annual awareness training and embedded phishing training — the practice of showing a training page immediately after someone clicks a simulated phish. It found no meaningful relationship between completing annual training and subsequent phishing susceptibility, and only a marginal benefit from embedded training. Work from ETH Zurich on the content, nudges and incentives used in embedded phishing training has similarly found that the details of how training is delivered matter more than whether it is delivered, and that some common implementations do not help at all. Set against that, the scale of the problem is not in dispute. Verizon's breach research has consistently placed the human element in the majority of breaches — 68 percent in its 2024 analysis, and around 62 percent in recent years. So the human factor is the dominant risk, and the primary control deployed against it for two decades has weak evidence behind it. That is an uncomfortable position for a security programme to occupy, and pretending otherwise is how budget gets wasted.
The 60-Second Problem
The most operationally useful finding in this literature is about speed. The same breach research found that the median time for a user to fall for a phishing email is under sixty seconds from opening it. One minute. That is the entire window in which awareness can operate. Any control that depends on a person pausing, reflecting, checking a sender domain against a mental checklist and deciding not to click has to work inside sixty seconds, under time pressure, for a message engineered by someone whose profession is manipulation. Designing your primary defence around that moment is a bad architectural choice. Designing around what happens after it — detection, reporting, containment, and controls that make the click non-fatal — is a good one.
What Actually Moves the Numbers
Phishing-resistant authentication. The single highest-return intervention available. Hardware security keys and passkeys defeat credential phishing structurally, because there is no reusable secret for the victim to hand over. App-based push approval is better than nothing and is routinely defeated by fatigue attacks and real-time relay. Reporting rate, not click rate. Verizon's data has shown roughly a fifth of users reporting phishing in simulation exercises, and notably that about one in nine of those who clicked also reported it. That second figure is the valuable one. A user who clicks and immediately reports gives the security team a head start; a user who clicks and stays silent out of embarrassment does not. Programmes that punish clicking optimise directly against the behaviour they most need. Time to report and time to contain. Measure minutes from first delivery to first report, and from report to mailbox purge and credential reset. These are operational numbers that improve with tooling and practice, unlike awareness, which decays. Technical controls at the boundary. Email authentication properly enforced, link and attachment detonation, external-sender marking, blocking of high-risk attachment types, and browser isolation for untrusted links. Each one removes a class of message before judgement is required. Process controls on the transaction, not the email. Most business email compromise losses end in a payment. Mandatory callback verification on any change of bank details, using a number already held on file; dual authorisation above a threshold; and a standing rule that urgency from a senior executive is a reason for more verification, not less. These controls work regardless of whether the email was convincing. Least privilege and segmentation. So that a compromised account produces a limited blast radius rather than a lateral path to everything.
What Training Is Still Good For
This is not an argument for abolishing awareness programmes. It is an argument for expecting the right things from them. Training is genuinely effective at teaching people the reporting mechanism and normalising its use. It is effective at role-specific risk — finance teams on payment fraud patterns, developers on secrets handling, executives and their assistants on targeted impersonation. It is effective at communicating what the organization expects and what will not get you into trouble. And it is legitimately required by many regulatory and certification regimes, which is a reason to run it well rather than a reason to believe it is a control. What it is not is a substitute for authentication architecture.
Running a Programme Worth the Money
- Measure reporting rate and time to report as primary metrics. Click rate is a secondary diagnostic, not a scoreboard.
- Never punish clicking. One-click reporting, visible thanks, no blame. Silence is the expensive failure mode.
- Target the risk, not the population. Short, specific, role-based content beats an annual module for everyone.
- Simulate realistically and ethically. Avoid campaigns that exploit deeply personal themes — bonuses, redundancy, medical results. The trust damage outlasts the lesson, and increasingly attracts scrutiny from works councils and regulators, including under GCC and European employee-monitoring expectations.
- Spend the marginal dollar on controls first. If you are choosing between a premium awareness platform and rolling out phishing-resistant authentication, the decision is not close.
- Include voice and messaging in the threat model. Recent data shows simulated attacks through phone-centric channels succeeding at meaningfully higher rates than email, and AI-generated voice has made impersonation cheap and convincing.
- Rehearse the response. A tabletop exercise on a reported phish that has already harvested credentials teaches your team more than any module teaches your staff.
Common Questions
Does security awareness training reduce breaches?
The evidence is weak. Large studies have found little or no relationship between completing annual training and phishing susceptibility, and only marginal benefit from embedded training after simulated phishes. It remains useful for teaching reporting behaviour and meeting compliance requirements.
What should we measure instead of click rate?
Reporting rate, the proportion of clickers who also report, median time from delivery to first report, and time from report to containment.
What is the most effective anti-phishing control?
Phishing-resistant authentication such as hardware security keys or passkeys, combined with process controls on payments — particularly callback verification on any change of bank details.
Should employees be penalised for failing phishing simulations?
No. Penalties suppress reporting, and unreported clicks are far more damaging than reported ones. Make reporting easy, fast and consequence-free.
Awareness Program Review — Outpace rebuilds human-risk programmes around what measurably works: phishing-resistant authentication, fast reporting and containment, and payment controls that hold even when someone clicks.
