Security awareness training: what it actually buys

DCDaniel C. · Head of Security Operations
Phishing & Social Engineering Defense·8 min read

I've signed awareness-training renewals for a decade and rarely had a credible way to tie them to a prevented incident. Here's what the line item reliably delivers, what it cannot carry on its own, and where incremental phishing budget reduces exposure more directly.

The awareness-training renewal landed in my queue the same week as a quote for FIDO2 security keys, and the two numbers were close enough to force a comparison I'd been avoiding for years. Both purchases competed for the same security budget. The training deck promised risk reduction; the key deck promised that a phished password would stop mattering.

I've signed that training renewal every year for a decade, and I have never once been able to show a CFO the incident it prevented. My budget rule now: fund the compliance minimum, build the program around fast reporting, and put incremental spend into controls that make a user's mistake less consequential rather than betting the mistake never happens.

In brief:

  • Awareness training reliably buys compliance evidence, onboarding literacy, and a way to teach employees to report suspicious messages.
  • Completion rates and simulated-phish click rates are weak proxies for real phishing resilience unless the cohorts, lures, and measurement conditions are comparable.
  • Some employees will click regardless of training, so the defense that matters most is what happens after: how fast the SOC hears about it and how much the click can cost.
  • FIDO2 authentication and post-delivery detection are often a better use of incremental budget than a premium training tier.

What the awareness-training line item is sold as

The textbook definition: security awareness training is a program of instruction and simulated phishing that teaches employees to recognize and report social engineering. The definition describes intent and says little about effect. The pitch attached to it is risk reduction, and it commonly comes with a dramatic benchmark showing click rates falling after sustained training.

The headline number rarely survives a close reading of the methodology. Vendor benchmarks can use populations or methods that make baseline and follow-up figures hard to compare directly. In the programs I've reviewed, trained and untrained employees have sometimes failed the same lures at similar rates. At renewal, I'm buying a documented control with a limited behavioral effect. Priced that way, the advanced tier looks like an insurance rider.

What it actually buys

Training buys a compliance checkbox. It also buys a liability story and that second part is the one most programs don't design for.

A compliance checkbox and a liability story

Training is among the easiest controls to evidence in an audit, since organizations can retain completion and policy-acknowledgment records. It also appears in major control frameworks: NIST SP 800-53's AT-2 control calls for literacy training at an organization-defined frequency, not a prescribed annual cadence. In incident reviews I've handled, adding or strengthening training has been an obvious remedial step when a program was inadequate.

When I prepare for an insurance review, the same artifact gives me a clear answer to the training question and gives legal teams a record of the precautions taken before a breach. I treat that audit-and-insurance value as administrative, separate from whether the program measurably reduced phishing risk.

A click-rate dip that decays without reinforcement

Training can move click rates, but the dip decays without reinforcement. I've seen stronger results among the most susceptible employees in some settings, though those results vary sharply with lure difficulty and with how the exercise is designed and deployed.

In programs I've run, behavioral improvement has faded before the next annual training cycle. An organization running the compliance minimum therefore spends part of every year with a trained population that may have reverted toward baseline, while holding a valid certificate.

Why training doesn't change behavior for long

Every vendor I've asked about decay has offered better content as the fix. In my experience, the problem sits in program structure, not content.

Program structure, not content, explains the decay

The decay is a program-structure problem, not a content problem: attention, workload, message context, and lure quality all influence whether someone acts, not training completion alone. Periodic simulations work mainly as reminders, and the module content itself gets limited engagement.

Lure design can materially change click rates: routine password notices perform differently from messages about vacation policies or other timely workplace concerns.

The evidence for training's effect is hard to trust

I don't treat before-and-after vendor dashboards as causal evidence. A credible estimate needs comparable cohorts and consistent reporting definitions, and a true control group is rarely available in production. The lures are also getting harder on their own.

Microsoft's 2025 Digital Defense Report found AI-enabled phishing achieved a 54% click-through rate in the data it analyzed, against 12% for conventional attempts, a finding worth taking seriously but not as a universal benchmark.

What actually reduces phishing risk

The right question isn't whether an employee might click, since some inevitably will. The question is whether that click can produce credential theft, malware execution, fraud, or an uncontained campaign, and how quickly the SOC can detect and limit the damage.

What bypasses the trainee's judgment entirely

The highest-severity phishing outcomes increasingly bypass the trainee's ability to identify a suspicious message:

  • Adversary-in-the-middle attacks relay legitimate login pages and capture authenticated sessions.
  • Device-code phishing hands an attacker a live access token after the user completes a real MFA-backed login.
  • ClickFix uses fake verification or troubleshooting prompts to persuade the victim to paste and run a command directly. In the Digital Defense Report cited above, Microsoft reported it represented 47% of initial-access techniques observed in the Defender Experts notifications covered by its 2025 report.

Awareness training cannot be the sole or primary defense against these three techniques, though it can still help a user recognize a prompt as suspicious and report it.

The controls that don't depend on the user

Phishing-resistant authentication changes the architecture instead of relying on user judgment. FIDO2 security keys and properly deployed passkeys use origin-bound public-key authentication, which makes conventional credential phishing and many MFA-relay attacks far less useful. Protection depends on implementation: close off password, SMS, and help-desk recovery fallbacks, or an attacker just targets the weaker channel instead.

Behind the login, I budget for post-delivery detection: user-reporting telemetry, message search and purge, and rapid session or token revocation that warn on suspicious messages and pull back email the gateway allowed through. At workforce scale, those controls compete directly with a premium training license for budget.

The minimal training still worth doing

The training worth keeping teaches one action: report, and report fast. A better exercise model replaces surprise tests with announced fire-drill-style exercises measured by time to first report, not click rate.

The metric I take to the monthly security review now is median time to first report: if five employees report the same lure within ten minutes, the SOC has a chance to search for the campaign, purge related messages, and review sessions before credential theft becomes an account-takeover incident.

The reporting pipeline only works if the SOC closes that loop. Each user submission creates manual triage, and in my experience, employees who repeatedly report suspicious mail and hear nothing back become less willing to keep reporting. So the training budget that survives my review funds a one-click report button and a triage workflow that sends a verdict back to the reporter, plus a reminder before the annual effect has faded.

How to right-size the spend

What to cut and what to keep

Cut the parts of the program that exist to catch people, not help them:

  • Simulations designed to shame the employees who miss them, which turns the exercise into a gotcha and weakens the trust reporting depends on.
  • Embedded training triggered by a single failure, which in my experience rarely improves results.
  • Monthly 30-minute modules. For a large workforce, calculate this explicitly: completion time multiplied by loaded hourly cost often exceeds the platform license.

Keep an onboarding module, one annual or role-defined refresh, a nudge before the behavioral effect decays, and the completion evidence that supports insurance and audit questionnaires.

Where the savings should go

I move the savings into FIDO2 keys or passkeys, starting with finance and other high-risk groups, and into post-delivery remediation backed by a report-to-verdict pipeline the SOC actually staffs. I downgraded from the advanced tier to the foundation tier this cycle and put the delta into keys.

Pricing the tradeoff that way shortened the CFO conversation: here's the control that makes a stolen password less useful, and here's the evidence that satisfies the auditor and the underwriter. Before your next renewal call, I pull the engagement export and look at time on page, then I ask the vendor how it measures program effect against a comparable cohort.

Frequently asked questions about security awareness training

What is security awareness training?

Security awareness training is a program of instruction and simulated phishing, with policy acknowledgment, that organizations run to teach employees to recognize and report social engineering. In practice it is mainly a documented control used to demonstrate that required awareness education occurred. In the programs I've reviewed, its measured effect on phishing behavior has often been limited.

How effective is security awareness training?

Training can improve knowledge, policy awareness, and reporting behavior, and I've seen stronger simulated-phish results in some programs I've reviewed. Its effect on real-world phishing risk is harder to isolate, since results depend on lure difficulty, campaign timing, employee role, and measurement design. I treat completion and click-rate dashboards as operational signals, not proof that the organization is protected, and I've seen trained and untrained populations fail the same lures at similar rates when the comparison wasn't a true randomized cohort.

Why does security awareness training fail to change behavior?

Training doesn't always translate into reliable action under real working conditions. Employees make quick decisions while managing workload, trust relationships, business urgency, and increasingly credible lures, and in my reviews, module content has often been minimally consumed while reminders drove most of the visible effect. That's why I build the program around reporting and escalation, and let technical controls reduce the harm when a message still gets through.

How often should security awareness training be conducted?

Set the formal cadence from the regulatory and contractual requirements that apply to the organization. Those requirements include insurance terms. Where the compliance floor is annual, use a shorter reminder cycle if the observed behavioral effect fades before renewal. In my programs, short reminders have often outperformed longer modules because reminders produced most of the visible effect.

Who is required to complete security awareness training?

The covered population depends on the applicable security framework. A framework may cover everyone who can affect protected systems or data or identify specific groups such as managers, administrators, users, or contractors. Map each applicable rule to the workforce population it covers and the required cadence, with completion records preserved.


About the author

DCDaniel C. is a security operations leader with over a decade of experience building and scaling SOC capabilities for cloud-native companies. He has led security teams through multiple stages of growth — from early-stage environments with minimal tooling to mature organizations operating 24/7 security operations with distributed teams. His experience includes designing SOC architectures, evaluating and managing MDR providers, and building internal detection and response capabilities. Daniel has been responsible for vendor selection across SIEM, EDR, and XDR platforms, as well as defining SLAs, response models, and escalation frameworks. He has also worked closely with executive leadership on budgeting, board reporting, and aligning security operations with broader business risk. He writes about the practical decisions security leaders face — including build vs buy tradeoffs, how to evaluate security vendors, and what it actually takes to run an effective security operations function at scale

Stay sharp on security operations

Practitioner takes on SOC modernization, detection engineering, threat hunting, and more. No fluff. No product pitches.

Security awareness training: what it actually buys | Future of SecOps