← All stories
● Covered by 1 source · 1 reportLow impact1 neutral

Security Awareness Training Effectiveness Debated Amidst Rising Attacks

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Empirical evidence suggests security awareness training is not working.
  • Training programs are often repetitive and generic due to compliance requirements.
  • Current training does not reflect sophisticated social engineering and AI attacks.
  • Compliance mandates can reduce training to a legal checkbox.

Debate on Training Efficacy

Enterprises universally conduct security awareness training, but its tangible benefits are debatable. Despite widespread training, successful cyberattacks continue to increase, leading to questions about its effectiveness. Opinions vary on whether awareness training works, with some suggesting it is ineffective while others believe it has value under specific conditions.

Focus on Social Engineering

Awareness training typically aims to reduce the impact of poor judgment leading to insider threats and to harden employees against malicious social engineering. The current discussion primarily focuses on the latter aspect, as social engineering remains a significant vector for attacks.

Compliance-Driven Repetition

Many experts, including Stefan Dasic of Malwarebytes, argue that most training programs fail due to their execution. They are often repetitive and generic, making them seem pointless to employees. This repetition is frequently driven by compliance and insurance requirements that mandate annual re-delivery of the same content, regardless of employee knowledge. This approach risks reducing awareness training to a mere annual legal checkbox.

Outdated Training for Modern Threats

Robert Costello of Merlin Group and Mike Lyman of Black Duck highlight that much of today's training is compliance-focused and does not address sophisticated social engineering or AI-enabled attacks. Re-taking identical courses across multiple employers illustrates 'training-as-compliance-theater,' which produces checkbox completion without necessarily changing behavior. This may explain why some studies show weak or null effects even with high completion rates.

Compliance as a Target, Not a Baseline

A core issue with compliance requirements is that they often become a target to achieve rather than a baseline for continuous improvement. This mindset can hinder the evolution of training programs to effectively counter new and evolving threats.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~4 min · 3 stories · Oct 08

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Security awareness training is widely implemented in enterprises, but its effectiveness in preventing cyberattacks is questioned. Experts suggest current training methods are often repetitive, compliance-driven, and fail to address modern social engineering and AI-enabled threats. The focus on compliance rather than actual behavioral change limits its impact.