Enterprises universally conduct security awareness training, but its tangible benefits are debatable. Despite widespread training, successful cyberattacks continue to increase, leading to questions about its effectiveness. Opinions vary on whether awareness training works, with some suggesting it is ineffective while others believe it has value under specific conditions.
Awareness training typically aims to reduce the impact of poor judgment leading to insider threats and to harden employees against malicious social engineering. The current discussion primarily focuses on the latter aspect, as social engineering remains a significant vector for attacks.
Many experts, including Stefan Dasic of Malwarebytes, argue that most training programs fail due to their execution. They are often repetitive and generic, making them seem pointless to employees. This repetition is frequently driven by compliance and insurance requirements that mandate annual re-delivery of the same content, regardless of employee knowledge. This approach risks reducing awareness training to a mere annual legal checkbox.
Robert Costello of Merlin Group and Mike Lyman of Black Duck highlight that much of today's training is compliance-focused and does not address sophisticated social engineering or AI-enabled attacks. Re-taking identical courses across multiple employers illustrates 'training-as-compliance-theater,' which produces checkbox completion without necessarily changing behavior. This may explain why some studies show weak or null effects even with high completion rates.
A core issue with compliance requirements is that they often become a target to achieve rather than a baseline for continuous improvement. This mindset can hinder the evolution of training programs to effectively counter new and evolving threats.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Security awareness training is widely implemented in enterprises, but its effectiveness in preventing cyberattacks is questioned. Experts suggest current training methods are often repetitive, compliance-driven, and fail to address modern social engineering and AI-enabled threats. The focus on compliance rather than actual behavioral change limits its impact.