Editorial

When is Enough Security Awareness Training?

Rethinking security awareness to turn 'yawns' into 'smiles' 

Tuesday, June 02, 2026 | 5 MINS

There was a time when annual security awareness training was considered a significant step forward. Every employee completed a compliance module, watched a handful of videos, answered a short multiple-choice assessment and received a certificate confirming they had understood the risks. 

For many organisations, that model remained largely unchanged for years.  The problem is that cyber threats did not stand still.

Employees now work across multiple devices, collaborate through dozens of SaaS applications, regularly interact with AI tools and process business-critical information almost entirely through cloud services. The volume and sophistication of phishing, business email compromise and social engineering attacks have increased dramatically. Yet, many organisations continue to rely on awareness programmes that have changed very little from those designed a decade ago.

At the same time, employees are becoming increasingly fatigued.  Mandatory training, simulated phishing exercises, repeated policy reminders and regular compliance campaigns all compete for attention alongside people's day jobs. Security teams understandably want to reinforce good behaviour, but there is a point where frequency begins to reduce effectiveness. When every message is marked as important, employees inevitably begin to tune them out.

This raises an uncomfortable question for security leaders - how much awareness training actually improves security, and when does it simply become background noise?  The answer is unlikely to be found by increasing the number of training modules.

Most security professionals recognise that human behaviour is considerably more complex than knowledge alone. Employees rarely click on malicious links because they have forgotten the contents of last year's awareness course. They do so because they are busy, distracted, under pressure or presented with messages that appear entirely legitimate within the context of their daily work.

Effective security awareness is becoming less about delivering information and more about influencing behaviour. Rather than relying on generic annual programmes, many organisations are moving towards contextual education delivered at the point where decisions are made. Short interventions, role-specific guidance, timely coaching following risky behaviour and practical reinforcement often prove far more valuable than lengthy compliance exercises completed months earlier.

Changing the way success is measured


Completion rates and assessment scores remain useful for demonstrating regulatory compliance, but they reveal very little about whether security behaviour is actually improving. Organisations are increasingly looking at indicators such as phishing susceptibility over time, reporting rates, response times, policy adoption and the willingness of employees to seek advice before taking potentially risky actions.

Cultural shift, or technical?

Perhaps the biggest shift, however, is cultural rather than technical.  Security awareness has traditionally focused on reducing human error. Increasingly, mature organisations are recognising that employees represent one of their strongest defensive capabilities when they are trusted, supported and equipped to make informed decisions. People should not be viewed as the weakest link; they are often the first to recognise unusual activity, question suspicious requests or report incidents before technology detects them.  That requires a different relationship between security teams and the wider business.

Building a different type of relationship


Awareness programmes that rely heavily on fear, punishment or repeated testing rarely foster long-term engagement. Those that treat employees as active participants in organisational resilience are far more likely to build the behaviours that security leaders are ultimately trying to encourage.

The question, then, is not whether organisations should invest in security awareness, it's whether they are investing in approaches that genuinely change behaviour, or simply asking employees to complete another training module because the calendar says it is time.

Community Note


Security awareness continues to evolve alongside human risk management, behavioural science and AI-driven social engineering. If you have practical experience designing awareness programmes, measuring behavioural change or improving organisational security culture, we'd like to hear your perspective.

Don't hesitate to get in touch with our Community Editor, Sam Redwood, at sam.redwood@myredfort.com if you have something you wish to contribute on this topic

Other topics