Cybersecurity training doesn’t reduce phishing risk. Studies show most staff already know the answers before they take the course, don’t engage with the material, and behave no differently afterward.
Why, then, do companies keep running cybersecurity (and compliance) training anyway? Greg Low has thoughts.
Not too long ago, I read about a study that concluded that cybersecurity training doesn’t actually work. I can’t say I was surprised by it – and here’s why.
Why compliance training exists (and it’s not to teach you)
I spend a lot of time mentoring on client sites – many of which are large organizations – and they often require me to attend regular ‘training’ sessions to satisfy their corporate compliance goals.
I don’t at all mind taking these courses, despite their repetition. At company A, I complete one on conflicts of interest, or handling private or sensitive data, or IT security, and over at company B I take another that’s nearly word-for-word identical. It then happens again at company C.
This, also, is not surprising. After all, there aren’t many vendors producing this ‘training’ content for business use, so content overlap is inevitable.
Is the password advice even accurate?
I’m always fascinated by the information presented as factual in these courses. For a simple example: password complexity and rotation.
Many large companies I consult with have rules that say user passwords must contain a certain combination of upper and lower-case characters, numbers, etc – and these passwords should be changed regularly. This is considered ‘perceived wisdom’.
By default, Windows want to enforce the same rules – and corporate cybersecurity regards both as something that users need to know.
If I ever ask the organization why they do this, the answer is simple: security.
NIST vs ‘perceived wisdom’
The National Institute of Standards and Technology (NIST) doesn’t just repeat this information. They researched these topics. Their guidelines completely disagree with the ‘perceived wisdom’ I mentioned above.
SP 800-63B Section 5.1.1.2 paragraph 9 says: “Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically). However, verifiers SHALL force a change if there is evidence of compromise of the authenticator.”
The same paragraph recommends against the use of composition rules.
The bottom line is: the research shows that this requirement has the overall effect of reducing security – not increasing it.
But let’s not allow research get in the way of ‘perceived wisdom’…
Completion isn’t learning: how these courses are measured
Let’s start by agreeing that training should involve learning something. There should be a way to measure something as ‘different’ after the training has been completed. At the organizations I consult at, however, the vast majority of staff wouldn’t actually learn anything from these courses.
Invariably, the questions they need to get correct – say, 80% correct – are so mind-numbingly obvious that I see many of them not even paying attention when the videos are playing. Then, at the end, they quickly answer the questions just to keep their managers happy.
So many of these quizzes are absurd.
Why do these courses even exist then?
The primary reasons these courses exist are twofold.
Firstly, to provide backside protection for the companies (rather than being about actually teaching the staff something).
Second, to facilitate an easy way to blame staff when something goes wrong. After all, once they’ve ‘taken’ the course, the staff can’t say they ‘didn’t know’.
What the company is actually measuring is completion, not learning.
And, if nearly everyone could pass the assessment before taking the course, the assessment cannot demonstrate that the course has actually taught anyone anything new.
Does training actually stop phishing?
All the evidence – including the outcome of the report I referenced earlier – says no. This training does not actually stop or reduce the risk of phishing.
The general way this is tested afterwards is by sending (fake) malicious emails that pretend to be legitimate, to see what employees will click on, or what information they provide – if any.
And the outcome of the report shows little evidence of any change in behavior after the training.
Ironically, the report concluded that “one reason the trainings are not effective is that the majority of people do not engage with the embedded training materials.”
That’s exactly the point I was making earlier.
OK, it’s ineffective – but why is that a problem?
My biggest issue is that, for many companies, nearly their entire corporate training budget is being spent on these courses.
My take: the cost of delivering this material should be in a ‘corporate compliance’ budget, not in anything that pretends to be the ‘training’ budget.
Staff often don’t have any budget available to them to learn something that could actually help with their job.
What would actually reduce phishing risk
Most of the people being ‘trained’ at these companies aren’t even IT staff – they often just have IT access as an ancillary part of their role. So, what the training tries to do is teach them routine ways to identify phishing attacks.
That might sound like a great idea, but is it really? If you can train a non-IT person to take a series of steps to avoid a phishing scam, the real question is: why haven’t your IT systems taken the same steps?
Why did the malicious content even reach the staff member in the first place?
We IT people need to do better.
Summary
The real problem isn’t that organizations care about security or compliance. Instead, it’s that they often confuse proving that training occurred with actually changing behavior.
If staff already know the answers, don’t engage with the material, and behave no differently afterwards, then calling it ‘training’ is – at best – generous. Worse, it can consume the budget that could instead be used on helping people genuinely improve their skills.
Compliance requirements may still need to be satisfied, but we should call them what they are.
And, when it comes to threats like phishing, the better answer isn’t simply to keep telling users to be more careful – it’s to build IT systems that don’t rely on every employee successfully identifying every attack.
Protect your data. Demonstrate compliance.
FAQs
1. Does cybersecurity training reduce phishing risk?
Evidence suggests no. Research into corporate security training found little change in employee behavior after completion, largely because most people don’t engage with the training material in the first place. Training measures completion, not learning.
2. Why do companies keep running cybersecurity training that doesn't work?
Two reasons: it protects the organization legally, and it lets staff be blamed when something goes wrong, since they can no longer say they ‘didn’t know.’ Neither reason is about actually teaching people something new.
3. What's a more effective way to prevent phishing attacks?
Building IT systems that don’t rely on every employee spotting every attack. If a non-technical staff member can be trained to catch a phishing email, the same steps could usually be automated in the mail or security system before it ever reaches them.
This document contains proprietary information and is protected by copyright law.
Copyright © 2026 Red Gate Software Limited. All rights reserved
Load comments