{"id":112554,"date":"2026-09-28T12:00:00","date_gmt":"2026-09-28T12:00:00","guid":{"rendered":"https:\/\/www.red-gate.com\/simple-talk\/?p=112554"},"modified":"2026-09-16T11:29:57","modified_gmt":"2026-09-16T11:29:57","slug":"cybersecurity-training-doesnt-work-heres-why","status":"publish","type":"post","link":"https:\/\/www.red-gate.com\/simple-talk\/career\/cybersecurity-training-doesnt-work-heres-why\/","title":{"rendered":"Cybersecurity training doesn&#8217;t work &#8211; here&#8217;s why"},"content":{"rendered":"\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><strong>Cybersecurity training doesn&#8217;t reduce phishing risk. Studies show most staff already know the answers before they take the course, don&#8217;t engage with the material, and behave no differently afterward. <\/strong><\/p>\n\n\n\n<p><strong>Why, then, do companies keep running cybersecurity (and compliance) training anyway? Greg Low has thoughts<\/strong>.<\/p>\n\n\n\n<p>Not too long ago, I <a href=\"https:\/\/www.kpbs.org\/news\/science-technology\/2025\/10\/31\/study-concludes-cybersecurity-training-doesnt-work\" target=\"_blank\" rel=\"noreferrer noopener\">read about a study<\/a> that concluded that <strong>cybersecurity training doesn\u2019t actually <em>work<\/em><\/strong>. I can\u2019t say I was surprised by it &#8211; and here&#8217;s why.<\/p>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-why-compliance-training-exists-and-it-s-not-to-teach-you\">Why compliance training exists (and it&#8217;s not to teach you)<\/h2>\n\n\n\n<p>I spend a lot of time mentoring on client sites &#8211; many of which are large organizations &#8211; and they often require me to attend regular &#8216;training&#8217; sessions to satisfy their corporate <a href=\"https:\/\/www.red-gate.com\/simple-talk\/data-security-privacy-compliance\/how-to-delete-personal-data-gdpr-ccpa-compliance\/\" target=\"_blank\" rel=\"noreferrer noopener\">compliance<\/a> goals.<\/p>\n\n\n\n<p>I don\u2019t at all mind taking these courses, despite their repetition. At company A, I complete one on conflicts of interest, or handling <a href=\"https:\/\/www.ibm.com\/think\/topics\/pii\" target=\"_blank\" rel=\"noreferrer noopener\">private or sensitive data<\/a>, or <a href=\"https:\/\/www.red-gate.com\/simple-talk\/data-security-privacy-compliance\/\" target=\"_blank\" rel=\"noreferrer noopener\">IT security<\/a>, and over at company B I take another that&#8217;s nearly word-for-word identical. It then happens again at company C.<\/p>\n\n\n\n<p>This, also, is not surprising. After all, there aren&#8217;t many vendors producing this &#8216;training&#8217; content for business use, so content overlap is inevitable.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-is-the-password-advice-even-accurate\">Is the password advice even accurate?<\/h2>\n\n\n\n<p>I&#8217;m always fascinated by the information presented as <em>factual<\/em> in these courses. For a simple example: password complexity and rotation.<\/p>\n\n\n\n<p>Many large companies I consult with have rules that say user passwords <em>must<\/em> contain a certain combination of upper and lower-case characters, numbers, etc &#8211; and these passwords should be changed regularly. This is considered &#8216;perceived wisdom&#8217;. <\/p>\n\n\n\n<p>By default, Windows want to enforce the same rules &#8211; and corporate <strong><a href=\"https:\/\/www.microsoft.com\/en-gb\/security\/business\/security-101\/what-is-cybersecurity\" target=\"_blank\" rel=\"noreferrer noopener\">cybersecurity<\/a><\/strong> regards both as something that users <em>need<\/em> to know. <\/p>\n\n\n\n<p>If I ever ask the organization <em>why<\/em> they do this, the answer is simple: <strong>security.<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-nist-vs-perceived-wisdom\">NIST vs &#8216;perceived wisdom&#8217;<\/h3>\n\n\n\n<p>The <a href=\"https:\/\/www.nist.gov\/\" target=\"_blank\" rel=\"noreferrer noopener\">National Institute of Standards and Technology (NIST)<\/a> doesn&#8217;t just repeat this information. They researched these topics. <a href=\"https:\/\/pages.nist.gov\/800-63-FAQ\/\" target=\"_blank\" rel=\"noreferrer noopener\">Their guidelines<\/a> <em>completely disagree<\/em> with the &#8216;perceived wisdom&#8217; I mentioned above.<\/p>\n\n\n\n<p><a href=\"https:\/\/pages.nist.gov\/800-63-3\/sp800-63b.html#memsecretver\" target=\"_blank\" rel=\"noreferrer noopener\">SP 800-63B Section 5.1.1.2 paragraph 9<\/a> says: <em><strong>&#8220;Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily<\/strong> (e.g., periodically). However, verifiers SHALL force a change if there is evidence of compromise of the authenticator.&#8221;<\/em><\/p>\n\n\n\n<p>The same paragraph recommends against the use of composition rules.<\/p>\n\n\n\n<p>The bottom line is: the research shows that <strong>this requirement has the overall effect of reducing security &#8211; not increasing it. <\/strong><\/p>\n\n\n\n<p>But let&#8217;s not allow research get in the way of &#8216;perceived wisdom&#8217;&#8230;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-completion-isn-t-learning-how-these-courses-are-measured\">Completion isn&#8217;t learning: how these courses are measured<\/h2>\n\n\n\n<p>Let&#8217;s start by agreeing that training should involve <em>learning<\/em> something. There should be a way to measure something as &#8216;different&#8217; after the training has been completed. At the organizations I consult at, however, the vast majority of staff wouldn\u2019t actually learn anything from these courses. <\/p>\n\n\n\n<p>Invariably, the questions they need to get correct &#8211; say, 80% correct &#8211; are so mind-numbingly obvious that I see many of them not even paying attention when the videos are playing. Then, at the end, they quickly answer the questions just to keep their managers happy. <\/p>\n\n\n\n<p>So many of these quizzes are absurd.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-why-do-these-courses-even-exist-then\">Why do these courses even exist then?<\/h3>\n\n\n\n<p>The primary reasons these courses exist are twofold. <\/p>\n\n\n\n<p>Firstly, to provide backside protection for the companies (rather than being about <em>actually teaching the staff something<\/em>).<\/p>\n\n\n\n<p>Second, to facilitate an easy way to blame staff when something goes wrong. After all, once they&#8217;ve &#8216;taken&#8217; the course, the staff can&#8217;t say they <em>&#8216;didn&#8217;t know&#8217;.<\/em><\/p>\n\n\n\n<p><strong>What the company is actually measuring is completion, not learning. <\/strong><\/p>\n\n\n\n<p>And, if nearly everyone could pass the assessment <em>before<\/em> taking the course, the assessment cannot demonstrate that the course has actually taught anyone anything new.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-does-training-actually-stop-phishing\">Does training actually stop phishing?<\/h2>\n\n\n\n<p>All the evidence &#8211; including the outcome of the report I referenced earlier &#8211; says <em>no<\/em>. This training does not actually stop or reduce the risk of<strong> <a href=\"https:\/\/www.crowdstrike.com\/en-gb\/cybersecurity-101\/social-engineering\/phishing-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">phishing<\/a>.<\/strong><\/p>\n\n\n\n<p>The general way this is tested afterwards is by sending (fake) malicious emails that pretend to be legitimate, to see what employees will click on, or what information they provide &#8211; if any. <\/p>\n\n\n\n<p>And the outcome of the report shows little evidence of any change in behavior <em>after<\/em> the training.<\/p>\n\n\n\n<p>Ironically, the report concluded that <em>&#8220;one reason the trainings are not effective is that the majority of people do not engage with the embedded training materials.&#8221;<\/em><\/p>\n\n\n\n<p>That&#8217;s exactly the point I was making earlier.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-ok-it-s-ineffective-but-why-is-that-a-problem\">OK, it&#8217;s ineffective &#8211; but why is that a problem?<\/h3>\n\n\n\n<p>My biggest issue is that, for many companies, nearly their entire corporate training budget is being spent on these courses. <\/p>\n\n\n\n<p>My take: <strong>the cost of delivering this material should be in a &#8216;corporate compliance&#8217; budget, not in anything that <em>pretends<\/em> to be the &#8216;training&#8217; budget.<\/strong><\/p>\n\n\n\n<p>Staff often don&#8217;t have any budget available to them to learn something that could actually help with their job.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-would-actually-reduce-phishing-risk\">What would actually reduce phishing risk<\/h2>\n\n\n\n<p>Most of the people being &#8216;trained&#8217; at these companies aren&#8217;t even IT staff &#8211; they often just have IT access as an ancillary part of their role. So, what the training <em>tries<\/em> to do is teach them routine ways to identify phishing attacks.<\/p>\n\n\n\n<p>That might sound like a great idea, but is it really? If you can train a non-IT person to take a series of steps to avoid a phishing scam, the real question is: <em>why haven&#8217;t your IT systems taken the same steps?<\/em> <\/p>\n\n\n\n<p>Why did the malicious content even reach the staff member in the first place?<\/p>\n\n\n\n<p>We IT people need to do better.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-summary\">Summary<\/h2>\n\n\n\n<p>The real problem isn\u2019t that organizations care about security or compliance. Instead, it\u2019s<strong> <\/strong>that they<strong> often confuse <em>proving<\/em> <em>that training occurred <\/em>with <em>actually changing behavior<\/em>.<\/strong> <\/p>\n\n\n\n<p>If staff already know the answers, don\u2019t engage with the material, and behave no differently afterwards, then calling it &#8216;training&#8217; is &#8211; at best &#8211; generous. Worse, it can consume the budget that could instead be used on helping people <em>genuinely <\/em>improve their skills. <\/p>\n\n\n\n<p>Compliance requirements may still need to be satisfied, but we should call them what they are. <\/p>\n\n\n\n<p><strong>And, when it comes to threats like phishing, the better answer isn\u2019t simply to keep telling users to be more careful &#8211; it\u2019s to build IT systems that don\u2019t rely on every employee successfully identifying every attack.<\/strong><\/p>\n\n\n\n<section id=\"my-first-block-block_19b4e3b04db7752e2e26317f491fa3c1\" class=\"my-first-block alignwide\">\n    <div class=\"bg-brand-600 text-base-white py-5xl px-4xl rounded-sm bg-gradient-to-r from-brand-600 to-brand-500 red\">\n        <div class=\"gap-4xl items-start md:items-center flex flex-col md:flex-row justify-between\">\n            <div class=\"flex-1 col-span-10 lg:col-span-7\">\n                <h3 class=\"mt-0 font-display mb-2 text-display-sm\">Protect your data. Demonstrate compliance.<\/h3>\n                <div class=\"child:last-of-type:mb-0\">\n                                            With Redgate, stay ahead of threats with real-time monitoring and alerts, protect sensitive data with automated discovery &#038; masking, and demonstrate compliance with traceability across every environment.                                    <\/div>\n            <\/div>\n                                            <a href=\"https:\/\/www.red-gate.com\/solutions\/use-cases\/security-and-compliance\/\" class=\"btn btn--secondary btn--lg\" aria-label=\"Learn more: Protect your data. Demonstrate compliance.\">Learn more<\/a>\n                    <\/div>\n    <\/div>\n<\/section>\n\n\n<section id=\"faq\" class=\"faq-block my-5xl\">\n    <h2>FAQs<\/h2>\n\n                        <h3 class=\"mt-4xl\">1. Does cybersecurity training reduce phishing risk?<\/h3>\n            <div class=\"faq-answer\">\n                <p dir=\"ltr\">Evidence suggests no. Research into corporate security training found little change in employee behavior after completion, largely because most people don&#8217;t engage with the training material in the first place. Training measures completion, not learning.<\/p>\n            <\/div>\n                    <h3 class=\"mt-4xl\">2. Why do companies keep running cybersecurity training that doesn&#039;t work?<\/h3>\n            <div class=\"faq-answer\">\n                <p dir=\"ltr\">Two reasons: it protects the organization legally, and it lets staff be blamed when something goes wrong, since they can no longer say they &#8216;didn&#8217;t know.&#8217; Neither reason is about actually teaching people something new.<\/p>\n            <\/div>\n                    <h3 class=\"mt-4xl\">3. What&#039;s a more effective way to prevent phishing attacks?<\/h3>\n            <div class=\"faq-answer\">\n                <p dir=\"ltr\">Building IT systems that don&#8217;t rely on every employee spotting every attack. If a non-technical staff member can be trained to catch a phishing email, the same steps could usually be automated in the mail or security system before it ever reaches them.<\/p>\n            <\/div>\n            <\/section>\n","protected":false},"excerpt":{"rendered":"<p>Research shows cybersecurity training rarely changes behavior or stops phishing. Here&#8217;s why compliance courses fail &#8211; and what actually reduces risk instead.&hellip;<\/p>\n","protected":false},"author":346483,"featured_media":113084,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[45105,53,46],"tags":[4362,4619,5765,4341],"coauthors":[159368],"class_list":["post-112554","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-career","category-featured","category-data-security-privacy-compliance","tag-career","tag-security","tag-security-and-compliance","tag-training"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/posts\/112554","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/users\/346483"}],"replies":[{"embeddable":true,"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/comments?post=112554"}],"version-history":[{"count":16,"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/posts\/112554\/revisions"}],"predecessor-version":[{"id":113097,"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/posts\/112554\/revisions\/113097"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/media\/113084"}],"wp:attachment":[{"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/media?parent=112554"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/categories?post=112554"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/tags?post=112554"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/coauthors?post=112554"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}