root64Offensive Security. Cyber Resilience. Trusted Expertise.
Insight

Why most cyber awareness training fails

Annual video modules and click-rate leaderboards do not change behaviour. What does.

ROOT64 / FIELD NOTES26 August 20265 min · Root64

Most organisations run awareness training once a year, record completion, and file the certificate. Then someone in finance pays a fraudulent invoice and everyone is surprised. The training was not wrong. It was designed to be completed, not to be used.

Failure one: measuring the wrong number

Phishing simulations are usually judged on click rate. Click rate is the least useful number available. Some people will always click, and driving the figure down mostly teaches staff to be suspicious of internal email — which has its own cost.

The number that matters is the report rate, and specifically the time from first delivery to first report. That measures whether your organisation has a working immune response. An employee who clicks and reports within two minutes is more valuable than one who deletes the message silently.

Failure two: punishing the reporter

If reporting a mistake produces a lecture, a note to a manager, or a public statistic, people stop reporting. They do not stop clicking. The cost of an incident is dominated by how long it stayed hidden, so any process that adds delay is expensive.

The instruction has to be genuinely safe to follow: tell us immediately and nothing bad happens to you. That only works if it is true the first time someone tests it.

Failure three: generic content

A stock module about a Nigerian prince teaches nothing about the invoice fraud attempt that will actually arrive. Attacks are role-specific. Finance sees payment diversion. HR sees payroll changes and fake CVs with attachments. Engineering sees dependency and repository attacks. Leadership sees impersonation of themselves.

Training that uses your own domain names, your own vendor names and your own approval workflows is recognised. Training that uses stock scenarios is watched.

Failure four: annual cadence

One session a year against a threat that changes monthly is a compliance artefact. Short, frequent, specific contact works better than a long annual event — a five-minute briefing when a new fraud pattern appears in your sector will be remembered longer than a two-hour module in April.

What a working programme looks like

  • A baseline measurement before any training, so improvement is demonstrable
  • Role-specific content for finance, HR, engineering and leadership
  • Simulations built on your own context, not stock templates
  • Report rate and time-to-report as the headline metrics
  • A one-click reporting route that is genuinely consequence-free
  • Departmental results given to managers, not a company leaderboard
  • Short reinforcement through the year, not one annual event
  • A tabletop exercise for leadership, because their decisions dominate the cost of an incident

The uncomfortable part

Awareness training is a control with real limits. A sufficiently good pretext will get through any workforce, and blaming the person who fell for it is a way of avoiding the harder question of why one click was enough to matter.

Train people so incidents are reported early. Build systems so one mistake is survivable. Both, not either.


All insights

Your next move

Start a conversation

Contact us