Instructor leading IT Security Awareness Training session with seated employees watching padlock

IT security awareness training for employees: does it actually work?

The largest phishing training trial found only a 2% click-rate drop. Learn what actually reduces risk and how to meet NIS2, ISO 27001, and GDPR requirements.

200+ companies already trust deeploi

Key Takeaways

  • Does security awareness training work? Not as most companies run it. The largest trial to date – 19,500 employees over 8 months – found embedded phishing training cut click rates by only about 2%, and annual modules showed no effect at all.

  • Employees don't engage. 75% spent under a minute on the training material; a third closed the page immediately.

  • Phishing-resistant MFA does the heavy lifting. Microsoft reports it stops more than 99% of identity-based attacks, even when the attacker already holds valid credentials.

  • Measure reporting rate, not click rate. Fast reporting lets incident response contain threats; click rate only shows who recognised one template.

  • Training is still legally mandatory. NIS2/BSIG § 30 requires staff awareness measures, § 38 obliges management to train personally, and ISO 27001 Annex A 6.3 mandates it.

The largest randomized controlled trial of security awareness training to date delivered a sobering result. Researchers at UC San Diego tracked roughly 19,500 employees over eight months and found that embedded phishing training reduced click rates by only about two percentage points. Annual mandatory training modules showed no significant effect at all. Perhaps the most telling detail: (University of California San Diego) 75% of employees spent under a minute on the training material, and a third closed the page immediately without engaging.

So does security awareness training work? The honest answer is: not the way most companies run it today. But that doesn't mean you can skip it. Training is legally mandatory across multiple frameworks, and every customer security questionnaire will ask about it. The real question is not should we train but how do we train so it isn't theatre.

What does the evidence actually say about security awareness training?

Most vendor content on this topic repeats a familiar claim: "the human factor causes 90% or more of breaches." That statistic, however true, quietly implies that training humans will fix the problem. The UC San Diego trial tested that assumption rigorously and found the fix barely registers. Embedded phishing simulations, where employees who click a simulated phish are immediately shown a training page, produced roughly a 2% reduction in future clicks. Annual compliance modules, the kind most companies deploy once a year, showed no measurable improvement at all.

This doesn't mean awareness is worthless. It means the delivery model is broken. Asking employees to sit through a 45-minute slide deck once a year, checking a compliance box, and then measuring success by whether fewer people clicked a fake email is a formula designed to produce reports, not behavior change.

Why click-rate is the wrong KPI

Click rate has become the default metric for cybersecurity awareness programmes, but it measures the wrong thing. A low click rate might mean employees learned to recognize a specific template, not that they developed a genuine security reflex. Worse, a focus on "gotcha" simulations creates a culture of anxiety rather than vigilance.

The metric that actually matters is reporting rate: did the employee flag the suspicious message? A team where 60% of people report a phish within minutes is far safer than a team where 5% click but nobody reports. Time-to-report is equally important, because fast reporting lets your incident response process contain threats before they spread. If you are measuring your programme, shift the scoreboard from "how many fell for it" to "how many raised the alarm."

What reduces risk more than a training slide deck?

Technical controls that remove the human from the equation

Training tries to change behavior. Technical controls remove the opportunity for the behavior to cause damage in the first place. When it comes to phishing, the single most effective technical measure is phishing-resistant MFA (multi-factor authentication, meaning a method that proves your identity using something a phisher cannot steal remotely, such as a hardware key or device-bound passkey). (Microsoft) reports that more than 99.9% of compromised accounts do not have MFA enabled. And according to (Microsoft), phishing-resistant MFA stops more than 99% of identity-based attacks even when the attacker already holds valid credentials.

Beyond MFA, several other controls make a measurable difference:

  • Domain-bound password managers that autofill credentials only on legitimate domains, preventing employees from typing passwords into look-alike sites.

  • Least-privilege access, so a compromised account can only reach the data and systems that specific role genuinely needs.

  • Device hardening: enforced disk encryption, automatic OS patching, and endpoint security even without dedicated IT staff.

  • Fast offboarding: revoking accounts and wiping devices within hours, not days, when someone leaves. Stale accounts are open doors.

These measures shrink the attack surface in ways that no amount of training can replicate. If an employee clicks a phishing link but a hardware-bound passkey refuses to authenticate on the fake domain, the attack fails. That outcome doesn't depend on the employee's judgement in the moment. It depends on technical policy enforcement.

Training redesigned to actually change behavior

None of the above means you should abandon training. It means you should redesign it. The evidence points to a few principles that separate effective programmes from compliance theatre:

  1. Keep sessions short and frequent. Five-minute monthly micro-sessions outperform a two-hour annual module. Spaced repetition helps people retain information; a once-a-year event does not.

  2. Make content role-specific. Finance teams face CEO-fraud and invoice scams. HR handles sensitive personal data. Developers manage API keys. Generic training that covers everything for everyone covers nothing well.

  3. Measure reporting, not clicks. Reward employees who flag suspicious messages. Publicly celebrate fast reporters. Stop naming and shaming clickers.

  4. Connect training to real incidents. When a real phishing wave targets your industry, send a brief heads-up referencing the actual attack pattern. Context makes advice stick.

  5. Build a no-blame reporting culture. If employees fear punishment for clicking, they will hide mistakes instead of reporting them. Fast reporting is your best early-warning system; fear kills it.

Companies that combine AI-aware phishing defences with this kind of training redesign create two layers of protection: technical controls catch most attacks automatically, and a trained, motivated workforce catches the rest by reporting quickly.

You still have to do it: the legal requirements you cannot skip

Regardless of how well training works, multiple legal frameworks make it mandatory. In Germany, the NIS2 implementation through the BSIG (specifically § 30 and § 38) requires organizations in scope to implement cybersecurity awareness measures for all staff. Crucially, § 38 places a personal training obligation on management: executives must undergo security training themselves and can face personal liability if they do not. The size thresholds for NIS2 applicability generally start at 50 employees or €10 million in annual turnover, though critical-sector companies may be covered regardless of size.

ISO 27001 Annex A control 6.3 explicitly requires information security awareness, education, and training. GDPR Article 32 mandates "appropriate technical and organisational measures," and regulators have consistently interpreted this to include staff training on data protection. Beyond regulation, every customer security questionnaire and vendor assessment you encounter will ask whether you run a security awareness programme, how often, and how you measure its effectiveness.

Compliance, in other words, is table stakes. The question is whether you treat it as a box to check or as a genuine layer of defense.

Conclusion

Security awareness training is legally required, culturally useful, and, when redesigned around the right principles, a genuine contributor to your security posture. But it only works when paired with technical controls that remove the opportunity for human error to escalate into a breach. Phishing-resistant MFA, enforced device policies, automated offboarding: these are the measures that hold the line when an employee inevitably clicks the wrong link.

Platforms like deeploi automate exactly that technical layer, from MFA enforcement and device hardening to offboarding, so your training programme can focus on what it does best: building a culture where people report threats fast rather than hide mistakes. That combination, technical guardrails plus a reporting culture, is what turns awareness training from theatre into defence.

FAQ

Does phishing simulation training actually reduce clicks?

Marginally. The largest randomized trial found roughly a 2% reduction from embedded phishing training and no significant effect from annual modules. Simulations are not useless, but they are not a silver bullet either. Pair them with phishing-resistant MFA and password managers for meaningful risk reduction.

What does NIS2 require for employee security training?

The German NIS2 implementation (BSIG § 30 and § 38) requires mandatory awareness measures for all employees in covered organisations. Management faces a personal obligation to undergo training and can be held liable for non-compliance. SMEs meeting the size thresholds should treat this as a priority.

How can we make security awareness training effective instead of performative?

Replace annual click-through modules with short, frequent, role-specific sessions. Measure reporting rate and time-to-report rather than click rate. Build a no-blame culture where flagging suspicious messages is celebrated, not punished. And layer training on top of technical controls that catch attacks even when training fails.

What technical controls matter most alongside training?

Phishing-resistant MFA tops the list. Add domain-bound password managers, least-privilege access policies, automatic device patching, and fast offboarding. These controls remove the opportunity for human error to cause damage, which is exactly what training alone cannot guarantee.

This article is for general information only and does not constitute legal advice.

Founded
Customer Size
Headquarters
Industry
KEY RESULTS
CUSTOMER STORIES
This field is required
This field is required
This field is required
Choose
This field is required
This field is required
Thank you for your interest!

We’ll get back to you shortly.

Oops! Something went wrong while submitting the form.

Download the professional onboarding checklist for free

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

Get the checklist